About the Role:
As a Senior Manager of the Incident Response & Forensics Team within a high-impact and operationally critical cyber defence environment, you will live and breathe blue team operations. Your technical expertise in digital forensics and cyber incident response is second only to your integrity and passion for cyber security and technology in general. In addition to technical execution and oversight, you will also take ownership of people management.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
We seek a leader with a strong technical understanding of how to respond to cyber-attacks and assist organizations with remediation and recovery. You must be able to execute technical assessments and incident response activities as a coordinator and main escalation point for crisis management, as well as act as a key decision maker. This role requires you to engage in hands-on activities, ranging from analysis tasks to managing emergency situations in critical industries.
Responsibilities:
- Take ownership and oversight of a team who executes all aspects of reactive & proactive defensive security projects, including a DFIR Lab, for one on-site VIP customer.
- Perform the required duties of the Incident Response and Forensic Team’s Senior Manager, encompassing both people management and operational management duties.
- Serve as the technical lead on active incident response engagements across different sub-entities for this VIP customer.
- Lead and execute the coordination, investigation, and resolution of large-scale incidents following industry-standard processes (e.g., 800-61 r2 PICERL) in a calm and methodical manner utilizing your strong technical skills.
- Execute, coordinate, and lead threat hunting activities in support of incident response, proactive environment assessments, and SOC activities.
- Provide subject matter expertise in the threat detection and cyber defense domains.
- Take ownership of the DFIR Lab & service for this VIP on-site customer, contributing significantly in a leadership capacity toward process documentation and continuous service improvement activities.
- Lead and coordinate host and/or network-based forensics across various platforms.
- Lead and coordinate digital systems and mobile forensic investigations supporting cyber incident response engagements.
- Draft detailed reports and technical briefs, effectively communicating tasks, methodology, and guidance to the VIP on-site customer.
- Maintain composure in highly challenging situations to instill trust among client stakeholders; communicate technical findings in an understandable manner for both technical and non-technical stakeholders.
- Demonstrate industry thought leadership through internal knowledge-sharing sessions, coordinating the team’s topics for such sessions.
- Develop talent within the team by providing constructive direction and support to achieve targets, build capabilities, and take on challenging DFIR & research projects.
- Lead research activities aiming at service improvement tasks and better understanding of the threat landscape.
- Foster and nurture a team culture built on trust, respect, appreciation, flexibility, and unity.
- Prepare for a flexible schedule that accommodates changing situations and opportunities, as with any position related to Incident Response.
- Be a team player with a humble and approachable nature, willing to go the extra mile.
- Ensure capability to make an impact within the initial weeks of adapting to the new environment.
- This role does not involve set shifts, but the team’s shifts will rotate monthly from 6 AM to 2 PM and from 2 PM to 10 PM, with an on-call rotation once every two months lasting one week.
Technical Skills:
- Expert understanding of blue team operations and threat hunting.
- Deep understanding of digital forensics methodologies as well as the usage of various tools.
- Expert understanding of network protocols, TCP/IP, etc.
- Expert knowledge of network forensic principles and applications.
- Expert understanding of Microsoft Windows; strong understanding of Linux and OSX.
- Expert comprehension of enterprise IT and IT security infrastructure to lead strategic recommendations for customers, in collaboration with the DFIR Team, ensuring the proper remediation of managed incidents.
- Strong forensic skills across multiple operating systems.
- Proven experience performing duties utilizing PICERL / NIST IR standards.
Qualifications:
- Strong attention to detail and reporting accuracy.
- Strong English language skills, both spoken and written.
- Minimum 10 years dedicated to IT security and/or security infrastructure experience.
- At least 6 years in a security role as part of an incident response team (CERT, CSIRT), including 4 years managing incident response teams, or equivalent blue teams (e.g., defense consulting, SOC).
- Previous experience performing digital forensics is a MUST.
- Scripting skills in Shell, Python, or PowerShell are a plus.
- Must hold at least three of the following certifications: CISSP, GCIH, GCFA, GNFA, GCFE, OSCP, GREM, GDAT, or equivalent certifications along with experience in the relevant domains.
- A Bachelor’s/Master’s degree in computer science or information security is desirable but not mandatory; experience in a similar position is the most important factor.