Tabbio
Login to App
yesterday

Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

CCDS · Riyadh, Riyadh Province, Saudi Arabia
WorkableApply on company site
Full Time
Onsite

Role overview

Location: On-site – Riyadh, Saudi Arabia Contract/engagement: Project-based managed cybersecurity services (13-month) Minimum experience: 7+ years

Role Purpose Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.

Key Responsibilities · Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets. · Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities. · Collect, preserve, and analyze digital evidence in accordance with approved chain-of-custody procedures. · Conduct disk, memory, network, endpoint, and malware analysis using appropriate forensic tools. · Develop and maintain incident-response and DFIR procedures, playbooks, investigation methods, and evidence-handling guides. · Prepare technical and executive incident reports, forensic findings, and RCA reports. · Coordinate with internal teams and stakeholders and ensure incident classification and reporting comply with NCA requirements.

Requirements Technical and Professional Requirements · Saudi nationality is a must. · Bachelor’s degree in Cybersecurity, Digital Forensics, Computer Science, or a related field. · At least 7 years of experience in cyber incident response and digital forensic investigations. · Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK. · Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools. · Strong understanding of digital evidence handling and chain of custody.

Personal Requirements · Calm and decisive during high-pressure incidents. · Strong investigative thinking, attention to detail, and professional judgment. · Clear technical writing and the ability to communicate findings to both executives and technical teams. · High integrity and strict respect for confidentiality.

Professional Certifications Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.

Responsibilities

1Location: On-site – Riyadh, Saudi Arabia
2Contract/engagement: Project-based managed cybersecurity services (13-month)
3Minimum experience: 7+ years
4Role Purpose
5Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.
6Key Responsibilities
7· Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets.
8· Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities.

Requirements

1Technical and Professional Requirements
2· Saudi nationality is a must.
3· Bachelor’s degree in Cybersecurity, Digital Forensics, Computer Science, or a related field.
4· At least 7 years of experience in cyber incident response and digital forensic investigations.
5· Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK.
6· Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools.
7· Strong understanding of digital evidence handling and chain of custody.
8Personal Requirements
9· Calm and decisive during high-pressure incidents.
10· Strong investigative thinking, attention to detail, and professional judgment.
11· Clear technical writing and the ability to communicate findings to both executives and technical teams.
12· High integrity and strict respect for confidentiality.
13Professional Certifications
14Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.

Skills and tags

SACybersecurityCompliance

Claim your tabbio link
before it's taken