Search Jobs

Search by job, company or skills

Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

cloud consultancy - ccds
  • Posted 21 days ago
  • Be among the first 10 applicants

Job Description

Location: On-site - Riyadh, Saudi Arabia

Contract/engagement: Project-based managed cybersecurity services (13-month)

Minimum experience: 7+ years

Role Purpose

Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.

Key Responsibilities

  • Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets
  • Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities
  • Collect, preserve, and analyze digital evidence in accordance with approved chain-of-custody procedures
  • Conduct disk, memory, network, endpoint, and malware analysis using appropriate forensic tools
  • Develop and maintain incident-response and DFIR procedures, playbooks, investigation methods, and evidence-handling guides
  • Prepare technical and executive incident reports, forensic findings, and RCA reports
  • Coordinate with internal teams and stakeholders and ensure incident classification and reporting comply with NCA requirements

Requirements

Technical and Professional Requirements

  • Saudi nationality is a must
  • Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, or a related field
  • At least 7 years of experience in cyber incident response and digital forensic investigations
  • Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK
  • Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools
  • Strong understanding of digital evidence handling and chain of custody

Personal Requirements

  • Calm and decisive during high-pressure incidents
  • Strong investigative thinking, attention to detail, and professional judgment
  • Clear technical writing and the ability to communicate findings to both executives and technical teams
  • High integrity and strict respect for confidentiality

Professional Certifications

Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

NIST incident response

Autopsy