Role at a glance
- Job function
-
Software Engineering & IT Cybersecurity
- Salary
- Not Disclosed
- Location
- Riyadh
- Work arrangement
- On-site
- Employment
- Full-time
Spotted an issue?
We’ll check it against the original posting.
Role Summary
The Security Delivery Senior Analyst works in Security Operations, taking ownership of incidents escalated from L1 analysts and investigating security events. The role also supports SIEM detection improvements and contributes to consistent SOC procedures and incident response practices.
What You'll Do
- Triage, validate, investigate, categorize, and document escalated security events according to SOC processes, severity levels, and runbooks.
- Correlate security information to assess suspicious activity and escalate complex or high-risk incidents through appropriate channels.
- Work with SIEM administrators and security engineering teams to support the creation, testing, and refinement of SIEM use cases and...
- Identify potential detection gaps and share investigation insights with the appropriate security teams.
- Develop and improve SOPs, investigation playbooks, and incident response plans; capture lessons learned and collaborate with L1 analysts...
Generated from the employer's posting. Verify important details before applying.
View full postingQualifications
Experience in a SOC or cybersecurity monitoring environment, including hands-on security-event triage, investigation, and escalation. Requires understanding of incident response processes, SOC procedures, runbooks, security alerts, severity classification, SIEM technologies, detection use cases, and correlation rules; experience creating or maintaining SOPs, playbooks, and incident-response documentation; ability to investigate and correlate events; and strong analytical, troubleshooting, communication, and detail-oriented skills.
Required
- SOC or cybersecurity monitoring experience
- Hands-on security-event triage, investigation, and incident escalation
- Understanding of incident response processes, SOC procedures, security runbooks, alert severity classification, and escalation processes
- Experience using SIEM technologies and understanding of SIEM detection use cases and correlation rules
- Ability to investigate and correlate security events and identify potentially malicious activity
- Experience creating or maintaining SOPs, playbooks, and incident-response documentation
- Strong analytical, troubleshooting, and problem-solving capabilities; strong written and verbal communication skills and attention to detail
Preferred
- Experience supporting SIEM use-case development or detection tuning
- Exposure to EDR, SOAR, endpoint security, or other security-monitoring technologies
- Familiarity with MITRE ATT&CK and common attack techniques
- Experience with threat hunting or deeper incident investigation
- Relevant cybersecurity or SOC certifications
Original job description
Content provided by the employer
Original job description
Content provided by the employer
As a Security Delivery Senior Analyst, you will play a key role within Security Operations, taking ownership of security events escalated from L1 analysts and performing deeper triage, investigation and analysis. You will help ensure incidents are handled consistently according to established processes and runbooks, while contributing to stronger playbooks, incident response procedures and SIEM detection use cases.
What You’ll Do
Incident Triage & Investigation
- Take ownership of security incidents and events escalated from L1 analysts and handle them according to defined SOC processes and procedures.
- Perform detailed triage, validation and investigation of detected and escalated security events.
- Analyze and categorize events of interest according to agreed severity levels, escalation criteria and runbooks.
- Correlate available security information to determine the nature, scope and potential impact of suspicious activity.
- Escalate complex or high-risk incidents through the appropriate response channels where required.
- Maintain accurate investigation findings, evidence and incident documentation.
SIEM & Detection Support
- Work closely with SIEM administrators and security engineering teams to support the creation and enhancement of security-monitoring use cases.
- Provide investigation insights that can help identify opportunities to improve existing detection logic.
- Support testing and refinement of SIEM use cases based on operational security requirements.
- Identify potential detection gaps observed during incident investigations and raise them with the appropriate security teams.
SOC Procedures & Continuous Improvement
- Develop, maintain and continuously improve Standard Operating Procedures (SOPs), investigation playbooks and Incident Response plans.
- Help standardize investigation and triage practices to promote consistent incident handling across the SOC.
- Capture lessons learned from investigations and contribute to improvements in operational processes.
- Collaborate with L1 analysts and other security teams to support effective incident handling and knowledge sharing.
What You’ll Need
- Experience working within a Security Operations Center (SOC) or cybersecurity monitoring environment.
- Hands-on experience with security event triage, investigation and incident escalation.
- Good understanding of Incident Response processes, SOC procedures and security runbooks.
- Experience using Security Information and Event Management (SIEM) technologies.
- Ability to investigate and correlate security events and identify potentially malicious activity.
- Understanding of security alerts, event severity classification and escalation processes.
- Experience creating or maintaining SOPs, playbooks and Incident Response documentation.
- Understanding of SIEM detection use cases and correlation rules.
- Strong analytical, troubleshooting and problem-solving capabilities.
- Strong written and verbal communication skills with attention to detail.
Bonus Points If You Have
- Experience supporting SIEM use-case development or detection tuning.
- Exposure to EDR, SOAR, endpoint security or other security-monitoring technologies.
- Familiarity with MITRE ATT&CK and common attack techniques.
- Experience with threat hunting or deeper incident investigation.
- Relevant cybersecurity or SOC certifications.
About Accenture
Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.Visit us at www.accenture.com
Equal Employment Opportunity Statement
We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, sexual orientation, gender identity or expression, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.
About the company
Accenture
Large Enterprise
Accenture is a global professional services company that specializes in providing consulting, technology, and outsourcing services. With a diverse range of industries served, including financial services, healthcare, and telecommunications, Accenture leverages advanced technologies and data analytics to help organizations improve their performance and drive innovation. Committed to sustainable progress, the company emphasizes its dedication to inclusivity, digital transformation, and building a more sustainable future for its clients and communities. With a presence in over 120 countries, Accenture is known for its expertise in integrating cutting-edge solutions that address complex business challenges.