Company logo hidden

Cybersecurity Defense DFIR

Unlock employer Riyadh, Saudi Arabia Posted: 11 Jun 2026

Financial

  • Estimate: $80k - $120k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Intermediate
  • English: Professional

Position

Established in 2008, the company epitomizes customer-focused empowerment and commercial success through continuous innovation. The company makes best-in-class digital payment solutions available for all by attracting and leveraging the best creative and entrepreneurial talent in the market. Our solutions give any business the chance to get ahead and reach for more, regardless of their size or maturity. Our technology mirrors our people - Smart, Innovative & Forward Thinking.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

The Cybersecurity Defense DFIR role is responsible for identifying, investigating, and responding to cyber incidents across the organization. This position combines advanced digital forensics, threat analysis, and incident response activities to rapidly contain threats, determine root causes, and support recovery efforts. The DFIR Specialist will work closely with SOC and threat intelligence teams to strengthen the organization’s security posture and resilience.

Key Accountabilities:

  • Lead or support the full lifecycle of incident response, including identification, containment, eradication, and recovery.
  • Perform rapid triage and analysis of security alerts, logs, network traffic, and endpoint telemetry.
  • Document incident timelines, technical findings, and recommendations for stakeholders.
  • Conduct forensic acquisition and analysis of endpoints, servers, cloud systems, and mobile devices.
  • Perform disk, memory, and malware analysis to determine attacker activity, persistence mechanisms, and impact.
  • Preserve and maintain chain-of-custody for digital evidence.
  • Provide feedback to SOC and detection engineering teams to improve alerting, detection rules, and playbooks.

Technical / Professional Qualifications:

  • Bachelor’s degree in Computer Science, Information Technology, Telecommunications, Electronics & Electrical or any related field.
  • 3+ years of experience in cybersecurity operations (SOC, DFIR, cyber defense, or related roles).
  • Certifications: CompTIA Security+, GCIH, GCFE, GCFA.
  • In-depth knowledge of security concepts such as cyber-attacks and techniques, threat vectors, and incident management.
  • Familiarity with best practice security frameworks such as NIST, SAMA CSF, OWASP, ISO 27001, and PCI-DSS.
  • Experience in Cybersecurity Incident Response, Security Information and Event Management (SIEM), EDR, IDS/IPS, DLP, SOAR, Cloud Security (AWS/OCI/GCP/Azure), and Email Security.
  • Good understanding of IS security controls, monitoring systems, and business drivers that impact security policy and practice.
Apply Direct

Jobs you might like   View all jobs

Ready to apply for this role?

Apply Direct