Cybersecurity Incident Response And Digital Forensics Specialist
Location
On-site – Riyadh, Saudi Arabia
Contract/engagement
Project-based managed cybersecurity services (13-month)
Minimum experience
7+ years
Role purpose
Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.
Key responsibilities
Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets.
Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities.
Collect, preserve, and analyze digital evidence in accordance with approved chain-of-custody procedures.
Conduct disk, memory, network, endpoint, and malware analysis using appropriate forensic tools.
Develop and maintain incident-response and DFIR procedures, playbooks, investigation methods, and evidence-handling guides.
Prepare technical and executive incident reports, forensic findings, and RCA reports.
Coordinate with internal teams and stakeholders and ensure incident classification and reporting comply with NCA requirements.
Requirements
Technical and professional requirements
Saudi nationality is a must.
Bachelor’s degree in Cybersecurity, Digital Forensics, Computer Science, or a related field.
At least 7 years of experience in cyber incident response and digital forensic investigations.
Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK.
Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools.
Strong understanding of digital evidence handling and chain of custody.
Personal requirements
Calm and decisive during high-pressure incidents.
Strong investigative thinking, attention to detail, and professional judgment.
Clear technical writing and the ability to communicate findings to both executives and technical teams.
High integrity and strict respect for confidentiality.
Professional certifications
Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.