About the Role
As a Lead Incident Responder in the Incident Response & Forensics Team, you will operate within a high-impact cyber defence environment, taking on blue team operations with technical expertise in digital forensics and cyber incident response. This role calls for a motivated individual who excels in teamwork but can also work independently in varied scenarios. You will face new challenges in a dynamic setting, contributing positively with your team spirit and willingness to assist others.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- Serve as technical and coordination lead on active incident response engagements.
- Communicate effectively in English and manage stakeholder interactions to coordinate technical staff and report investigation progress to clients.
- Execute and coordinate threat hunting activities supporting incident response engagements and SOC operations.
- Perform host and/or network-based forensics on Windows, Mac, and Linux platforms.
- Conduct digital forensic investigations in connection with cyber incident response engagements.
- Contribute to process documentation and continuous service improvement initiatives.
- Lead the production of detailed reports and technical briefs, clearly communicating tasks, methodologies, and guidance to clients.
- Perform Quality Assurance on reports generated by junior team members.
- Translate technical findings into understandable terms for both technical and non-technical audiences.
- Demonstrate thought leadership by creating and developing internal learning sessions.
- Lead team research activities aimed at service enhancement.
- Maintain the client-fostered DFIR Forensics Lab.
- Become the team's subject matter expert in at least two areas: host forensics, network forensics, mobile forensics, malware analysis, OT/ICS Incident Response, cloud forensics, or threat hunting.
- Achieve independence in task completion after an initial two months, adapting to a flexible schedule typical of incident response.
- Maintain a team-oriented, humble, and approachable demeanor while going the extra mile.
Technical Skills
- Strong understanding of blue team operations and threat hunting.
- Sound knowledge of network protocols, TCP/IP, and Microsoft Windows.
- Proficient in Linux and OSX environments.
- Solid forensic skills across multiple operating systems.
- Proficient with network analysis tools like Bro/Zeek, Rita, or Suricata.
- Ability to analyze system and network device logs.
- Knowledgeable in static and dynamic malware analysis techniques.
- Understanding of enterprise systems, technologies, and infrastructure.
- Capable of identifying targeted attacks and developing tailored remediation plans for compromised organizations.
- Familiarity with current threats, vulnerabilities, and attack trends.
- Strong grasp of the ATT&CK framework.
- Understanding of AI security processes with the ability to integrate AI appropriately within IR investigations.
- Excellent organizational skills with the capacity to prioritize and work independently.
Qualifications
- Attention to detail and exceptional accuracy in reporting.
- Strong stakeholder management and communication skills, with excellent command of the English language.
- GIAC certified in at least one discipline (two preferred): GNFA, GCIH, GCIA, GCFE, GCFA, GDAT, etc., or equivalent qualifications (e.g., eLearnSecurity).
- Prior experience in digital forensics is essential; experience in malware analysis is desirable.
- A Bachelor's degree in Computer Science or Engineering is preferred but not mandatory.