Senior DFIR & Incident Response Expert Saudi National

Robert Walters• Riyadh, Saudi Arabia

Full time
TypeFull time
LocationRiyadh, Saudi Arabia
Posted1d ago

Job description

About the Role

;">Robert Walters is seeking a Senior DFIR & Incident Response Expert to join a growing cybersecurity team in Riyadh, Saudi Arabia. This full-time position is a hands-on technical and leadership role for an experienced investigator who will lead complex forensic investigations, coordinate DFIR activities, and help organizations respond to evolving cyber threats. The role requires 5-10 years of experience.

Role Context

********;">The successful candidate will work across endpoint, cloud, and network environments, combining deep forensic expertise with advanced investigation techniques, automation, and AI-assisted workflows. This position plays a key role in identifying the root cause of incidents, reconstructing attacker activity, and translating technical findings into actionable recommendations for senior stakeholders.

Key Responsibilities

• Lead end-to-end digital forensic investigations across endpoints, cloud platforms, and network infrastructure, from initial triage through root-cause analysis and reporting.

• Coordinate and guide DFIR teams during active investigations, ensuring consistent methodologies, evidence integrity, and timely outcomes.

• Analyze telemetry and logs from EDR/XDR, SIEM, DLP, identity platforms, and email security gateways to reconstruct detailed attack and user activity timelines.

• Acquire and analyze forensic images from laptops, mobile devices, servers, and cloud repositories while maintaining a robust chain of custody.

• Investigate forensic artifacts, including file systems, memory, Windows Registry, system logs, and configuration data, to establish incident details.

• Correlate endpoint, network, and identity telemetry to develop a comprehensive understanding of attacker behavior, access patterns, and potential data exfiltration.

• Develop AI-assisted workflows to automate evidence collection, pattern detection, and timeline generation, improving investigative efficiency.

• Present technical findings through clear, chronological, and actionable reports for executives and cross-functional stakeholders.

• Collaborate with legal, HR, and compliance teams while maintaining investigative accuracy and confidentiality.

• Translate investigation outcomes into improvements for detection rules, access controls, security policies, and incident response processes.

• Ensure investigative activities align with applicable cybersecurity and regulatory requirements, including NCA ECC and SAMA CSF.

Qualifications and Requirements

• Saudi National is a mandatory requirement.

• Proven experience leading or coordinating DFIR investigations and engagements.

• Previous leadership experience, including guiding investigators or coordinating response activities.

• Strong hands-on experience with forensic investigation tools such as FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms.

• Solid understanding of network protocols, including TCP/IP, HTTP/S, and DNS, alongside practical SIEM log analysis experience.

• Proficiency in Python, PowerShell, or Bash, with experience automating evidence collection, processing, or investigative workflows.

• Deep technical knowledge of Windows, macOS, and Linux/Unix systems, including system-level and forensic artifacts.

• Demonstrated experience using AI tools or developing AI-assisted workflows to improve investigative triage, pattern detection, or reporting.

• Strong understanding of incident response methodologies, evidence preservation, and forensic investigation practices.

• Familiarity with NCA ECC and SAMA CSF compliance requirements.

Preferred Certifications

**********;">Candidates with one or more of the following certifications are preferred:

• SANS / GIAC - GCFA, GCFE, GNFA, GCIA, or equivalent.

• IACIS CFCE.

• EC-Council CHFI.

• OffSec - OSDA, OSIR, or equivalent.
Apply now You'll be taken to the employer's application page.