Senior DFIR Lead: Incident Response & Digital Forensics

cloud consultancy - ccds

As Sudiyah

On-site

OMR 31,000 - 43,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

cloud consultancy - ccds in Riyadh, Saudi Arabia, seeks an experienced cybersecurity Incident Response Lead for a 13-month project-based engagement. You will direct investigations, preserve evidence, and report to executives with a focus on regulatory compliance.

The role requires 7+ years in IR and DFIR, strong knowledge of NIST/MITRE ATT&CK, and hands-on use of SIEM/EDR tools, EnCase, FTK, Volatility, and Autopsy. Saudi nationality is mandatory.

Qualifications

  • Saudi nationality is required.
  • Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, or related field.
  • 7+ years of experience in cyber incident response and digital forensics.
  • Strong knowledge of attacker behavior, incident investigation methods, NIST, and MITRE ATT&CK.
  • Hands-on experience with forensic tools: SIEM, EDR, EnCase, FTK, Volatility, Autopsy.
  • Understanding of digital evidence handling and chain of custody.

Responsibilities

  • Investigate cybersecurity incidents and determine scope, impact, entry vectors, and affected assets.
  • Contain, eradicate, recover, perform root-cause analysis, and conduct post-incident reviews.
  • Collect, preserve, and analyze digital evidence with proper chain-of-custody.
  • Conduct disk, memory, network, endpoint, and malware analysis using forensic tools.
  • Develop and maintain incident-response procedures, playbooks, and evidence-handling guides.
  • Prepare technical and executive incident reports, forensic findings, and RCA reports.
  • Coordinate with internal teams and stakeholders to ensure NCA-compliant classification and reporting.

Skills

Incident response
Digital forensics
Technical writing
Regulatory reporting

Education

Bachelor's degree in Cybersecurity or related field

Tools

SIEM
EDR
EnCase
FTK
Volatility
Autopsy

Job description

cloud consultancy - ccds in Riyadh, Saudi Arabia, seeks an experienced cybersecurity Incident Response Lead for a 13-month project-based engagement. You will direct investigations, preserve evidence, and report to executives with a focus on regulatory compliance.

The role requires 7+ years in IR and DFIR, strong knowledge of NIST/MITRE ATT&CK, and hands-on use of SIEM/EDR tools, EnCase, FTK, Volatility, and Autopsy. Saudi nationality is mandatory.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 43,000
Cyber Defense Specialist — Detection & Monitoring Lead
Cyber Defense Specialist — Detection & Monitoring Lead

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 62,000
Cyber Defense Specialist - Detection & Monitoring
Cyber Defense Specialist - Detection & Monitoring

cloud consultancy - ccds • As Sudiyah

On-site
OMR 31,000 - 62,000
Senior Cloud Security & Encryption Architect
Senior Cloud Security & Encryption Architect

cloud consultancy - ccds • As Sudiyah

On-site
OMR 25,000 - 37,000
Cybersecurity Governance, Risk & Compliance (GRC) Specialist
Cybersecurity Governance, Risk & Compliance (GRC) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 29,000 - 48,000
Senior Cyber GRC Specialist: Policy, Risk & Compliance
Senior Cyber GRC Specialist: Policy, Risk & Compliance

cloud consultancy - ccds • As Sudiyah

On-site
OMR 29,000 - 48,000
Cloud Security & Encryption Specialist
Cloud Security & Encryption Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 25,000 - 37,000
Cybersecurity Architecture Specialist
Cybersecurity Architecture Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 33,000 - 53,000
Cybersecurity Architect
Cybersecurity Architect

Your ITeams Sp. z o.o. • As Sudiyah

Hybrid
OMR 34,000 - 47,000
Luxmed Gold Extended medical care
Multisport Plus benefit
Outstanding integration trips to Europe
Identity & Access Management (IAM/PAM) Specialist
Identity & Access Management (IAM/PAM) Specialist

cloud consultancy - ccds • As Sudiyah

On-site
OMR 18,000 - 29,000