Manager - Tech Consulting - Cyber Automation, Detection Engineering / AI - Riyadh
Job description
Role Summary
We are seeking experienced Managers Autonomous SOC Engineering, AI & Automation to lead the design, engineering, deployment, and continuous improvement of next-generation Security Operations capabilities.
The role will be responsible for enabling the transition from traditional analyst-led SOC operations toward an AI-assisted and increasingly autonomous SOC operating model, combining security automation, AI/GenAI, detection engineering, orchestration, and advanced security analytics.
The successful candidates will be technically hands-on and will work across SIEM, SOAR, EDR/XDR, threat intelligence, case management, APIs, AI/LLM platforms, and security data sources to automate security workflows, develop use cases and improve detection quality, accelerate investigations and response, and reduce repetitive analyst effort.
The role requires strong experience across automation engineering, AI-enabled security operations, and detection engineering, with the ability to translate SOC use cases into scalable production capabilities.
Key Responsibilities
Autonomous SOC & AI Engineering
* Lead the technical design and deployment of AI-driven and autonomous SOC capabilities.
* Identify SOC processes suitable for automation and autonomous execution across alert triage, investigation, enrichment, containment, and response.
* Design and implement AI-assisted security investigation and decision-support workflows.
* Develop and integrate LLM/GenAI-based SOC capabilities, including analyst copilots, automated investigation, incident summarisation, threat intelligence analysis, and response recommendations.
* Design appropriate human-in-the-loop controls, approval gates, guardrails, and escalation mechanisms for autonomous security actions.
* Evaluate the accuracy, reliability, security, and operational effectiveness of AI-enabled SOC use cases.
* Support the development of an Autonomous SOC roadmap and progressively increase the level of automation across security operations.
Security Automation & Orchestration
* Design, build, and maintain automated security workflows and orchestration playbooks.
* Automate repetitive SOC activities including:
* Alert enrichment
* IOC investigation
* Phishing analysis
* Endpoint investigation
* Identity investigation
* Threat intelligence enrichment
* Malware analysis
* Case creation and management
* Containment and remediation
* Develop integrations between SIEM, SOAR, EDR/XDR, threat intelligence, email security, identity, network security, cloud security, ticketing, and other security platforms.
* Build automation using Python, REST APIs, webhooks, SDKs, scripting, and orchestration platforms.
* Develop reusable automation components and standardized integration patterns.
* Implement error handling, logging, monitoring, testing, and rollback mechanisms for automated security actions.
Detection Engineering
* Lead the development and continuous improvement of the SOC’s detection engineering capability.
* Design, develop, test, tune, and maintain security detection rules across SIEM, EDR/XDR, cloud, identity, network, and other security technologies.
* Translate threat intelligence, attack techniques, incident findings, and threat hunting results into actionable detections.
* Map detection coverage against MITRE ATT&CK and identify detection gaps.
* Develop detection-as-code approaches including version control, testing, peer review, deployment, and lifecycle management.
* Define detection quality metrics including precision, false-positive rates, coverage, and detection effectiveness.
* Work with automation engineers to connect detections directly to automated investigation and response workflows.
AI & Security Data Integration
* Integrate security telemetry from multiple platforms into AI-driven investigation and automation workflows.
* Develop mechanisms for AI systems to securely retrieve and correlate relevant security context.
* Design structured prompts, workflows, agent logic, and tool integrations for security use cases.
* Support integration of enterprise knowledge sources, threat intelligence, historical incidents, detection content, and SOC procedures into AI-enabled workflows.
* Apply appropriate security controls around data privacy, access control, model usage, auditability, and AI-generated decisions.
* Monitor AI outputs for hallucinations, incorrect conclusions, unsafe actions, and other operational risks.
SOC Engineering & Continuous Improvement
* Assess existing SOC processes and identify opportunities to improve efficiency through engineering and automation.
* Reduce manual analyst workload and improve mean time to detect, investigate, and respond.
* Establish engineering standards for automation, integrations, detection content, and AI-enabled workflows.
* Conduct testing and validation before deploying automated response actions into production.
* Track the effectiveness of Autonomous SOC capabilities through measurable operational KPIs.
* Mentor SOC analysts and engineers on automation, detection engineering, AI-assisted investigations, and new security technologies.
* Work with SOC leadership, architecture, infrastructure, cloud, IAM, and security engineering teams to deliver integrated capabilities.
Required Skills & Experience
Candidates should have strong hands-on experience across several of the following areas:
* 7+ years of cybersecurity experience, with significant experience in SOC engineering, detection engineering, security automation, incident response, or security operations.
* Strong hands-on experience with SIEM technologies such as Microsoft Sentinel, Splunk ES, Google SecOps or equivalent.
* Strong experience with SOAR and security orchestration platforms.
* Experience developing security automation using Python and REST APIs.
* Strong understanding of SOC workflows, alert triage, investigation and incident response.
* Demonstrated experience designing and engineering security detections.
* Strong knowledge of MITRE ATT&CK and threat-informed defence.
* Experience integrating security platforms through APIs and developing automated investigation or response workflows.
* Experience with EDR/XDR, identity security, email security, network security, cloud security, and threat intelligence platforms.
* Understanding of detection lifecycle management, detection-as-code, Git/version control, CI/CD, and automated testing.
AI / GenAI Experience
Strong knowledge or practical experience in:
* Generative AI and Large Language Models.
* AI agents and agentic workflows.
* LLM APIs and enterprise AI platforms.
* Prompt and context engineering.
* Retrieval-Augmented Generation (RAG).
* Tool/function calling and API-enabled AI agents.
* AI-assisted investigation and security analytics.
* AI evaluation, accuracy testing, hallucination management, and guardrails.
* Secure implementation of AI within enterprise cybersecurity environments.
Candidates do not need to be machine-learning researchers, the emphasis is on applying AI practically within security operations.
Preferred Experience
Experience with technologies such as:
* Microsoft Sentinel / Security Copilot
* Splunk ES / Splunk SOAR
* Cortex XSOAR / XSIAM
* Microsoft Defender XDR
* CrowdStrike
* ServiceNow SecOps
* Threat intelligence platforms
* Git / GitLab / GitHub
* Python
* REST APIs
* Azure OpenAI / OpenAI APIs or equivalent enterprise LLM platforms
* Cloud security platforms across Azure, AWS or GCP
Experience building or deploying AI-enabled SOC, Autonomous SOC, hyperautomation, or security-agent solutions would be highly advantageous.
Expected Outcomes
The role will be expected to deliver measurable improvements including:
* Increased percentage of SOC activities automated.
* Reduced manual analyst intervention.
* Improved detection coverage and quality.
* Reduced false-positive rates.
* Reduced Mean Time to Triage and Mean Time to Respond.
* Increased automated enrichment and investigation coverage.
* Deployment of AI-assisted and autonomous investigation workflows.
* Increased integration between detection, investigation, and automated response.