S
Network & Security Team Lead (SME)
Riyadh, Riyadh Province, Saudi Arabia · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- há 1 hora
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Job description
Role Overview
We are recruiting on behalf of a premier IT partner in Saudi Arabia managing a critical large-scale monitoring initiative for a major governmental organization. The position sought is for a Network & Security Team Lead and Subject Matter Expert (SME), responsible for providing both leadership and expert technical oversight of the Network & Security monitoring division.
Key Responsibilities
- Take complete ownership of the Network & Security monitoring tower, ensuring comprehensive coverage of all connectivity and security facets.
- Conduct advanced diagnosis and root cause analysis for network and security incidents.
- Lead incident containment efforts and manage digital evidence related to cybersecurity events.
- Act as the escalation authority for Priority 1 (Critical) and Priority 2 (High) incidents, managing all aspects of incident escalation.
- Coordinate Major Incident Management activities, including technical bridge facilitation and validation of change readiness for network/security updates.
- Analyze false positive rates from security and network monitoring tools to recommend tuning improvements.
- Lead knowledge transfer initiatives and ensure quality of runbooks and Standard Operating Procedures (SOPs) for the monitoring team.
- Support the Operations Manager with technical risk assessments and operational decision-making.
- Serve as the escalation point during after-hours per the on-call schedule.
- Review recurring incidents and drive problem management and root cause documentation within the tower.
Incident Escalation Duties
- Priority 1 (Critical): Immediate engagement as tower lead; join incident bridge within 5 minutes and direct technical remediation under major incident management.
- Priority 2 (High): Assume ownership within 15 minutes of assignment; execute diagnosis, evaluate business impact, and escalate to Operations Manager as warranted.
- Priority 3 and 4: Manage runbook adherence and handle tower backlog in routine operations.
Required Technical Expertise
- Extensive hands-on skills with firewall technologies such as Palo Alto, Fortinet, and Cisco ASA.
- Experience with SIEM platforms including Splunk, QRadar, and ArcSight plus handling security event triage.
- Strong proficiency in network protocols, routing, switching, and VPN solutions.
- Practical knowledge of incident containment procedures and digital evidence management related to cybersecurity events.
- Understanding of Major Incident Management workflows and technical bridge coordination.
- Experience adjusting monitoring tools to minimize false positives.
- Capability to create and validate runbooks and SOPs for monitoring teams.
Candidate Profile
- Proven background in senior network or security engineering roles or leadership positions.
- Demonstrated ability to independently manage incidents end-to-end and steer technical responses under pressure.
- Availability for a consistent morning shift schedule with responsibility for on-call duties beyond working hours.
- Relevant professional certifications such as CCNP, CCIE, Security+, CEH, or CISSP are highly desirable.
- Fluent command of English language; Arabic language skills are an asset.