Company logo hidden

Cybersecurity Incident Lead

Unlock employer Riyadh, Saudi Arabia Posted: 08 Dec 2025

Financial

  • Estimate: $80k - $120k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Senior
  • English: Professional

Position

The Cybersecurity Incident Lead's primary function is to take command of an active security crisis, directing the Incident Response (IR) team and coordinating internal and external stakeholders—including legal, communication, and executive teams—to execute a comprehensive strategy for immediate containment, threat eradication, system recovery, and evidence preservation. They are responsible for critical decision-making under pressure, serving as the main liaison for executive reporting and regulatory compliance, and subsequently leading the post-incident analysis to identify root causes and implement lessons learned to strengthen future defenses.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Tasks & Responsibilities

  • Own incident response (IR) lifecycle: detect, triage, contain, eradicate, recover, and post-incident review per SAMA CSF and NCA ECC-2.
  • Lead major incident war-rooms, coordinate SOC, IT, Product, Legal, and Comms, and ensure timely regulator-ready reporting.
  • Maintain IR playbooks for fintech/payments threats (account takeover, fraud, ransomware, API abuse, data leakage).
  • Run tabletop and simulation drills; measure MTTR, response quality, and control improvements.
  • Drive root-cause analysis and track corrective/preventive actions to closure.

Qualifications

  • Bachelor’s in Cybersecurity/CS or related field.
  • 7–10+ years in SOC/IR with 2+ years leading incidents in regulated environments.
  • Strong knowledge of forensics basics, malware triage, cloud/SaaS IR, and crisis communications.
  • Working knowledge of SAMA CSF and NCA ECC-2 incident controls.
  • Certs preferred: GCIH, GCFA, CISSP, or equivalent.

Location
Riyadh, Riyadh, Saudi Arabia.

Apply Direct

Jobs you might like   View all jobs

Ready to apply for this role?

Apply Direct