Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

cloud consultancy - ccds

As Sudiyah

On-site

OMR 31,000 - 43,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

cloud consultancy - ccds in Riyadh, Saudi Arabia, seeks an experienced cybersecurity Incident Response Lead for a 13-month project-based engagement. You will direct investigations, preserve evidence, and report to executives with a focus on regulatory compliance.

The role requires 7+ years in IR and DFIR, strong knowledge of NIST/MITRE ATT&CK, and hands-on use of SIEM/EDR tools, EnCase, FTK, Volatility, and Autopsy. Saudi nationality is mandatory.

Qualifications

  • Saudi nationality is required.
  • Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, or related field.
  • 7+ years of experience in cyber incident response and digital forensics.
  • Strong knowledge of attacker behavior, incident investigation methods, NIST, and MITRE ATT&CK.
  • Hands-on experience with forensic tools: SIEM, EDR, EnCase, FTK, Volatility, Autopsy.
  • Understanding of digital evidence handling and chain of custody.

Responsibilities

  • Investigate cybersecurity incidents and determine scope, impact, entry vectors, and affected assets.
  • Contain, eradicate, recover, perform root-cause analysis, and conduct post-incident reviews.
  • Collect, preserve, and analyze digital evidence with proper chain-of-custody.
  • Conduct disk, memory, network, endpoint, and malware analysis using forensic tools.
  • Develop and maintain incident-response procedures, playbooks, and evidence-handling guides.
  • Prepare technical and executive incident reports, forensic findings, and RCA reports.
  • Coordinate with internal teams and stakeholders to ensure NCA-compliant classification and reporting.

Skills

Incident response
Digital forensics
Technical writing
Regulatory reporting

Education

Bachelor's degree in Cybersecurity or related field

Tools

SIEM
EDR
EnCase
FTK
Volatility
Autopsy

Job description

Location: On-site - Riyadh, Saudi Arabia

Contract/engagement: Project-based managed cybersecurity services (13-month)

Minimum experience: 7+ years

Role Purpose

Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.

Key Responsibilities
  • Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets
  • Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities
  • Collect, preserve, and analyze digital evidence in accordance with approved chain-of-custody procedures
  • Conduct disk, memory, network, endpoint, and malware analysis using appropriate forensic tools
  • Develop and maintain incident-response and DFIR procedures, playbooks, investigation methods, and evidence-handling guides
  • Prepare technical and executive incident reports, forensic findings, and RCA reports
  • Coordinate with internal teams and stakeholders and ensure incident classification and reporting comply with NCA requirements
Requirements
Technical and Professional Requirements
  • Saudi nationality is a must
  • Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, or a related field
  • At least 7 years of experience in cyber incident response and digital forensic investigations
  • Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK
  • Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools
  • Strong understanding of digital evidence handling and chain of custody
Personal Requirements
  • Calm and decisive during high-pressure incidents
  • Strong investigative thinking, attention to detail, and professional judgment
  • Clear technical writing and the ability to communicate findings to both executives and technical teams
  • High integrity and strict respect for confidentiality
Professional Certifications

Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DFIR Lead: Incident Response & Digital Forensics
Senior DFIR Lead: Incident Response & Digital Forensics

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 43,000
Cyber Defense Specialist - Detection & Monitoring
Cyber Defense Specialist - Detection & Monitoring

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 62,000
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 29,000 - 48,000
Cloud Security & Encryption Specialist
Cloud Security & Encryption Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 25,000 - 37,000
Cybersecurity Architecture Specialist
Cybersecurity Architecture Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 33,000 - 53,000
Cyber Defense Specialist — Detection & Monitoring Lead
Cyber Defense Specialist — Detection & Monitoring Lead

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 62,000
Identity & Access Management (IAM/PAM) Specialist
Identity & Access Management (IAM/PAM) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 18,000 - 29,000
Cybersecurity Architect
Cybersecurity Architect

Your ITeams Sp. z o.o. • As Sudiyah

Hybrid
OMR 34,000 - 47,000
Luxmed Gold Extended medical care
Multisport Plus benefit
Outstanding integration trips to Europe
Senior Cyber GRC Specialist: Policy, Risk & Compliance
Senior Cyber GRC Specialist: Policy, Risk & Compliance

cloud consultancy - ccds • As Sudiyah

On-site
OMR 29,000 - 48,000
Cyber Security Specialist
Cyber Security Specialist

Gulfjobfair • As Sudiyah

On-site
OMR 50,000 - 70,000