Jobless Developer
Ccds logo

Posted 28 days ago

Open

Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

RiyadhOn-siteFull-time

AI Summary

Lead and execute cybersecurity incident response and digital forensic investigations, preserving evidence and meeting regulatory reporting requirements for a project-based engagement in Riyadh.

About this role

Location: On-site – Riyadh, Saudi Arabia

Contract/engagement: Project-based managed cybersecurity services (13-month)

Minimum experience: 7+ years

Role Purpose

Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.

Key Responsibilities

· Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets.

· Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities.

· Collect, preserve, and analyze digital evidence in accordance with approved chain-of-custody procedures.

· Conduct disk, memory, network, endpoint, and malware analysis using appropriate forensic tools.

· Develop and maintain incident-response and DFIR procedures, playbooks, investigation methods, and evidence-handling guides.

· Prepare technical and executive incident reports, forensic findings, and RCA reports.

· Coordinate with internal teams and stakeholders and ensure incident classification and reporting comply with NCA requirements.

Requirements

Technical and Professional Requirements

· Saudi nationality is a must.

· Bachelor’s degree in Cybersecurity, Digital Forensics, Computer Science, or a related field.

· At least 7 years of experience in cyber incident response and digital forensic investigations.

· Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK.

· Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools.

· Strong understanding of digital evidence handling and chain of custody.

Personal Requirements

· Calm and decisive during high-pressure incidents.

· Strong investigative thinking, attention to detail, and professional judgment.

· Clear technical writing and the ability to communicate findings to both executives and technical teams.

· High integrity and strict respect for confidentiality.

Professional Certifications

Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.

Skills

AutopsyChain Of CustodyDigital Evidence HandlingDisk AnalysisEDREncaseEndpoint AnalysisForensic Investigation MethodsFTKIncident ClassificationIncident Response ProceduresMalware AnalysisMemory AnalysisMITRE ATT&CKNetwork AnalysisNIST Incident ResponseRoot-cause AnalysisSIEMVolatility

Explore related jobs

Browse these categories

Market data for this role

All reports →