Company logo hidden

Cyber Security Incident Response Specialist

Unlock employer Dubai, United Arab Emirates Posted: 13 Nov 2025

Financial

  • Estimate: $80k - $120k*
  • Zero income tax location

Accessibility

  • Visa Provided

Requirements

  • Experience: Junior
  • English: Professional

Position

Location
Dubai, United Arab Emirates

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

As a member of the ETMSA team at the company, you will be integral to responding to and managing cybersecurity threats and incidents throughout their lifecycle – from Preparation to Identification, Containment, Eradication, Recovery, and Lessons Learned – collaborating with a global team of incident responders.

You will apply your comprehensive skills in cyber defense, digital forensics, log analysis, and intrusion analysis to address security incidents across our endpoints, network, and cloud infrastructure. In this role, you will be responsible for prevention, detection, response, and remediation activities, ensuring that information assets and technologies are adequately protected by leveraging various technologies such as Next-Generation Firewalls (NGFW), Endpoint Detection and Response (EDR), Intrusion Detection/Prevention Systems (IDS/IPS), Data Loss Prevention (DLP), and more.

You will also leverage your collaboration and communication skills to work effectively with all relevant stakeholders in multicultural and global environments.

Responsibilities

  • Report to Director to facilitate all phases in the incident response lifecycle
  • Be involved in various incident prevention projects to improve Security posture

Preparation

  • Understand different regulatory and compliance requirements like critical time to report, escalation flows, etc.
  • Take part in self-assessment exercises like Tabletop Exercises, Attack Simulations, Red/Purple Team exercises to ensure the incident response process is working smoothly
  • Develop incident response runbooks, playbooks, and SOPs with reference to different regulatory requirements
  • Evaluate the incident response readiness of different layers - people, process, technology

Detection & Analysis

  • Respond to cyber security incidents escalated from various channels including the 24/7 SOC team.
  • Respond to cyber security incidents in compliance with local authority/regulatory requirements.
  • Assess the risk, impact, and scope of the identified security threats
  • Perform deep-dive incident analysis of various data sources by analysing and investigating security-related logs against medium-term threats and IOCs

Containment, Eradication, and Recovery

  • Communicate with stakeholders and provide guidance and recommendations to contain and eradicate the security incident
  • Participate in root cause analysis using forensic and other custom tools to identify any sources of compromise and/or malicious activities taking place.
  • Document and present investigative findings for high-profile events and other incidents of interest.

Post-Incident Activities

  • Provide lessons learned meetings to stakeholders
  • Lead and keep track of follow-up activities
  • Document the incident in the case management system and provide incident reports

Always ready to jump in, in the event of security incidents.

Requirements

  • At least 2 years experience in the Cyber Security industry
  • Strong technical and analytical skills
  • Familiarity with the cyber security incident response process
  • Familiarity with AI tools and their application in automating security tasks and processes.
  • Hands-on experience performing incident response activities
  • Scripting experience in languages like Bash, PowerShell, Python, Go, etc., and the ability to use these skills to aid in responding to incidents involving Windows, Linux, macOS, as well as cloud environments
  • Knowledge of cybersecurity tools and software like NGFW, EDR, IDS/IPS, EDR, DLP, SIEM, and other log management platforms.
  • Familiarity with the MITRE ATT&CK Framework and/or Cyber Kill Chain
  • Passionate about exploring new technologies and having creative initiative to boost team capabilities
  • Holders of security-related certifications (e.g. Azure, AWS, CISSP, GCIH, GCIA, GCFA, GNFA, GREM, or other equivalents) are a plus
  • Awareness of regulatory and compliance requirements like GDPR, MAS, PSD2, etc. is a plus.

Preferably

  • Fast learner with a can-do attitude, ready to get hands dirty
  • A strong team player who can collaborate with compassion
  • Passionate to learn and willing to put in extra effort
  • Understand the concept of ownership and accountability, coupled with a sense of urgency and prioritization
  • Confident in handling incidents and managing relevant senior and technical stakeholders
  • Possess business acumen/mindset (not only technical) when making critical decisions
Apply Direct

Jobs you might like   View all jobs

Ready to apply for this role?

Apply Direct