About the Role
As a key member of the DFIR team, you will own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure. This involves everything from initial triage to root cause analysis, including the identification of indicators of compromise (IoC), data exfiltration, and unauthorized access. You will coordinate and lead the DFIR team through active investigations, ensuring a consistent methodology, integrity of evidence, and a swift investigative process.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- Conduct thorough forensic investigations across various environments including endpoints, cloud platforms, and network infrastructure.
- Lead and coordinate the DFIR team during active investigations, maintaining consistency in methodology and preserving evidence integrity.
- Analyze logs from various platforms such as EDR/XDR, SIEM, DLP, IdP, and email gateways to accurately reconstruct attack and user activity timelines.
- Acquire forensic images from laptops, mobile devices, servers, and cloud repositories while ensuring full chain of custody.
- Investigate artifacts including file systems, memory, registry, logs, and configuration states to reconstruct events with precision.
- Correlate telemetry from endpoints, networks, and identities to form a cohesive understanding of attacker behavior and system access.
- Implement AI-assisted workflows to automate evidence collection, pattern detection, and timeline generation to enhance investigative capacity.
- Present technical findings in clear, chronological narratives suitable for executives and cross-functional stakeholders, avoiding jargon and ambiguity.
- Utilize investigation outcomes to improve detection rules, access controls, and policies.
Education
- Bachelor’s degree in Cybersecurity, International Relations, Computer Science, or a related field.
Experience
- Minimum of 5 years in digital forensics, incident response, or security investigations, with experience leading or coordinating DFIR engagements.
- Exceptional written and verbal communication skills in both English and Arabic.
- Hands-on proficiency with forensic tools such as FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms.
- Strong understanding of network protocols (TCP/IP, HTTP/S, DNS) and expertise in log analysis across SIEM platforms.
- Proficient in scripting languages (Python, PowerShell, or Bash) for automating evidence processing.
- Deep knowledge of Windows, macOS, and Linux/Unix environments at both the artifact and system level.
- Proven experience in integrating AI tools into investigative workflows to enhance triage, pattern detection, or reporting processes.
- Clear and confident communicator, capable of briefing executives and collaborating with legal, HR, and compliance teams while maintaining technical accuracy.
- Ensures all operations comply with NCA ECC and SAMA CSF regulations.
- Saudi nationality is required.
Certifications (Highly Preferred)
- SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar)
- IACIS CFCE
- EC-Council CHFI
- Offsec (OSDA, OSIR)
Benefits
- Impact that Matters: Build products that shape the future of cybersecurity and protect organizations globally.
- On-Site Collaboration: Work in our Almadina office alongside passionate experts.
- Continuous Growth: Gain access to certifications, training, and opportunities for skill enhancement.
- Ownership Mindset: Participate in our Employee Stock Ownership Plan (ESOP) and grow with the company's success.
- Culture of Trust: A workplace that empowers talent, encourages personal ownership, and celebrates tangible outcomes.