- Location
- Riyadh, KAFD 3.09, Saudi Arabia
- Workplace
- Onsite
- Type
- Full-time
- Department
- Transportation
- Closing date
- Today
- Source
- Workday
Description
As a Security Delivery Specialist, you will act as a subject-matter expert across Security Operations, Incident Response, SIEM, Endpoint Detection and Response, and Network Detection and Response. You will lead complex security investigations, enhance detection capabilities, administer critical security platforms and guide team members in delivering effective cybersecurity operations.
You will work with security engineering, infrastructure, network and business stakeholders to continuously improve cyber defense processes, technologies and reporting.
What You’ll Do
Incident Response & SOC Operations
- Develop, maintain and continuously improve Incident Response plans, SOC policies, processes, procedures and operational playbooks.
- Lead the detection, triage, investigation, containment and response to complex cybersecurity events and incidents.
- Analyze security events and telemetry to determine their nature, scope, severity and potential business impact.
- Provide technical direction and guidance to team members throughout investigations and response activities.
- Coordinate escalations and ensure incidents are handled according to established procedures and service requirements.
- Participate in on-call and after-hours security support when required.
- Identify lessons learned from security incidents and translate them into improvements across people, process and technology.
SIEM & Detection Engineering
- Work closely with SIEM engineers and other cybersecurity teams to develop, refine and optimize security-monitoring use cases.
- Create and tune correlation and detection rules using telemetry from SIEM, EDR, NDR and other security technologies.
- Analyze alerts, logs and security events to identify malicious activity, behavioral anomalies and emerging threats.
- Review existing detection logic and recommend improvements to increase detection effectiveness and reduce false positives.
- Identify monitoring gaps and support the development of new detection scenarios.
- Support the integration of EDR, NDR and other security platforms with enterprise SIEM technologies.
EDR Administration
- Administer and optimize enterprise Endpoint Detection and Response technologies.
- Deploy, upgrade and maintain EDR agents across Windows, macOS and Linux environments.
- Monitor agent health, coverage and connectivity, and troubleshoot endpoints that are not reporting correctly.
- Develop, implement and maintain EDR policies and configurations.
- Integrate EDR platforms with SIEM and other cybersecurity technologies.
- Review EDR configurations periodically and recommend enhancements to improve endpoint security coverage and detection capabilities.
- Manage platform-related support tickets and coordinate with technology vendors through resolution.
NDR Administration
- Administer and optimize enterprise Network Detection and Response technologies.
- Develop, implement and maintain NDR policies, configurations and monitoring rules.
- Integrate NDR platforms with SIEM and the broader security technology ecosystem.
- Develop and maintain custom correlation rules using EDR, NDR and other security telemetry.
- Monitor platform health and troubleshoot technical, connectivity and reporting issues.
- Periodically assess existing NDR configurations and recommend improvements to enhance network visibility and threat detection.
- Manage technical support cases with NDR vendors and follow identified issues through to resolution.
Cyber Intelligence, Reporting & Leadership
- Produce clear, actionable cyber intelligence, incident and operational reports.
- Communicate technical findings, security risks, business impact and recommended actions to varied audiences.
- Present complex cybersecurity matters clearly to information security teams, non-technical business representatives and senior management.
- Provide technical leadership, coaching and knowledge-sharing to cybersecurity team members.
- Collaborate across SOC, security engineering, infrastructure, network, application and business teams.
- Support continuous improvement initiatives that strengthen the overall maturity and effectiveness of security operations.
What You’ll Need
- Strong experience in Security Operations and Incident Response.
- Demonstrated experience developing or maintaining Incident Response plans, SOC policies, processes, procedures and playbooks.
- Hands-on experience using security tools and technologies for detection, investigation and response.
- Strong knowledge of Security Information and Event Management technologies.
- Experience developing, refining and tuning SIEM correlation or detection rules.
- Hands-on experience administering enterprise EDR and NDR platforms.
- Experience deploying and maintaining EDR agents across Windows, macOS and Linux.
- Experience integrating EDR and NDR platforms with SIEM and other security technologies.
- Strong understanding of security-event analysis, alert triage, incident investigation and response.
- Strong analytical, troubleshooting and organizational capabilities.
- Ability to lead technical investigations and provide clear guidance to team members.
- Excellent verbal and written communication skills.
- Ability to communicate both technical and strategic cybersecurity matters to diverse audiences.
- Strong documentation, cyber intelligence reporting and stakeholder-management capabilities.
- Ability to participate in on-call or after-hours support when required.
Bonus Points If You Have
- GIAC Certified Incident Handler (GCIH)
- GIAC Continuous Monitoring Certification (GMON)
- GIAC Certified Forensic Analyst (GCFA)
- Equivalent certifications in Incident Response, SOC operations, digital forensics or security monitoring.
- Experience supporting a large-scale enterprise or Managed Security Services environment.
- Exposure to threat hunting, cyber threat intelligence or digital forensics.
- Familiarity with MITRE ATT&CK and detection-engineering methodologies.
- Experience with platforms such as Splunk, Microsoft Sentinel, IBM QRadar, Microsoft Defender or CrowdStrike.
About Accenture
Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.Visit us at www.accenture.com
Equal Employment Opportunity Statement
We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, sexual orientation, gender identity or expression, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.