Job Summary
This role leads the design, deployment, and enhancement of advanced Security Operations capabilities, focusing on transitioning SOC operations to AI-assisted and autonomous models using automation, AI/GenAI, and detection engineering.
Responsibilities
- Lead technical design and deployment of AI-driven autonomous SOC capabilities.
- Identify SOC processes for automation across alert triage, investigation, and response.
- Develop AI-assisted investigation and decision-support workflows including LLM/GenAI integrations.
- Design human-in-the-loop controls and escalation mechanisms for autonomous actions.
- Create and maintain automated security workflows and orchestration playbooks using Python, REST APIs, and other tools.
- Lead detection engineering by developing and tuning detection rules across multiple security technologies.
- Integrate security telemetry into AI-driven workflows and ensure secure data handling and AI output monitoring.
- Assess and improve SOC processes to reduce manual workload and improve detection and response times.
Requirements
- 7+ years in cybersecurity with experience in SOC engineering, detection engineering, security automation, or incident response.
- Hands-on experience with SIEM tools like Microsoft Sentinel, Splunk ES, or Google SecOps.
- Experience with SOAR platforms and security orchestration.
- Proficiency in security automation using Python and REST APIs.
- Strong knowledge of SOC workflows, detection engineering, and MITRE ATT&CK framework.
- Experience integrating security platforms and developing automated investigation and response workflows.
- Familiarity with EDR/XDR, identity, email, network, cloud security, and threat intelligence platforms.
- Understanding of detection lifecycle management, detection-as-code, version control, CI/CD, and automated testing.
- Practical knowledge of Generative AI, Large Language Models, AI agents, prompt engineering, and secure AI implementation in cybersecurity.
- Experience with AI evaluation, accuracy testing, hallucination management, and guardrails.
Nice to haves
- Experience with Microsoft Sentinel / Security Copilot, Splunk ES / SOAR, Cortex XSOAR / XSIAM, Microsoft Defender XDR, CrowdStrike, ServiceNow SecOps.
- Familiarity with Git, GitLab, GitHub, Azure OpenAI, OpenAI APIs, or equivalent enterprise LLM platforms.
- Experience with cloud security platforms across Azure, AWS, or GCP.
- Background in building or deploying AI-enabled SOC, Autonomous SOC, hyperautomation, or security-agent solutions.
We refresh listings regularly, but some roles close early on the source platform.
Country: Saudi Arabia
City: Riyadh
Job Category: Consulting
Job Type: Full Time
Company Name: EY
Seniority level: Mid-Senior level
Sorry! This job has expired.

