Company logo hidden

Threat Intelligence & SOAR Engineer

Unlock employer Riyadh, Saudi Arabia Posted: 01 Feb 2026

Financial

  • Estimate: $55k - $74k*
  • Zero income tax location

Accessibility

  • Office Only
  • Apply from abroad
  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional

Position

We are seeking a highly skilled Threat Intelligence & SOAR Specialist to strengthen our cybersecurity operations by integrating threat intelligence platforms, automating incident response, and proactively identifying emerging threats. The ideal candidate will work closely with SOC and Incident Response teams to enhance detection, response, and threat visibility across enterprise environments.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Key Responsibilities:

  • Integrate and manage multiple Threat Intelligence Platforms (TIPs) to centralize, correlate, and operationalize threat intelligence feeds.
  • Configure, maintain, and optimize SOAR playbooks to automate incident response and security workflows.
  • Enrich SIEM and XDR alerts using threat intelligence to improve detection accuracy, prioritization, and triage efficiency.
  • Conduct proactive threat hunting across endpoint, network, and cloud environments to identify advanced and emerging threats.
  • Collaborate with SOC and Incident Response teams to manage phishing campaigns, malware outbreaks, and Advanced Persistent Threat (APT) investigations.
  • Maintain and enhance threat intelligence dashboards and reporting frameworks.
  • Deliver monthly and ad-hoc threat intelligence reports to technical and business stakeholders.
  • Continuously evaluate new threat intelligence sources and detection techniques to improve security posture.

Required Experience & Skills:

  • 3+ years of hands-on experience in Threat Intelligence, SOAR, SOC operations, or Incident Response.
  • Strong experience with Threat Intelligence and SOAR tools, including:
    • ThreatQuotient TIP
    • Palo Alto Cortex XSOAR
    • MISP
    • Anomali ThreatStream
  • Solid understanding of MITRE ATT&CK framework, kill chains, and adversary tactics, techniques, and procedures (TTPs).
  • Experience integrating TIPs with SIEM/XDR platforms.
  • Proven ability to design and automate SOAR playbooks for real-world security incidents.
  • Strong analytical, documentation, and communication skills.

Preferred Qualifications:

  • Experience in banking, financial services, or large enterprise environments.
  • Familiarity with phishing analysis, malware analysis, and threat actor profiling.
  • Relevant cybersecurity certifications (e.g., GCIA, GCTI, GCED, CISSP, or vendor-specific certifications) are a plus.

Location: Riyadh, Saudi Arabia
Work Conditions: On-site, Full-time

Apply Direct

Jobs you might like   View all jobs

About Information Technology & Services Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct