Lead Consultant - Incident Response

CPX

Abu Dhabi

On-site

AED 300,000 - 540,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CPX is seeking a Principal Consultant – Incident Response to lead blue team operations and IR engagements in a fast-paced security environment. You will perform threat hunting, host and network forensics, and produce client-ready reports.

You will work with EDR/forensic tools across Windows, Linux, and macOS, collaborating closely with clients to strengthen defenses and reduce risk. A strong communicator with GIAC certs will excel.

Qualifications

  • 6+ years of work experience in incident response or blue team operations.
  • GIAC cert in GNFA, GCIH, GCIA, GCFE, GCFA or equivalent.
  • Experience with EDR and threat-hunting tools.
  • Strong reporting and communication skills.
  • Bachelor's degree in Computer Science or Engineering preferred.

Responsibilities

  • Serve as technical lead on active IR engagements and retainer customers.
  • Achieve tasks independently within the team after initial period.
  • Execute threat hunting activities to support IR and environment assessments.
  • Carry out host/network forensics across Windows, Linux, and macOS.
  • Produce detailed reports and technical briefs for customers.
  • Collaborate with customers to improve security posture.
  • Contribute to process documentation and continuous improvement.
  • Demonstrate thought leadership through internal knowledge sharing.

Skills

Blue team operations
Threat hunting
EDR tools
Network analysis
Forensics
ATT&CK framework
Windows
Linux/OSX
Log analysis
Malware analysis
Documentation
Independent work
Team collaboration

Education

Bachelor's degree in Computer Science or Engineering

Tools

EDR tools
Threat-hunting tools
Bro/Zeek
Rita
Suricata
Wireshark

Job description

Overview

As a Principal Consultant – Incident Response, you live and breathe blue team operations. Your technical expertise in endpoint and network threat detection and defence is complemented by your integrity and passion for cyber security and technology in general. You work well in a team of highly motivated and skilled blue teamers, but you can also achieve your work independently in different engagements and scenarios. You enjoy taking on new challenges in a fast paced and dynamic working environment. You are a team player who is always willing to help out where required, with a humble and positive attitude

Responsibilities
  • Serve as technical lead on active incident response engagements and across different IR Retainer customers
  • Achieve tasks independently within the team after initial 2-3 months
  • Execute threat hunting activities in support of incident response and proactive environment assessments
  • Carry out host-based assessments using EDR tools and network assessments utilizing full packet data to determine the extent and scope of possible compromise
  • Perform host and/or network-based forensics across Windows, Mac, and Linux platforms.
  • Execute digital forensic investigations supporting cyber incident response engagements
  • Contribute to process documentation and continuous service improvement activities
  • Collaboration with customers to enhance defensive security posture and existing security controls
  • Flexible schedule that is open to changing situations and opportunities
  • Produce detailed reports and technical briefs, effectively communicate tasks, methodology and guidance to customers
  • Explain technical findings in a manner that can be easily understood by technical and non-technical staff
  • Demonstrate industry thought leadership through blog posts, internal brown-bag sessions
  • You must be a team player, with a humble and approachable nature who is willing to go the extra mile
Qualifications
Technical Skills
  • Strong understanding of blue team operations and threat hunting
  • Sound understanding of network protocols, TCP/IP, etc.
  • Sound understanding of Microsoft Windows
  • Sound understanding of Linux and OSX
  • Sound forensic skills across multiple operating systems
  • Strong understanding of network analysis tools like Bro/Zeek, Rita, or Suricata
  • Ability to perform analysis of system and network devices logs
  • Sound understanding of the capabilities of static and dynamic malware analysis
  • Sound understanding of enterprise systems, technologies, and infrastructure
  • Strong understanding of targeted attacks and ability to create customized tactical and strategic remediation plans for compromised organizations
  • Strong understanding of current threats, vulnerabilities, and attack trends
  • Strong understanding of the ATT&CK framework
  • Excellent organizational skills, ability to prioritize, and ability to work independently
  • Any other responsibilities as required by the Line Manager
Skills/Certifications (Technical & Non-Technical)
  • Good attention to detail and reporting accuracy
  • English language skills, both spoken and written
  • GIAC Certified in a minimum of one discipline: GNFA, GCIH, GCIA, GCFE, GCFA, GDAT, etc. Or equivalent (eLearn Security, etc.)
  • Previous experience working with EDR tools and threat-hunting tools
  • Previous experience performing network forensics is desirable
  • Knowledge about cloud security infrastructure (AWS, Azure, Oracle, others) is desirable
  • Excellent organizational skills, ability to prioritize, and ability to work independently
  • Minimum Work Experience - 6 years
  • Education - Bachelor's degree in Computer Science or Engineering is desirable but not mandatory
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Consultant – Incident Response
Lead Consultant – Incident Response

Forensic Focus Limited • Abu Dhabi

On-site
AED 300,000 - 520,000
Senior Incident Response Lead — Threat Hunting & Forensics
Senior Incident Response Lead — Threat Hunting & Forensics

Forensic Focus Limited • Abu Dhabi

On-site
AED 300,000 - 520,000
Senior Incident Response Lead — Flexible Schedule
Senior Incident Response Lead — Flexible Schedule

CPX • Abu Dhabi

On-site
AED 300,000 - 540,000
Security Engineer (DFIR Lab)
Security Engineer (DFIR Lab)

CPX • Abu Dhabi

On-site
AED 180,000 - 300,000
DFIR Analyst
DFIR Analyst

CyberGate Defense • Abu Dhabi

On-site
AED 150,000 - 200,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

MEX Group • Dubai

On-site
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

EstateSight AI • Abu Dhabi

On-site
AED 330,000 - 441,000
Competitive salary
Professional development opportunities
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

Recenso • Abu Dhabi

On-site
AED 300,000 - 400,000
Security Operations Lead
Security Operations Lead

Good co India • United Arab Emirates

On-site
AED 350,000 - 750,000
Senior Consultant, Red Team, Google Cloud
Senior Consultant, Red Team, Google Cloud

Google • United Arab Emirates

On-site
AED 250,000 - 450,000