Senior Manager - Incident Response (CPX)

CPX

Abu Dhabi

On-site

AED 180,000 - 240,000

Full time

23 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

CPX is seeking a Senior Manager to lead the Incident Response & Forensics Team in a high-impact cyber defence environment. You will own people management, coordinate crisis response, and drive investigations, reporting, and remediation for an on-site VIP customer.

You will oversee DFIR lab activities, lead threat hunts, and work across sub-entities to ensure effective incident handling and service improvements. Strong leadership with hands-on forensic expertise is essential.

Qualifications

  • 10+ years in IT security or security infrastructure.
  • At least 6 years in a security role within an incident response team (CERT, CSIRT).
  • 4 years of incident response team management or equivalent.
  • Experience in digital forensics is a MUST.
  • Strong English language skills, both spoken and written.
  • Bachelor’s / Master in CS or InfoSec desirable, but not mandatory.

Responsibilities

  • Take ownership of a team executing defensive security projects for a VIP customer.
  • Lead IR and forensic engagements and incident response leadership.
  • Coordinate host and network forensics across platforms.
  • Draft detailed reports and technical briefs for VIP on-site client.
  • Develop talent and lead continuous service improvements within the DFIR team.
  • Coordinate threat hunting and SOC activities in support of incident response.

Skills

Blue team operations
Threat hunting
Digital forensics
Network protocols (TCP/IP)
Windows
Linux/OSX
IT security infrastructure
Forensic skills across OS
PICERL/NIST IR standards

Education

Bachelor’s / Master in CS or InfoSec
Certifications: CISSP, GCIH, GCFA, GNFA, GCFE, OSCP, GREM, GDAT

Tools

PICERL
NIST IR standards
Forensic tools

Job description

Overview

-As a Senior Manager of the Incident Response & Forensics Team within a high-impact and operationally critical cyber defence environment, you live and breathe blue team operations. Your technical expertise in digital forensics and cyber incident response is second only to your integrity and passion for cyber security and technology in general.

In addition to the technical execution and oversight you will also own people management.

We want a leader with a strong technical understanding of how to respond to cyber-attacks and assist organisations with remediation and recovery. You must be able to execute technical assessments and incident response activities as a coordinator and main escalation point for crisis management as well as key decision maker. In this role you will be expected to get your hands dirty, from analysis tasks to emergency situations at critical industries.

Responsibilities
  • Take ownership and oversight of a team who executes all aspects of reactive & proactive defensive security projects, including a DFIR Lab, for one on-site VIP customer
  • Perform the required duties of the Incident Response and Forensic Team’s Senior Manager (both people management and operational management duties)
  • Serve as technical lead on active incident response engagements across different sub-entities for this one VIP customer. Lead and execute the coordination, investigation and resolution of large-scale incidents following industry standard processes e.g. 800-61 r2 PICERL in a calm and methodical manner utilizing your strong technical skills
  • Execute, coordinate and lead threat hunting activities in support of incident response, as well as proactive environment assessments and SOC activities
  • Provide subject matter expertise in the threat detection and cyber defence domains
  • Take ownership of the DFIR Lab & service for this VIP on-site customer, contributing significantly in a leadership capacity, to process documentation and continuous service improvement activities
  • Lead and coordinate host and/or network-based forensics across various platforms
  • Lead and coordinate digital systems and mobile forensic investigations supporting cyber incident response engagements
  • Lead and coordinate the drafting of detailed reports and technical briefs, effectively communicating tasks, methodology and guidance to VIP on-site customer
  • Use your ability to stay calm and grounded in highly challenging situations to instil trust within client stakeholders; explain technical findings in a manner that can be easily understood by technical and non-technical stakeholders
  • Demonstrate industry thought leadership through internal brown-bag knowledge sharing sessions, coordinate the team’s topics for such sessions
  • Develop talent within the team by providing constructive and positive direction and support to achieve targets, build capabilities, and take on challenging DFIR & research projects
  • Lead research activities in search of service improvement tasks and better understanding of threat landscape.
  • lead and nurture a team culture built on trust, respect, appreciation, flexibility, and unity
  • Flexible schedule that is open to changing situations and opportunities, as with any position that is related to Incident Response
  • You must be a team player, with a humble and approachable nature who is willing to go the extra mile.
  • Ability to make an impact already after the initial couple of weeks of adapting into the new environment. Flexible schedule that is open to work in shifts (as per the team’s schedule) as well as changing situations and opportunities. There will be no working shift for this position, but the team’s shifts shall rotate from 6AM to 2PM and from 2PM to 10PM in a monthly basis, as a requirement to work for this important VIP on-site client, including on-call rotation as well of one week duration once every 2 months.
Technical Skills
  • Expert understanding of blue team operations and threat hunting
  • Deep understanding of digital forensics methodologies as well as usage of various tools
  • Expert understanding of network protocols, TCP/IP etc.
  • Expert understanding of network forensic principles and applications
  • Expert understanding of Microsoft Windows
  • Strong understanding of Linux and OSX
  • Expert understanding of enterprise IT and IT Security infrastructure. You will use this knowledge to lead strategic recommendations to customers, with the help of the DFIR Team, and ensure the best remediation of the managed incidents
  • Strong forensic skills across multiple operating systems
  • Proven experience performing duties utilising PICERL / NIST IR standards
Qualifications
  • Strong attention to detail and reporting accuracy
  • Strong English language skills, both spoken and written
  • Minimum 10 Years dedicated to IT security, and/or security infrastructure experience
  • At least 6 years in a security role as part of an incident response team (CERT, CSIRT), including 4 years managing incident response teams, or equivalent blue teams (e.g. defence consulting, SOC, )
  • Previous experience performing digital forensics is A MUST
  • Scripting skills (Shell, Python, PowerShell) are a plus
  • Must have at least three of the following certifications, CISSP, GCIH, GCFA, GNFA, GCFE, OSCP, GREM, GDAT or equivalent certifications as well as experience in the relevant domains
  • Bachelor’s / Master’s degree in computer science or information security desirable, but not mandatory. Experience in a similar position is still the most important factor.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager - Incident Response (CPX)
Senior Manager - Incident Response (CPX)

Showcify • Abu Dhabi

On-site
AED 400,000 - 700,000
Senior Manager - Incident Response CPX
Senior Manager - Incident Response CPX

CPX • Abu Dhabi

On-site
AED 350,000 - 650,000
Senior Consultant - Incident Response CPX
Senior Consultant - Incident Response CPX

CPX • Abu Dhabi

On-site
AED 300,000 - 480,000
Senior Incident Response & Forensics Manager VIP Lead
Senior Incident Response & Forensics Manager VIP Lead

CPX • Abu Dhabi

On-site
AED 350,000 - 650,000
Senior Manager – Incident Response
Senior Manager – Incident Response

Forensic Focus Limited • Abu Dhabi

On-site
AED 400,000 - 700,000
Security Engineer DFIR Lab
Security Engineer DFIR Lab

CPX • Abu Dhabi

On-site
AED 300,000 - 540,000
Incident Response & Digital Forensics Lead
Incident Response & Digital Forensics Lead

Showcify • Abu Dhabi

On-site
AED 400,000 - 700,000
DFIR Analyst
DFIR Analyst

CyberGate Defense • Abu Dhabi

On-site
AED 150,000 - 200,000
Senior Incident Response Lead - Forensics & Threat Hunting
Senior Incident Response Lead - Forensics & Threat Hunting

CPX • Abu Dhabi

On-site
AED 300,000 - 480,000
Specialist Cybersecurity Analyst (Emirati Talent)
Specialist Cybersecurity Analyst (Emirati Talent)

EDGE • Abu Dhabi

On-site
AED 180,000 - 260,000