Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist
نبذة عن الوظيفة
Location: On-site – Riyadh, Saudi Arabia Contract/engagement: Project-based managed cybersecurity services (13-month) Minimum experience: 7+ years
Role Purpose Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.
Key Responsibilities · Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets. · Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities. · Collect, preserve, and analyze digital evidence in accordance with approved chain-of-custody procedures. · Conduct disk, memory, network, endpoint, and malware analysis using appropriate forensic tools. · Develop and maintain incident-response and DFIR procedures, playbooks, investigation methods, and evidence-handling guides. · Prepare technical and executive incident reports, forensic findings, and RCA reports. · Coordinate with internal teams and stakeholders and ensure incident classification and reporting comply with NCA requirements.
Requirements Technical and Professional Requirements · Saudi nationality is a must. · Bachelor’s degree in Cybersecurity, Digital Forensics, Computer Science, or a related field. · At least 7 years of experience in cyber incident response and digital forensic investigations. · Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK. · Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools. · Strong understanding of digital evidence handling and chain of custody.
Personal Requirements · Calm and decisive during high-pressure incidents. · Strong investigative thinking, attention to detail, and professional judgment. · Clear technical writing and the ability to communicate findings to both executives and technical teams. · High integrity and strict respect for confidentiality.
Professional Certifications Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.