Be the change. Join the world's most visionary developer.
Join RSG and be part of the positive change for Saudi Arabia and the world.
Job Purpose:
Manage and oversee RSG's Digital Forensics and Incident Response (DFIR) function, including incident triage, containment and recovery, digital forensic investigations, malware and artifact analysis, threat hunting, and post-incident reporting across RSG's corporate, cloud, and operational technology environments, ensuring that security incidents are detected, investigated, and resolved within agreed service levels, that evidence is preserved in a defensible manner, and that DFIR practices align with RSG's organizational strategy, risk appetite, and applicable national and international standards.
Job Responsibilities:
- Manage the configuration, tuning, and daily operation of DFIR tooling, including endpoint detection and response, forensic acquisition and analysis platforms, and the log and telemetry sources relied upon for investigations.
- Ensure incident response and forensic practices comply with RSG's information security policies, regulatory requirements, and national/international standards (e.g., NCA ECC, PDPL, ISO 27001, NIST SP 800-61).
- Manage the development and maintenance of the incident response plan, playbooks, severity classification, and escalation matrix, ensuring they remain tested, current, and aligned to the evolving threat landscape.
- Ensure timely triage, containment, eradication, and recovery of security incidents, prioritized by business impact and closed within agreed service levels.
- Manage forensic evidence acquisition and handling, ensuring chain of custody, integrity verification, and defensible preservation for legal, regulatory, or disciplinary proceedings.
- Manage the development of detection use cases and hunting hypotheses derived from investigations, ensuring findings and indicators are fed back into RSG's monitoring, alerting, and response capability.
- Oversee the technical investigation of malware, intrusion, insider, and data exfiltration cases, including host, memory, network, identity, and cloud artifact analysis through documented root cause.
- Manage the quality and timeliness of incident reports, executive summaries, and post-incident reviews, ensuring actionable findings, lessons learned, and corrective actions are tracked to closure.
- Oversee proactive threat hunting across endpoint, network, cloud, and identity telemetry, using threat intelligence and adversary techniques mapped to recognized frameworks such as MITRE ATT&CK.
- Ensure DFIR readiness is verified through tabletop exercises, attack simulation and purple-team testing, and formal validation that documented response and recovery objectives are achievable.
- Manage the automation of investigation and response actions through orchestration playbooks and scripting, reducing manual effort and improving mean time to detect, contain, and recover.
- Ensure that all DFIR processes, technical configurations, and standard operating procedures are fully documented, maintained, and communicated to relevant stakeholders.
- Oversee the integration of cyber threat intelligence into detection, hunting, and response workflows, including indicator ingestion, enrichment, and retrospective sweeps across the estate.
- Oversee vendor and service-provider relationships for DFIR technologies and retained incident response services, ensuring adherence to service levels and recommended best practices.
- Manage the transfer of knowledge from contracted and external resources into RSG ownership, ensuring documented and verified handover of all DFIR operational activities.
- Act as escalation point for high-severity, sensitive, or legally significant incidents, validating risk, ensuring appropriate approvals and regulatory notifications, and driving corrective and preventive actions.
Managerial Responsibilities
- Provide input into the Department's cybersecurity strategy from the Digital Forensics & Incident Response Section perspective, ensuring alignment with RSG's vision, mission, and risk appetite.
- Develop Section objectives, KPIs, and annual operational plans for incident response, digital forensics, threat hunting, and investigation reporting, ensuring implementation meets established performance targets.
- Contribute to budget preparation and monitor financial performance of DFIR-related initiatives, tools, retainers, and services, ensuring efficient and cost-effective utilization.
- Implement and ensure adherence to Section policies, standards, and procedures for incident response and digital forensics, while overseeing performance monitoring, KPI reporting, and corrective actions where needed.
- Ensure effective staffing, development, and deployment of the DFIR team, including on-call and shift coverage, in coordination with higher management, fostering talent growth, capability building, and succession readiness.
Job Requirements:
Academic Qualification:
- Bachelor's degree (mandatory): Computer Science, Information Security, Information Systems, Software Engineering or a related technical discipline.
- Master's degree (preferred): Information Security, Cybersecurity Management, or Business Administration (MBA with IT/Security focus).
Qualifications & Experience:
- 6+ years in cybersecurity, of which a minimum of 3 years in hands-on digital forensics and incident response within an enterprise production environment.
- Preferred certifications: GCFA, GCFE, GCIH, GNFA, GREM, or CISSP. Fluent written and spoken Arabic and English. Participation in a defined 24/7 on-call escalation rota for security incidents, with readiness to travel to site for evidence acquisition when required.
For more information about Red Sea Global, visit: