
Manager - Tech Consulting - Cyber Automation, Detection Engineering / AI - Riyadh
Ernst and Young1 day ago
Riyadh, Saudi ArabiaStaff+
Responsibilities
- Lead the technical design, deployment, and continuous improvement of AI-driven and autonomous SOC capabilities.
- Identify and automate SOC processes covering alert triage, investigation, enrichment, containment, remediation, and response.
- Develop LLM/GenAI-based analyst copilots, investigation workflows, incident summaries, threat intelligence analysis, and response recommendations.
- Design human-in-the-loop controls, approval gates, guardrails, escalation mechanisms, and operational safeguards for autonomous security actions.
- Build and maintain security automation workflows, orchestration playbooks, reusable integration components, and standardized integration patterns.
- Integrate SIEM, SOAR, EDR/XDR, threat intelligence, email, identity, network, cloud security, ticketing, and other security platforms.
- Lead detection engineering, including designing, testing, tuning, maintaining, and lifecycle-managing detections across security technologies.
- Map detection coverage to MITRE ATT&CK, define detection quality metrics, and connect detections to automated investigation and response workflows.
- Integrate security telemetry and enterprise knowledge sources into secure AI-driven investigation and automation workflows.
- Establish engineering standards, conduct production validation, track operational KPIs, and mentor SOC analysts and engineers.
Requirements
- At least 7 years of cybersecurity experience, including significant experience in SOC engineering, detection engineering, security automation, incident response, or security operations.
- Hands-on experience with SIEM technologies such as Microsoft Sentinel, Splunk ES, Google SecOps, or equivalent platforms.
- Strong experience with SOAR and security orchestration platforms.
- Experience developing security automation with Python and REST APIs.
- Strong understanding of SOC workflows, alert triage, investigation, and incident response.
- Demonstrated experience designing and engineering security detections, with strong knowledge of MITRE ATT&CK and threat-informed defense.
- Experience integrating security platforms through APIs and developing automated investigation or response workflows.
- Experience with EDR/XDR, identity security, email security, network security, cloud security, and threat intelligence platforms.
- Understanding of detection lifecycle management, detection-as-code, Git/version control, CI/CD, and automated testing.
- Practical knowledge of generative AI, large language models, AI agents, agentic workflows, LLM APIs, prompt and context engineering, RAG, tool/function calling, AI evaluation, hallucination management, and guardrails.
- Experience securely implementing AI within enterprise cybersecurity environments.
- Experience with AI-enabled SOC, Autonomous SOC, hyperautomation, or security-agent solutions is preferred.
- Preferred experience includes Microsoft Sentinel, Security Copilot, Splunk ES, Splunk SOAR, Cortex XSOAR, Cortex XSIAM, Microsoft Defender XDR, CrowdStrike, ServiceNow SecOps, Git, GitLab, GitHub, Azure OpenAI, OpenAI APIs, and Azure, AWS, or GCP cloud security platforms.
About Ernst and Young
Ernst & Young (EY) provides audit/assurance, tax, consulting, strategy and transactions services to enterprises, financial institutions, and public‑sector clients. Structured as a global network of partner‑owned member firms, it sells professional services on a fee basis, including a dedicated Financial Services Organization for banking, insurance, and capital markets. Headquartered in London, EY was formed in 1989 from the merger of Ernst & Whinney and Arthur Young, and operates in 150+ countries.