ARCHIVED
This job listing has been archived and is no longer accepting applications.
MisuJob - AI Job Search Platform MisuJob

Senior SOC Analyst L3 - Saudi National - Jeddah, KSA

DeepSource Technologies

Jeddah, Makkah Province, Saudi Arabia permanent

Posted: March 8, 2026

Interested in this position?

Create a free account to apply with AI-powered matching

Quick Summary

We are seeking a highly experienced Senior SOC Analyst – Layer 3 (DFIR) to lead advanced digital forensic investigations and incident response operations in Jeddah, Saudi Arabia.

Job Description

Position Overview

We are seeking a highly experienced Senior SOC Analyst – Layer 3 (DFIR) to lead advanced digital forensic investigations and incident response operations within our Cybersecurity Operations Center (SOC) in Jeddah.

The selected candidate will act as the highest technical escalation point for major security incidents, conduct in-depth forensic investigations, manage complex breach scenarios, and provide strategic guidance to SOC L1 and L2 teams. This role requires strong hands-on DFIR expertise in enterprise environments, including endpoint, network, cloud, and hybrid infrastructures.

Key Responsibilities

1. Advanced Incident Response Leadership

• Lead end-to-end handling of high-severity cybersecurity incidents (Ransomware, APT, data exfiltration, insider threats).

• Direct containment, eradication, and recovery strategies during critical incidents.

• Serve as primary escalation point for SOC L2 investigations.

• Coordinate with IT, Legal, Risk, Compliance, and executive leadership during crisis situations.

• Conduct post-incident reviews and lessons-learned workshops.

2. Digital Forensics Investigations

• Perform forensic acquisition and analysis of endpoints, servers, and cloud workloads.

• Conduct disk, memory, and network forensics using industry-standard tools.

• Preserve and maintain chain-of-custody documentation.

• Analyze artifacts such as registry, event logs, browser history, persistence mechanisms, and lateral movement traces.

• Prepare forensic reports suitable for executive and legal review.

3. Endpoint & EDR Deep Analysis

• Perform deep investigations using enterprise EDR platforms such as

Microsoft Defender for Endpoint,

CrowdStrike Falcon, or equivalent.

• Conduct advanced threat hunting and behavioral analysis.

• Reverse-engineer suspicious scripts or malware (basic to intermediate level).

4. SIEM & Log Correlation Expertise

• Conduct advanced log analysis across SIEM platforms such as

Splunk Enterprise Security,

Microsoft Sentinel, or equivalent.

• Develop and optimize advanced detection queries (SPL / KQL).

• Correlate endpoint, network, identity, and cloud telemetry for full attack chain reconstruction.

• Map incidents to MITRE ATT&CK framework techniques.

5. Network & Cloud Forensics

• Analyze PCAP, NetFlow, DNS, proxy, and firewall logs.

• Investigate suspicious lateral movement and command-and-control traffic.

• Perform forensic investigations within Microsoft 365, Azure, and AWS environments.

• Assess identity compromise scenarios (AD, Azure AD, privileged access abuse).

6. Threat Intelligence & Proactive Defense

• Integrate threat intelligence feeds into DFIR investigations.

• Conduct proactive threat hunting campaigns.

• Participate in red team / purple team exercises.

• Identify detection gaps and recommend defensive improvements.

7. Governance & Compliance Support

• Ensure forensic readiness aligned with NCA ECC, SAMA CSF, ISO 27001, and other regulatory frameworks.

• Maintain forensic documentation aligned with legal admissibility standards.

• Contribute to incident response policy and playbook development.

8. On-Call & Crisis Response

• Participate in 24x7 on-call rotation for major incidents.

• Provide immediate response and executive-level briefing during critical cybersecurity events.


Requirements:
Candidates must demonstrate proven, hands-on DFIR experience in:

• Minimum 7–10 years of experience in cybersecurity operations.

• At least 3–5 years in L3 / DFIR role handling major enterprise incidents.

• Practical experience with forensic tools such as:

o EnCase

o FTK

o X-Ways

o Volatility

o Autopsy

• Memory forensics and live response techniques.

• Ransomware investigation and recovery coordination.

• Advanced Windows & Linux artifact analysis.

• Network protocol deep understanding (TCP/IP, DNS, HTTP/S, SMB, LDAP, Kerberos).

• Cloud security investigations (Azure / AWS / M365).

• Evidence handling and chain-of-custody documentation.

• Experience working in regulated sectors (Banking, Government, Critical Infrastructure preferred).

Why Apply Through MisuJob?

AI-Powered Job Matching: MisuJob uses advanced artificial intelligence to analyze your skills, experience, and career goals. Our matching algorithm compares your profile against thousands of job requirements to find positions where you have the highest chance of success. This saves you hours of manual job searching and ensures you only see relevant opportunities.

One-Click Applications: Once you create your profile, applying to jobs is effortless. Your resume and cover letter are automatically tailored to highlight the most relevant experience for each position. You can apply to multiple jobs in minutes, not hours.

Career Intelligence: Beyond job matching, MisuJob provides valuable career insights. See how your skills compare to market demands, identify skill gaps to address, and understand salary benchmarks for your experience level. Make data-driven decisions about your career path.

Frequently Asked Questions

How do I apply for this position?

Click the "Register to Apply" button above to create a free MisuJob account. Once registered, you can apply with one click and track your application status in your dashboard.

Is MisuJob free for job seekers?

Yes, MisuJob is completely free for job seekers. Create your profile, get matched with jobs, and apply without any cost. We help you find your dream job without any hidden fees.

How does AI matching work?

Our AI analyzes your resume, skills, and experience to understand your professional profile. It then compares this against job requirements using natural language processing to calculate a match percentage. Higher matches mean better fit for the role.

Can I apply to jobs in other countries?

Absolutely. MisuJob features jobs from companies worldwide, including remote positions. Filter by location or look for remote opportunities to find jobs that match your preferences.

Ready to Apply?

Join thousands of job seekers using MisuJob's AI to find and apply to their dream jobs automatically.

Register to Apply