We are seeking a highly skilled and proactive Senior Threat Detection Engineer to join our cybersecurity team. This role is responsible for designing, developing, and continuously improving threat detection capabilities across the organization’s security monitoring platforms. The ideal candidate will have strong hands-on experience in SIEM engineering, detection logic development, and security monitoring tools such as EDR and NDR, with a particular preference for expertise in QRadar.
You will play a critical role in strengthening the organization’s ability to detect, analyze, and respond to advanced cyber threats by building high-quality detection use cases, optimizing alerting mechanisms, and supporting threat hunting initiatives.
Key Responsibilities
1. SIEM Use Case Design & Implementation
Design, develop, and deploy advanced detection use cases within the SIEM platform to identify potential security threats and anomalies.
Translate threat intelligence, attack techniques, and business risks into actionable detection logic.
Ensure use cases align with frameworks such as MITRE ATT&CK and industry best practices.
Continuously review and enhance existing SIEM content to maintain effectiveness against evolving threats.
2. Correlation Searches & Alert Engineering
Develop and maintain correlation rules, searches, and alerting logic to identify multi-stage attacks and complex threat scenarios.
Create meaningful alert conditions that provide actionable insights to SOC analysts.
Establish thresholds, baselines, and behavioral analytics to improve detection accuracy.
Ensure alerts are properly enriched with contextual data to facilitate faster investigation and response.
3. Detection Engineering Across Security Tools (EDR, NDR, etc.)
Build and tune detection use cases across endpoint and network monitoring tools such as EDR and NDR platforms.
Integrate telemetry from multiple sources to enhance visibility and detection coverage.
Collaborate with engineering teams to onboard new data sources into the SIEM and other monitoring tools.
Optimize detection strategies across different layers (endpoint, network, application).
4. Alert Tuning & False Positive Reduction
Continuously analyze and tune alerts to minimize false positives and reduce alert fatigue within the SOC.
Conduct root cause analysis of noisy alerts and implement improvements to detection logic.
Balance sensitivity and accuracy to ensure high-fidelity alerts without missing critical threats.
Maintain documentation of tuning activities and improvements for audit and knowledge sharing.
5. Threat Hunting Support
Collaborate with threat hunting teams to develop hypotheses and detection strategies based on emerging threats.
Convert threat hunting findings into scalable detection use cases.
Analyze logs and telemetry data to identify indicators of compromise (IOCs) and suspicious behavior.
Support proactive threat detection initiatives to uncover hidden threats within the environment.
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in Saudi Arabia.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in Saudi Arabia, connecting you to thousands of jobs fast!
Find the best jobs in Saudi Arabia, apply in 1 click and get a job today!