Cybersecurity Incident Réponse Specialist

exequt MENA

Riyadh

On-site

SAR 240,000 - 420,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Performance-based pay
Bupa insurance (Golden Tier)
Mentorship & training

Job summary

ExeQut is seeking a hands-on Cybersecurity Incident Response Specialist in Riyadh to investigate, contain, eradicate, and recover from security incidents across endpoints, networks, identities, cloud, and applications.

You will work with SIEM/EDR tools, conduct threat hunting, and develop incident response playbooks while collaborating with clients on real-world threats in the Kingdom of Saudi Arabia. Saudi nationality is required.

Qualifications

  • Experience in Incident Response / DFIR / SOC / Threat Hunting.
  • Hands-on with Splunk, Microsoft Sentinel, QRadar, CrowdStrike, SentinelOne, Microsoft Defender, or Cortex XDR.
  • Strong Windows/Linux and networking knowledge.
  • Knowledge of PowerShell, Python, or Bash.
  • Strong understanding of MITRE ATT&CK and common attack techniques.
  • Saudi nationality required.

Responsibilities

  • Investigate and respond to cybersecurity incidents across environments.
  • Triage, containment, eradication, and recovery activities.
  • Threat hunting and root-cause analysis.
  • Develop incident response playbooks and detection rules.
  • Prepare detailed incident reports and remediation guidance.
  • Support SOC/CSIRT operations.

Skills

Incident Response
DFIR
Threat Hunting
SOC
MITRE ATT&CK

Tools

Splunk
Microsoft Sentinel
QRadar
CrowdStrike
SentinelOne
Microsoft Defender
Cortex XDR

Job description

About ExeQut

ExeQut is a fast-growing consulting and technology services firm specializing in cybersecurity, IAM, cloud, AI-driven platforms, and custom software engineering. We partner with public and private sector organizations to deliver high-impact digital transformation initiatives across the Kingdom of Saudi Arabia.

Position Summary

ExeQut is hiring a Cybersecurity Incident Response Specialist to investigate, contain, eradicate, and recover from security incidents across endpoints, networks, identities, cloud, and applications — helping clients respond to and learn from real-world threats.

What You Will Do
  • Investigate and respond to cybersecurity incidents including ransomware, malware, phishing, account compromise, data theft, and lateral movement
  • Perform incident triage, investigation, containment, eradication, and recovery
  • Conduct threat hunting and root-cause analysis
  • Perform basic digital forensics and malware analysis
  • Identify and analyze IOCs/IOAs and map attacks to MITRE ATT&CK
  • Investigate Windows, Linux, Active Directory, and cloud environments
  • Work with SIEM and EDR/XDR platforms to investigate security events
  • Develop and improve incident response playbooks and detection rules
  • Prepare detailed incident reports, timelines, and remediation recommendations
  • Support SOC/CSIRT operations and critical incident response
Required Qualifications
  • Strong experience in Incident Response / DFIR / SOC / Threat Hunting
  • Hands-on experience with Splunk, Microsoft Sentinel, QRadar, CrowdStrike, SentinelOne, Microsoft Defender, or Cortex XDR
  • Strong Windows/Linux and networking knowledge
  • Knowledge of PowerShell, Python, or Bash
  • Strong understanding of MITRE ATT&CK and common attack techniques
  • Saudi Nationality required
Preferred Qualifications
  • Experience investigating ransomware, phishing, credential theft, and endpoint compromise
What We Offer
  • Performance-based compensation structure
  • Bupa medical insurance (Golden Tier)
  • Ongoing training and mentorship from experienced leadership
  • Exposure to high-impact projects with leading clients in Saudi Arabia
  • A collaborative, growth-oriented culture

If you're a hands-on incident response specialist who thrives on investigating and neutralizing real security threats, we'd love to have you on board — let's build something great together!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Elite Cyber Incident Response Specialist
Elite Cyber Incident Response Specialist

exequt MENA • Riyadh

On-site
SAR 240,000 - 420,000
Performance-based pay
Bupa insurance (Golden Tier)
Mentorship & training
Splunk Engineer
Splunk Engineer

exequt MENA • Riyadh

On-site
SAR 240,000 - 420,000
Performance-based compensation
Medical insurance (Golden Tier)
Ongoing training and mentorship
+2
Account Manager – Cybersecurity Solutions
Account Manager – Cybersecurity Solutions

exequt MENA • Riyadh

On-site
SAR 180,000 - 280,000
Commission-based pay
Bupa medical insurance
Professional development
+2
Privileged Access Management Engineer (PAM)
Privileged Access Management Engineer (PAM)

exequt MENA • Riyadh

On-site
SAR 360,000 - 520,000
Performance-based compensation
Premium medical insurance
Ongoing training and mentorship
+2
Cyber Incident Responder
Cyber Incident Responder

Join Solutions • Jeddah

On-site
SAR 180,000 - 300,000
Information Security & Incident Response Specialist
Information Security & Incident Response Specialist

Al Tamimi • Al Khobar

On-site
SAR 120,000 - 180,000
Cybersecurity Solutions Account Manager – Saudi Growth
Cybersecurity Solutions Account Manager – Saudi Growth

exequt MENA • Riyadh

On-site
SAR 180,000 - 280,000
Commission-based pay
Bupa medical insurance
Professional development
+2
Cybersecurity Engineer (Saudi National)
Cybersecurity Engineer (Saudi National)

Astek Middle East • Riyadh

On-site
SAR <240,000
SOC Manager
SOC Manager

Managed • Riyadh

On-site
SAR 240,000 - 360,000
SOC Manager
SOC Manager

Managed Services • Riyadh

On-site
SAR 240,000 - 360,000