Company logo hidden

Senior Manager - Incident Response (CPX)

Unlock employer Abu Dhabi, United Arab Emirates Direct to Company 1 hour ago · 14 Sep 2026

Financial

  • Estimate: $90k - $150k*
  • Zero income tax location

Accessibility

  • Office Only
  • Visa Provided

Requirements

  • Experience: Senior
  • English: Professional

Position

About the Role:
As a Senior Manager of the Incident Response & Forensics Team within a high-impact and operationally critical cyber defence environment, you will take charge of blue team operations. Your technical expertise in digital forensics and cyber incident response is paramount, matched only by your integrity and passion for cyber security and technology. In addition to executing technical tasks and overseeing operations, you will be responsible for people management. We seek a leader with a thorough technical understanding of responding to cyber-attacks and assisting organizations in remediation and recovery. You will coordinate and act as the main escalation point for crisis management, making key decisions during emergencies in critical industries.

Ready to apply for roles like this?

Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.

Unlock employer & apply directly

Responsibilities:

  • Take ownership and oversight of a team executing all aspects of reactive and proactive defensive security projects, including a DFIR Lab, for one on-site VIP customer.
  • Perform the necessary duties of the Incident Response and Forensics Team’s Senior Manager (both people and operational management).
  • Serve as the technical lead on active incident response engagements across different sub-entities for the VIP customer.
  • Lead and execute coordination, investigation, and resolution of large-scale incidents in accordance with industry standard processes (e.g., 800-61 r2 PICERL) in a calm and methodical manner, utilizing strong technical skills.
  • Execute, coordinate, and lead threat hunting activities in support of incident response, along with proactive environment assessments and SOC activities.
  • Provide subject matter expertise in threat detection and cyber defence domains.
  • Own the DFIR Lab and service for the VIP customer, contributing to process documentation and continuous service improvement activities.
  • Coordinate host and/or network-based forensics across various platforms.
  • Lead and coordinate digital systems and mobile forensic investigations supporting cyber incident response engagements.
  • Prepare detailed reports and technical briefs, clearly communicating tasks, methodology, and guidance to the VIP customer.
  • Maintain trust with client stakeholders by explaining technical findings in layman's terms.
  • Demonstrate thought leadership through internal knowledge sharing sessions and coordinate team topics for these sessions.
  • Develop team talent by providing constructive direction and fostering capabilities for DFIR and research projects.
  • Conduct research for service improvements and a better understanding of the threat landscape.
  • Foster a team culture based on trust, respect, appreciation, flexibility, and unity.
  • Maintain a flexible schedule that adapts to changing situations and opportunities associated with Incident Response.
  • Be a team player with a humble and approachable nature who is willing to go the extra mile.
  • Create an impact within the first few weeks in the new environment, with a flexible schedule accommodating shifts from 6 AM to 2 PM and 2 PM to 10 PM on a monthly basis, alongside an on-call rotation for one week every two months.

Technical Skills:

  • Expert understanding of blue team operations and threat hunting.
  • Deep understanding of digital forensics methodologies and tools.
  • Expert understanding of network protocols, TCP/IP, and network forensic principles and applications.
  • Expert knowledge of Microsoft Windows, alongside strong understanding of Linux and OSX.
  • Extensive expertise in enterprise IT and IT Security infrastructure to lead strategic recommendations for incident remediation.
  • Proven forensic skills across multiple operating systems, with experience in utilizing PICERL / NIST IR standards.

Qualifications:

  • Strong attention to detail and accuracy in reporting.
  • Proficient English language skills, both spoken and written.
  • Minimum of 10 years of experience in IT security and/or security infrastructure.
  • At least 6 years in a security role as part of an incident response team (CERT, CSIRT), including a minimum of 4 years managing incident response teams or equivalent blue team roles (e.g., defense consulting, SOC).
  • Previous experience in digital forensics is mandatory.
  • Scripting skills (Shell, Python, PowerShell) are advantageous.
  • Must possess at least three of the following certifications: CISSP, GCIH, GCFA, GNFA, GCFE, OSCP, GREM, GDAT, or equivalent certifications, along with relevant experience.
  • A Bachelor’s or Master’s degree in computer science or information security is desirable but not mandatory; experience in a similar position is the most important factor.
Apply Direct

Jobs you might like   View all jobs

About Computer and Network Security Company

Company details are hidden. Subscribe to view full company profile.

Ready to apply for this role?

Apply Direct