Senior Incident Response Specialist

Help AG, an e& enterprise company

Abu Dhabi

On-site

AED 279,000 - 446,400

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Career progression
Learning and development
Flexible working
Open door policy

Job summary

Help AG is seeking an Incident Response Specialist to identify, analyze, contain, and respond to cybersecurity incidents across the enterprise. The role involves coordinating IR activities, conducting forensic investigations, and working with stakeholders to minimize business impact while enhancing cyber resilience.

You will monitor alerts, lead technical investigations, perform real-time incident handling, and prepare executive summaries and post-incident reports.

Qualifications

  • Minimum 2–4 years in cybersecurity with 3+ years in incident response/SOC.
  • Proven IR lifecycle experience: preparation to post-incident reviews.
  • Hands-on with SIEM, EDR, logs, and threat hunting.

Responsibilities

  • Monitor security alerts from SIEM/EDR/IDS-IPS and firewalls.
  • Lead investigations and coordinate incident response across teams.
  • Perform containment, eradication, and recovery during incidents.
  • Forensic evidence collection and malware analysis with chain of custody.

Skills

Incident response
SOC operations
Digital forensics
Threat intelligence
ELK/SIEM analysis
EDR expertise
MITRE ATT&CK
Log analysis
Scripting (PowerShell/Python/Bash)
Reporting & communication

Education

Bachelor's degree in Computer Science or related field

Tools

Microsoft Defender for Endpoint
CrowdStrike Falcon
QRadar / Splunk / Sentinel
ArcSight

Job description

Job Description

Help AG is looking for a talented and experienced Incident Response Specialist who will be responsible for identifying, analyzing, containing, investigating, and responding to cybersecurity incidents across the enterprise. The role involves coordinating incident response activities, conducting forensic investigations, analyzing security events, and working closely with internal stakeholders to minimize business impact while enhancing the organization's cyber resilience.

Responsibilities
  • Monitor and investigate security alerts generated by SIEM, EDR, IDS/IPS, firewalls, and other security tools.
  • Perform cyber incident triage by determining severity, scope, urgency, and business impact.
  • Lead technical investigations and coordinate incident response activities across multiple teams.
  • Execute containment, eradication, and recovery activities during cyber incidents.
  • Perform real-time incident handling, forensic evidence collection, malware analysis, and threat correlation.
  • Collect and preserve digital evidence following forensic best practices.
  • Analyze host, network, firewall, IDS/IPS, and application logs to identify attack patterns.
  • Perform malware analysis and identify Indicators of Compromise (IOCs).
  • Investigate compromised systems and recommend remediation measures.
  • Maintain complete incident records from detection through closure.
  • Prepare incident reports, executive summaries, and post-incident ("After Action") reports.
  • Develop technical guidance, incident response playbooks, and standard operating procedures.
  • Coordinate with Threat Intelligence teams to validate threats and enrich investigations.
  • Monitor external threat intelligence feeds and emerging cyber threats.
  • Recommend proactive improvements to security controls based on investigation findings.
  • Collaborate with infrastructure, application, SOC, legal, and business teams during incidents.
  • Support vendor evaluations and provide technical input into cybersecurity solutions.
  • Participate in developing technical specifications, RFPs, and SLAs.
Qualifications & Skills
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Technology, Computer Engineering, or a related discipline.
  • Minimum 2–4 years of experience in Cybersecurity, with at least 3 years specializing in Incident Response, Security Operations Center (SOC), or Cyber Defense.
  • Proven experience in managing the complete Incident Response lifecycle, including preparation, detection, analysis, containment, eradication, recovery, and post-incident reviews.
  • Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, ArcSight, or equivalent for security monitoring, log analysis, and incident investigation.
  • Strong expertise in Endpoint Detection and Response (EDR) solutions, including Microsoft Defender for Endpoint, CrowdStrike Falcon, Carbon Black, SentinelOne, or similar technologies.
  • Experience conducting digital forensic investigations, evidence collection, malware analysis, and root cause analysis while maintaining forensic integrity and chain of custody.
  • Solid understanding of cyber threat intelligence concepts, attacker tactics, techniques, and procedures (TTPs), with practical application of the MITRE ATT&CK Framework.
  • Proficiency in analyzing security logs from multiple sources, including operating systems, applications, network devices, cloud platforms, and security appliances to identify Indicators of Compromise (IOCs).
  • Working knowledge of scripting and automation using PowerShell, Python, or Bash to support investigations, automate repetitive tasks, and enhance incident response processes.
  • Preferred Certifications: Security+, CEH, CISSP, GICSP, CCNA Security, or equivalent (not mandatory but an advantage).
  • Strong analytical, problem-solving, and decision-making skills with the ability to perform effectively under pressure during critical cybersecurity incidents.
  • Excellent communication, stakeholder management, and report-writing skills, with the ability to prepare technical investigation reports, executive summaries, and post-incident recommendations, while collaborating effectively with cross-functional teams and external vendors.
  • Excellent written and verbal communication skills in English & Arabic.
Benefits
  • Career progression and growth through challenging projects and work.
  • Employee engagement and wellness campaigns activities throughout the year.
  • Excellent learning and development opportunities.
  • Inclusive and diverse working environment.
  • Flexible working environment.
  • Open door policy.
About Us

Help AG is the cybersecurity arm of e& enterprise (formerly Etisalat Digital) and provides leading enterprise businesses and governments across the Middle East with strategic consultancy combined with tailored information security services and solutions that address their diverse requirements, enabling them to evolve securely with a competitive edge. Present in the Middle East since 2004, Help AG was strategically acquired by e& (formerly Etisalat Group) in Feb 2020, hence creating a cybersecurity and digital transformation powerhouse in the region. Help AG has firmly established itself as the region's trusted IT security advisor by remaining vendor-agnostic, trustworthy, independent, and cybersecurity focused. With best-of-breed technologies from industry-leading vendor partners, expertly qualified service delivery teams and a state-of-the-art consulting practice, Help AG delivers unmatched value to its customers by strengthening their cyber defenses and safeguarding their business.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Support Technician
IT Support Technician

Help AG, an e& enterprise company • Dubai

Hybrid
AED 90,000 - 130,000
Health insurance
Career progression
Wellness campaigns and activities
+3
FortiSOAR Specialist
FortiSOAR Specialist

Help AG, an e& enterprise company • Dubai

Hybrid
AED 360,000 - 600,000
Health insurance
Annual flight tickets to home country
Flexible/Hybrid working environment
+1
Senior Infrastructure Engineer
Senior Infrastructure Engineer

Help AG, an e& enterprise company • Dubai

Hybrid
AED 390,600 - 725,400
Health insurance
Career progression
Wellness campaigns
+4
OT Senior Security Engineer
OT Senior Security Engineer

Help AG, an e& enterprise company • Abu Dhabi

On-site
AED 25,000 - 45,000
IT Support Technician
IT Support Technician

Help AG • Abu Dhabi

Hybrid
AED 60,000 - 90,000
Health insurance
Career progression
Wellness campaigns
+5
Senior Security Engineer – NGFW & DDOS
Senior Security Engineer – NGFW & DDOS

Help AG, an e& enterprise company • Dubai

Hybrid
Health insurance
Career progression through challenging projects
Annual flight tickets to home country
+2
Business Development Manager
Business Development Manager

Help AG, an e& enterprise company • Dubai

On-site
AED 257,069 - 330,517
Health insurance
Career progression
Flexible/Hybrid working environment
+2
Cyber Trust Advisory Consultant (UAE National)
Cyber Trust Advisory Consultant (UAE National)

Help AG, an e& enterprise company • Dubai

Hybrid
AED 100,000 - 140,000
Health insurance
Career progression
Wellness campaigns
+4
Web Developer & Digital Specialist (UAE National)
Web Developer & Digital Specialist (UAE National)

Help AG, an e& enterprise company • Dubai

Hybrid
AED 80,000 - 100,000
Health insurance
Career progression and growth
Flexible/Hybrid working environment
Help AG NextGen UAE Talent Program
Help AG NextGen UAE Talent Program

Help AG, an e& enterprise company • Dubai

Hybrid
AED 60,000 - 100,000
Health insurance
Career progression
Wellness campaigns
+4