About the Role:
As a Senior Manager of the Incident Response & Forensics Team within a high-impact and operationally critical cyber defense environment, you live and breathe blue team operations. Your technical expertise in digital forensics and cyber incident response is second only to your integrity and passion for cybersecurity and technology in general. In addition to the technical execution and oversight, you will also own people management.
We seek a leader with a strong technical understanding of how to respond to cyber-attacks and assist organizations with remediation and recovery. You must be able to execute technical assessments and incident response activities as a coordinator and main escalation point for crisis management as well as a key decision maker. In this role, you are expected to get your hands dirty, from analysis tasks to emergency situations at critical industries.
Ready to apply for roles like this?
Unlock the company name and direct application link. Subscribers get instant access to fresh jobs across Dubai, Abu Dhabi and Riyadh, many with visa support.
Unlock employer & apply directly
Responsibilities:
- Take ownership and oversight of a team executing all aspects of reactive & proactive defensive security projects, including a DFIR Lab, for one on-site VIP customer.
- Perform the required duties of the Incident Response and Forensic Team’s Senior Manager (both people management and operational management duties).
- Serve as technical lead on active incident response engagements across different sub-entities for this VIP customer, leading the coordination, investigation, and resolution of large-scale incidents following industry standard processes, e.g. 800-61 r2 PICERL, in a calm and methodical manner utilizing strong technical skills.
- Execute, coordinate, and lead threat-hunting activities in support of incident response, as well as proactive environment assessments and SOC activities.
- Provide subject matter expertise in threat detection and cyber defense domains.
- Take ownership of the DFIR Lab & service for this VIP on-site customer, contributing significantly in a leadership capacity to process documentation and continuous service improvement activities.
- Lead and coordinate host and/or network-based forensics across various platforms.
- Lead and coordinate digital systems and mobile forensic investigations supporting cyber incident response engagements.
- Lead and coordinate the drafting of detailed reports and technical briefs, effectively communicating tasks, methodology, and guidance to VIP on-site customer.
- Use your ability to stay calm and grounded in highly challenging situations to instill trust within client stakeholders and explain technical findings in a manner that can be easily understood by both technical and non-technical stakeholders.
- Demonstrate industry thought leadership through internal brown-bag knowledge sharing sessions and coordinate the team’s topics for such sessions.
- Develop talent within the team by providing constructive and positive direction and support to achieve targets, build capabilities, and take on challenging DFIR & research projects.
- Lead research activities in search of service improvement tasks and better understanding of the threat landscape.
- Lead and nurture a team culture built on trust, respect, appreciation, flexibility, and unity.
- Maintain a flexible schedule that is open to changing situations and opportunities, as this role is related to Incident Response.
- Be a team player with a humble and approachable nature who is willing to go the extra mile.
- Make an impact after the initial couple of weeks of adapting to the new environment.
- Be open to working shifts (as per the team’s schedule) and changing situations and opportunities; the team's shifts will rotate from 6 AM to 2 PM and from 2 PM to 10 PM on a monthly basis, with an on-call rotation of one week every two months.
Technical Skills:
- Expert understanding of blue team operations and threat hunting.
- Deep understanding of digital forensics methodologies and usage of various tools.
- Expert understanding of network protocols, TCP/IP, etc.
- Expert understanding of network forensic principles and applications.
- Expert understanding of Microsoft Windows.
- Strong understanding of Linux and OSX.
- Expert understanding of enterprise IT and IT security infrastructure, using this knowledge to lead strategic recommendations to customers with the help of the DFIR Team, ensuring the best remediation of the managed incidents.
- Strong forensic skills across multiple operating systems.
- Proven experience performing duties utilizing PICERL / NIST IR standards.
Qualifications:
- Strong attention to detail and reporting accuracy.
- Strong English language skills, both spoken and written.
- Minimum of 10 years dedicated to IT security and/or security infrastructure experience.
- At least 6 years in a security role as part of an incident response team (CERT, CSIRT), including 4 years managing incident response teams, or equivalent blue teams (e.g., defense consulting, SOC).
- Previous experience performing digital forensics is a must.
- Scripting skills (Shell, Python, PowerShell) are a plus.
- Must have at least three of the following certifications: CISSP, GCIH, GCFA, GNFA, GCFE, OSCP, GREM, GDAT, or equivalent certifications, as well as experience in the relevant domains.
- Bachelor’s/Master’s degree in computer science or information security desirable, but not mandatory; experience in a similar position is the most important factor.