img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

Role Overview

Cipher | سايڤر is seeking a Senior DFIR Consultant to join its team in Riyadh. This full-time position involves leading and performing end-to-end Digital Forensics and Incident Response (DFIR) engagements. The role focuses on conducting comprehensive investigations, advanced threat hunting, and developing automation workflows to enhance overall security posture.

Core Responsibilities

  • Lead and perform end-to-end Digital Forensics and Incident Response (DFIR) engagements independently, including incident triage, containment, eradication, recovery, and post-incident reporting.
  • Conduct host, memory, network, cloud, and log-based forensic investigations to determine attack scope, root cause, attacker activities, and business impact.
  • Perform advanced threat hunting across enterprise environments using SIEM, EDR, forensic artifacts, and threat intelligence to proactively identify malicious activity.
  • Develop, maintain, and automate DFIR workflows, forensic tooling, and investigation pipelines using Python, PowerShell, Bash, and other scripting languages.
  • Build and maintain internal DFIR tools, forensic parsers, automation frameworks, and investigation infrastructure.
  • Collaborate with SOC, Detection Engineering, Threat Intelligence, Red Team, and IT teams to improve incident response capabilities and security posture.
  • Conduct incident response readiness and maturity assessments, identifying gaps in people, processes, and technology, and provide actionable recommendations.
  • Produce high-quality technical and executive reports, clearly communicating investigation findings, attack timelines, root cause analysis, and remediation recommendations.
  • Mentor and train team members on digital forensics, incident response methodologies, malware analysis, forensic artifacts, and investigation best practices.

Essential Qualifications

  • Minimum of 6–8 years of hands-on experience in Digital Forensics and Incident Response.
  • Demonstrated experience leading complex incident response engagements from initial detection through remediation and lessons learned.
  • Ability to perform comprehensive incident investigations, root cause analysis, and security maturity assessments.
  • Excellent analytical, problem-solving, and investigative skills.
  • Strong communication skills and the ability to work collaboratively in a consulting environment.

Desirable Experience and Certifications

  • Experience performing cloud incident response across AWS, Azure, or Google Cloud Platform.
  • Experience with enterprise log analysis platforms such as Elasticsearch, Splunk, Microsoft Sentinel, or QRadar.
  • Experience with threat hunting and threat intelligence integration into DFIR investigations.
  • Experience performing malware analysis, reverse engineering, or memory forensics.
  • Experience building DFIR automation pipelines and forensic orchestration platforms.
  • Prior cybersecurity consulting background.
  • Prior offensive security, penetration testing, or purple team experience.
  • An active GitHub account demonstrating DFIR tools, automation projects, or forensic research.
  • Demonstrated home lab or enterprise DFIR lab experience for testing investigations, malware, and attack simulations.
  • Relevant certifications such as GCFA, GCFE, GREM, GCIH, GNFA, GCFR, or equivalent industry-recognized DFIR certifications.

Work Setting and Collaboration

This role is based in Riyadh and operates within a consulting environment. It requires close collaboration with various internal teams, including SOC, Detection Engineering, Threat Intelligence, Red Team, and IT, to enhance incident response capabilities and overall security posture.

Application Information

Candidates who meet the qualifications and experience outlined above are encouraged to apply for this full-time position.


متطلبات الوظيفة

  • تتطلب ٥-١٠ سنوات خبرة

وظائف مشابهة