Company logo hidden

Threat Detection Engineer - L2

Unlock employer Saudi Arabia Direct to Company 1 hour ago · 08 Sep 2026

Financial

  • Estimate: $35k - $70k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional
  • Arabic: Professional

Position

About the Role
As a Threat Detection Engineer, you’ll design high-impact detection strategies, build powerful automation, and elevate SOC operations to a world-class standard. You will also mentor rising cyber talent and collaborate with teams across threat intel, incident response, and platform engineering.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Advanced Threat Detection Engineering

  • Build high-fidelity correlation rules and behavioral detections within security platforms.
  • Translate adversary TTPs (MITRE ATT&CK), threat intel, and vulnerability data into actionable logic.
  • Identify detection gaps and introduce new data sources to cover evolving threat landscapes.
  • Automate detection testing and maintain detection quality over time.

Platform Engineering & Optimization

  • Lead architecture and optimization of XDR, SIEM, and SOC tech stacks for scale and resilience.
  • Streamline log ingestion pipelines — from parsing to normalization and enrichment.
  • Build scripts and automations (Python, PowerShell) to enhance SOC efficiency.
  • Integrate tools across the SOC stack to enable seamless workflows and response.

Threat Hunting & Incident Response

  • Collaborate with intel and incident response teams to enrich detection use cases and support threat hunts.
  • Provide Tier-3+ support for incident investigations and post-mortem analysis.

Mentorship & SOC Maturity

  • Improve SOC playbooks, SOPs, and detection engineering workflows.
  • Stay updated on global and regional threats — and evolve detection accordingly.
  • Ensure compliance alignment (e.g., NCA ECC, SAMA CSF).

Education

  • Bachelor’s in Computer Science, Cybersecurity, or related field.

Experience

  • Minimum 3 years of experience with hands-on expertise in developing and maintaining complex detection use cases.
  • Strong understanding of attacker behavior, incident response fundamentals, and digital forensics.

Technical Skills (You’re a Power User!)

  • SIEM: Expert in SIEM queries (SPL, KQL, Lucene), rule tuning, UEBA, and scaling.
  • EDR: Deep knowledge of EDR tools and endpoint detection tactics.
  • Network Security: Pro at packet analysis (Wireshark), IDS/IPS, and NetFlow.
  • Scripting: Advanced skills in Python and/or PowerShell for automation and integration.
  • OS Internals: Mastery of Windows/Linux/macOS logging, artifacts, and forensic value.
  • Threat Intelligence: Skilled in turning threat intel into real-time detection logic.
  • Cloud Security: Strong command of monitoring IaaS/PaaS/SaaS environments.

Certifications (Highly Preferred)

  • SANS GIAC (GDAT, GMON, GCIA, GCTI, GCIH)
  • Offsec (OSDA)
  • INE (eCTHP, eCIR)
  • (ISC)² CISSP, CSSLP

Soft Skills

  • Exceptional analytical thinking and creative problem-solving.
  • Excellent communication (English & Arabic), including technical reporting.
  • Strong mentorship abilities and a collaborative spirit.
  • Self-motivated, focused, and passionate about cyber defense.
  • Capable of juggling priorities under high-pressure situations.

Impact that Matters
Build products that shape the future of cybersecurity and protect organizations globally.

On-Site Collaboration
Be at the heart of innovation in our Almadina office, working side by side with passionate experts.

Continuous Growth
Access to certifications, trainings, and opportunities to sharpen your expertise.

Ownership Mindset
Benefit from our ESOP program and grow with the organization's success.

Culture of Trust
We empower talent, encourage ownership, and celebrate real outcomes.

Apply Direct

Jobs you might like   View all jobs

About Cybersecurity Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct