Location: On-site - Riyadh, Saudi Arabia
Contract/engagement: Project-based managed cybersecurity services (13-month)
Minimum experience: 7+ years
Role Purpose
Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.
Key Responsibilities
- Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets
- Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities
- Collect, preserve, and analyze digital evidence in accordance with approved chain-of-custody procedures
- Conduct disk, memory, network, endpoint, and malware analysis using appropriate forensic tools
- Develop and maintain incident-response and DFIR procedures, playbooks, investigation methods, and evidence-handling guides
- Prepare technical and executive incident reports, forensic findings, and RCA reports
- Coordinate with internal teams and stakeholders and ensure incident classification and reporting comply with NCA requirements
Requirements
Technical and Professional Requirements
- Saudi nationality is a must
- Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, or a related field
- At least 7 years of experience in cyber incident response and digital forensic investigations
- Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK
- Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools
- Strong understanding of digital evidence handling and chain of custody
Personal Requirements
- Calm and decisive during high-pressure incidents
- Strong investigative thinking, attention to detail, and professional judgment
- Clear technical writing and the ability to communicate findings to both executives and technical teams
- High integrity and strict respect for confidentiality
Professional Certifications
Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.