Assistant Manager - Digital Forensics and Incident Response

Red Sea Global

Riyadh

On-site

SAR 600,000 - 1,000,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Red Sea Global in Saudi Arabia is seeking a senior leader to manage its Digital Forensics and Incident Response (DFIR) program. You will oversee incident triage, containment and recovery across corporate, cloud, and OT environments, ensuring evidence is preserved and investigations stay within SLAs.

The role covers developing detection use cases, leading malware analysis, and coordinating with security policy, testing, and governance.

Qualifications

  • Bachelor’s degree in computer science, information security, information systems, software engineering, or related field.
  • Master’s degree in information security, cybersecurity management, or MBA with IT/security focus preferred.

Responsibilities

  • Manage and oversee DFIR tooling configuration, tuning, and daily operations.
  • Ensure incident response and forensic practices comply with policies and standards.
  • Develop and maintain incident response plans, playbooks, and escalation matrices.
  • Lead incident triage, containment, eradication, and recovery.

Skills

Cybersecurity
Digital forensics
Incident response
GCFA
GCFE
GCIH
GNFA
GREM
CISSP
Arabic
English
On-call rotation
Travel readiness

Education

Bachelor's degree in CS/IS/SE
Master's degree in InfoSec / Cybersecurity Mgmt or MBA IT Security

Job description

Be the change. Join the world's most visionary developer.
Join RSG and be part of the positive change for Saudi Arabia and the world.
Job Purpose:

Manage and oversee RSG's Digital Forensics and Incident Response (DFIR) function, including incident triage, containment and recovery, digital forensic investigations, malware and artifact analysis, threat hunting, and post-incident reporting across RSG's corporate, cloud, and operational technology environments, ensuring that security incidents are detected, investigated, and resolved within agreed service levels, that evidence is preserved in a defensible manner, and that DFIR practices align with RSG's organizational strategy, risk appetite, and applicable national and international standards.

Job Responsibilities:
  • Manage the configuration, tuning, and daily operation of DFIR tooling, including endpoint detection and response, forensic acquisition and analysis platforms, and the log and telemetry sources relied upon for investigations.
  • Ensure incident response and forensic practices comply with RSG's information security policies, regulatory requirements, and national/international standards (e.g., NCA ECC, PDPL, ISO 27001, NIST SP 800-61).
  • Manage the development and maintenance of the incident response plan, playbooks, severity classification, and escalation matrix, ensuring they remain tested, current, and aligned to the evolving threat landscape.
  • Ensure timely triage, containment, eradication, and recovery of security incidents, prioritized by business impact and closed within agreed service levels.
  • Manage forensic evidence acquisition and handling, ensuring chain of custody, integrity verification, and defensible preservation for legal, regulatory, or disciplinary proceedings.
  • Manage the development of detection use cases and hunting hypotheses derived from investigations, ensuring findings and indicators are fed back into RSG's monitoring, alerting, and response capability.
  • Oversee the technical investigation of malware, intrusion, insider, and data exfiltration cases, including host, memory, network, identity, and cloud artifact analysis through documented root cause.
  • Manage the quality and timeliness of incident reports, executive summaries, and post-incident reviews, ensuring actionable findings, lessons learned, and corrective actions are tracked to closure.
  • Oversee proactive threat hunting across endpoint, network, cloud, and identity telemetry, using threat intelligence and adversary techniques mapped to recognized frameworks such as MITRE ATT&CK.
  • Ensure DFIR readiness is verified through tabletop exercises, attack simulation and purple-team testing, and formal validation that documented response and recovery objectives are achievable.
  • Manage the automation of investigation and response actions through orchestration playbooks and scripting, reducing manual effort and improving mean time to detect, contain, and recover.
  • Ensure that all DFIR processes, technical configurations, and standard operating procedures are fully documented, maintained, and communicated to relevant stakeholders.
  • Oversee the integration of cyber threat intelligence into detection, hunting, and response workflows, including indicator ingestion, enrichment, and retrospective sweeps across the estate.
  • Oversee vendor and service-provider relationships for DFIR technologies and retained incident response services, ensuring adherence to service levels and recommended best practices.
  • Manage the transfer of knowledge from contracted and external resources into RSG ownership, ensuring documented and verified handover of all DFIR operational activities.
  • Act as escalation point for high-severity, sensitive, or legally significant incidents, validating risk, ensuring appropriate approvals and regulatory notifications, and driving corrective and preventive actions.
Managerial Responsibilities
  • Provide input into the Department's cybersecurity strategy from the Digital Forensics & Incident Response Section perspective, ensuring alignment with RSG's vision, mission, and risk appetite.
  • Develop Section objectives, KPIs, and annual operational plans for incident response, digital forensics, threat hunting, and investigation reporting, ensuring implementation meets established performance targets.
  • Contribute to budget preparation and monitor financial performance of DFIR-related initiatives, tools, retainers, and services, ensuring efficient and cost-effective utilization.
  • Implement and ensure adherence to Section policies, standards, and procedures for incident response and digital forensics, while overseeing performance monitoring, KPI reporting, and corrective actions where needed.
  • Ensure effective staffing, development, and deployment of the DFIR team, including on-call and shift coverage, in coordination with higher management, fostering talent growth, capability building, and succession readiness.
Job Requirements:
Academic Qualification:
  • Bachelor's degree (mandatory): Computer Science, Information Security, Information Systems, Software Engineering or a related technical discipline.
  • Master's degree (preferred): Information Security, Cybersecurity Management, or Business Administration (MBA with IT/Security focus).
Qualifications & Experience:
  • 6+ years in cybersecurity, of which a minimum of 3 years in hands-on digital forensics and incident response within an enterprise production environment.
  • Preferred certifications: GCFA, GCFE, GCIH, GNFA, GREM, or CISSP. Fluent written and spoken Arabic and English. Participation in a defined 24/7 on-call escalation rota for security incidents, with readiness to travel to site for evidence acquisition when required.
For more information about Red Sea Global, visit:
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist
Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

cloud consultancy - ccds • Saudi Arabia

On-site
OMR 31,000 - 43,000
DFIR Lead: Incident Response & Digital Forensics
DFIR Lead: Incident Response & Digital Forensics

Red Sea Global • Riyadh

On-site
SAR 600,000 - 1,000,000
Senior DFIR Guardian - Madinah
Senior DFIR Guardian - Madinah

COGNNA • Medina

On-site
SAR 240,000 - 360,000
Impact-driven work
On-site collaboration in Almadina
Certifications & growth
+1
SOC Manager
SOC Manager

Managed Services • Riyadh

On-site
SAR 240,000 - 360,000
SOC Manager
SOC Manager

Managed • Riyadh

On-site
SAR 240,000 - 360,000
Regional DFIR Technical Lead — 24/7 Incident Expert
Regional DFIR Technical Lead — 24/7 Incident Expert

Group-IB • Riyadh

On-site
SAR 400,000 - 650,000
Funding for professionalCertifications
Global opportunities across Group-IB's
Career growth in DFIR leadership
International Contract Bench, Incident Response (DFIR)
International Contract Bench, Incident Response (DFIR)

Lever, Inc. • Saudi Arabia

On-site
SAR 120,000 - 240,000
Flexible contract-based engagement
Live IR investigations
Hands-on exposure to ransomware and云端取
+1
Cybersecurity Incident Réponse Specialist
Cybersecurity Incident Réponse Specialist

exequt MENA • Riyadh

On-site
SAR 240,000 - 420,000
Performance-based pay
Bupa insurance (Golden Tier)
Mentorship & training
Senior Cybersecurity Engineer | Global Technologies GT – التقنيات العالمية | Riyadh, Saudi Arabia
Senior Cybersecurity Engineer | Global Technologies GT – التقنيات العالمية | Riyadh, Saudi Arabia

Global Technologies GT - التقنيات العالمية • Riyadh

On-site
SAR 200,000 - 360,000
Security Analyst
Security Analyst

Jobmaze FZ LLC • Al Khobar

On-site
SAR 180,000 - 240,000