Job Search and Career Advice Platform

Enable job alerts via email!

Incident Response Consultant

IBM

Riyadh

On-site

SAR 150,000 - 200,000

Full time

Today
Be an early applicant

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading enterprise security firm is seeking a Security Consultant in Riyadh to analyze business needs and design security solutions. The role involves responding to cybersecurity incidents, providing strategic security services, and conducting forensic analysis. The ideal candidate has a Bachelor's degree, extensive experience in incident response, strong skills with EDR and SIEM tools, and the ability to lead teams effectively. This full-time position requires proficiency in cybersecurity practices and a proactive approach to incident response.

Qualifications

  • Hands-on experience with incident response tools and computer forensics.
  • Experience in developing policies for IT risk mitigation.
  • Capable of leading incident response teams.

Responsibilities

  • Analyze business requirements to provide security solutions.
  • Respond to high profile cybersecurity incidents.
  • Conduct enterprise threat hunting and develop incident response plans.

Skills

Incident Response
Cybersecurity
Forensic Analysis
Leadership
Scripting (Python, PowerShell)

Education

Bachelor's Degree

Tools

EnCase
Splunk
EDR tools
SIEM tools
Job description
Introduction

Information and Data are some of the most important organizational assets in today’s businesses. As a Security Consultant, you will be a key advisor for IBM’s clients, analyzing business requirements to design and implement the best security solutions for their needs. You will apply your technical skills to find the balance between enabling and securing the client’s organization with the cognitive solutions that are making IBM the fastest growing enterprise security business in the world.

Your Role And Responsibilities

As a consultant for the IBM Security X-Force Incident Response (X-Force IR) team, you will be part of a team of consultants who are responding to high profile cybersecurity incidents within our clients’ enterprise networks. You will work with our clients to prepare for and respond to cybersecurity incidents, serve as a trusted advisor to our clients, help shape their cybersecurity program, and collaborate with internal IBM stakeholders to provide integrated solutions to our clients’ most challenging problems.

In this role you will demonstrate skills in various elements of Incident Response, conduct computer intrusion investigations, and have a strong foundation in cyber security policy, operations and best practices, ideally in large enterprise environments. You will need proficiency with leading EDR tools as well as familiarity with forensic analysis tools and live response analysis. Familiarity with Windows and Linux enterprise environments, including Active Directory, M365, firewalls, IPS/IDS, SIEMs, etc. is required. Excellent written and verbal communication skills are required. When not responding to breaches, you will conduct enterprise threat hunting, help clients develop incident response plans, facilitate tabletop exercises, and provide other strategic security services related to incident response.

Preferred Education

• Bachelor's Degree

Required Technical And Professional Expertise
  • Significant hands‑on experience with hardware/software tools used in incident response, computer forensics, network security assessments, and/or application security.
  • Experience with assessing and developing enterprise‑wide policies and procedures for IT risk mitigation and incident response.
  • Experience leading incident response teams and managing tasks across all phases of an engagement.
  • Capable of working independently as well as providing leadership on internal projects and client engagements.
Forensic Analysis & Incident Response Skills
  • Ability to forensically analyze both Windows & Unix systems for evidence of compromise.
  • Proficiency with industry‑standard forensic tools such as EnCase, FTK, X‑Ways, SleuthKit.
  • Experience performing log analysis locally and via SIEM/log aggregation tool.
  • Experience hunting threat actors in large enterprise networks and cloud environments.
  • Experience with using and configuring Endpoint Detection & Response (EDR) tools.
  • Demonstrated understanding of the behavior, security risks and controls of common network protocols.
  • Demonstrated understanding of common applications used in Windows and Linux enterprise environments.
  • Familiarity with Active Directory, Exchange and Office365 applications and logs.
  • Familiarity with cloud computing platforms like IBM Cloud, AWS, GCP or Azure.
  • Proficient in writing cohesive reports for both technical and non‑technical audiences.
Strategic Assessment Expertise
  • Examine and analyze available client internal policies, processes, and procedures to determine patterns and gaps at both a strategic and tactical level. Recommend appropriate actions to support maturing the client’s incident response program and cyber security posture.
  • Strong familiarity with security frameworks and standards such as ISO 27001/2, PCI DSS, NIST 800‑53, 800‑171, and applicable data privacy laws and regulations.
  • Demonstrated experience with planning, scoping, and delivering technical and/or executive‑level tabletop exercises, focusing on either tactical or strategic incident response processes.
  • Ability to incorporate current trends and develop custom scenarios applicable to a client.
  • Low‑level operating system knowledge, including automation and performing administrative tasks.
  • Scripting or programming experience, preferably in a language commonly used for DFIR such as Python or PowerShell.
  • Ability to work with data at scale using tools such as Splunk or ELK.
  • Expertise working with shell programs such as grep, sed and awk to process data quickly.
  • Experience with virtualization and cloud technology platforms like IBM Cloud, AWS, GCP & Azure.
Preferred Technical And Professional Experience
  • Diverse understanding of cyber security related vulnerabilities, common attack vectors, and mitigations.
  • Capable of developing strategic level incident response plans as well as tactical‑focused playbooks.
  • Ability to manage tasks and coordinate work streams during incident response investigations.
Seniority Level
  • Mid‑Senior level
Employment Type
  • Full‑time
Job Function
  • Consulting, Information Technology, and Sales
Industries
  • IT Services and IT Consulting

Referrals increase your chances of interviewing at IBM by 2x.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.