{bc}
indeed

Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

CCDS
Riyadh, KSA
Full-time
Senior
Onsite
Discovered 2 weeks ago
Cybersecurity incident responseDigital forensicsNIST incident responseMITRE ATT&CKSIEMEDR
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Cybersecurity incident responseDigital forensicsNIST incident response
Smart Apply

Full Job Posting

Location

  • On-site role based in Riyadh, Saudi Arabia.

Contract and Engagement

  • Project-based managed cybersecurity services engagement lasting 13 months.

Role Purpose

Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.

Key Responsibilities

  • Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets.
  • Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities.
  • Collect, preserve, and analyze digital evidence according to approved chain-of-custody procedures.
  • Conduct disk, memory, network, endpoint, and malware analysis using appropriate forensic tools.
  • Develop and maintain incident-response and DFIR procedures, playbooks, investigation methods, and evidence-handling guides.
  • Prepare technical and executive incident reports, forensic findings, and root-cause analysis reports.
  • Coordinate with internal teams and stakeholders and ensure incident classification and reporting comply with NCA requirements.

Technical and Professional Requirements

  • Bachelor’s degree in Cybersecurity, Digital Forensics, Computer Science, or a related field.
  • At least 7 years of experience in cyber incident response and digital forensic investigations.
  • Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK.
  • Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools.
  • Strong understanding of digital evidence handling and chain of custody.

Personal Requirements

  • Calm and decisive during high-pressure incidents.
  • Strong investigative thinking, attention to detail, and professional judgment.
  • Clear technical writing and ability to communicate findings to executives and technical teams.
  • High integrity and strict respect for confidentiality.

Preferred Certifications

  • CISSP, GCIA, GSEC, GCIH, CISM, or equivalent certifications are preferred.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at CCDS