About the Role
As a key player in our Digital Forensics and Incident Response (DFIR) team, you will own end-to-end forensic investigations across endpoints, cloud platforms, and network infrastructure. Your mission will encompass everything from initial triage to root cause analysis, including identifying Indicators of Compromise (IoC), data exfiltration, and unauthorized access. You will coordinate and lead the DFIR team through active investigations, ensuring a consistent methodology, the integrity of evidence, and a high investigative velocity.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities
- Own end-to-end forensic investigations across various platforms.
- Coordinate and lead the DFIR team during active investigations.
- Analyze logs from EDR/XDR, SIEM, DLP, IdP, and email gateways to reconstruct attack and user activity timelines.
- Acquire forensic images from laptops, mobile devices, servers, and cloud repositories while maintaining full chain of custody.
- Dive deep into artifacts, including file systems, memory, registry, logs, and config states, to accurately reconstruct events.
- Correlate endpoint, network, and identity telemetry to form a coherent picture of attacker behavior and system access.
- Build AI-assisted workflows to automate evidence collection, pattern detection, and timeline generation, thereby scaling investigative capacity.
- Translate technical findings into clear, chronological narratives for executives and cross-functional stakeholders, avoiding jargon and ambiguity.
- Ensure a feedback loop by incorporating investigation outcomes back into detection rules, access controls, and policy improvements.
Education
- Bachelor’s degree in Cybersecurity, International Relations, Computer Science, or a related field.
Experience
- 5+ years in digital forensics, incident response, or security investigations, with a successful track record of leading or coordinating DFIR engagements.
- Exceptional written and verbal communication skills in both English and Arabic.
- Hands-on proficiency with forensic tools such as FTK, X-Ways, Cellebrite, Axiom, or similar platforms.
- Strong understanding of network protocols (TCP/IP, HTTP/S, DNS) and log analysis across SIEM platforms.
- Proficiency in scripting with Python, PowerShell, or Bash for automating evidence processing.
- Deep working knowledge of Windows, macOS, and Linux/Unix environments at the artifact and system level.
- Proven experience in integrating AI tools into investigative workflows to enhance triage, pattern detection, or reporting.
- Ability to communicate clearly and confidently to executives and collaborate with legal, HR, and compliance teams while maintaining technical precision.
- Ensure that all operations align with NCA ECC and SAMA CSF regulations.
- Saudi nationality is required.
Certifications (Highly Preferred)
- SANS / GIAC (GCFA, GCFE, GNFA, GCIA or similar).
- IACIS CFCE.
- EC-Council CHFI.
- Offsec (OSDA, OSIR).
Benefits
- Impactful Work: Contribute to products that shape the future of cybersecurity and protect organizations globally.
- On-Site Collaboration: Work in our Almadina office alongside passionate experts in a collaborative environment.
- Continuous Growth: Access certification opportunities, trainings, and resources to enhance your expertise.
- Ownership Mindset: Participate in our Employee Stock Ownership Plan (ESOP) and grow with the company’s success.
- Culture of Trust: Be part of a culture that empowers talent, encourages ownership, and celebrates real outcomes.