img
نوع العقددوام كامل
طبيعة الوظيفةبالموقع
الموقعالرياض

وصف الوظيفة

About Exequt

Exequt is a rapidly expanding consulting and technology services firm. We specialize in cybersecurity, Identity and Access Management (IAM), cloud solutions, AI-driven platforms, and custom software engineering. Our firm partners with both public and private sector organizations to deliver high-impact digital transformation initiatives across the Kingdom of Saudi Arabia.

The Role: Cybersecurity Incident Response Specialist

Exequt is seeking a Cybersecurity Incident Response Specialist to join our team in Riyadh, Saudi Arabia. This full-time role focuses on investigating, containing, eradicating, and recovering from security incidents across various client environments, including endpoints, networks, identities, cloud platforms, and applications. The specialist will play a critical role in helping clients effectively respond to and learn from real-world cyber threats.

Key Responsibilities

  • Investigate and respond to cybersecurity incidents such as ransomware, malware, phishing, account compromise, data theft, and lateral movement.
  • Perform incident triage, investigation, containment, eradication, and recovery procedures.
  • Conduct threat hunting activities and perform root-cause analysis for security incidents.
  • Execute basic digital forensics and malware analysis tasks.
  • Identify and analyze Indicators of Compromise (IOCs) and Indicators of Attack (IOAs), mapping attacks to the MITRE ATT&CK framework.
  • Investigate security events within Windows, Linux, Active Directory, and cloud environments.
  • Utilize Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR) platforms for security event investigation.
  • Develop and improve incident response playbooks and detection rules.
  • Prepare detailed incident reports, timelines, and remediation recommendations.
  • Support Security Operations Center (SOC)/Computer Security Incident Response Team (CSIRT) operations and critical incident response efforts.

Required Qualifications and Skills

  • Strong experience in Incident Response (IR), Digital Forensics and Incident Response (DFIR), Security Operations Center (SOC), or Threat Hunting.
  • Hands-on experience with security platforms such as Splunk, Microsoft Sentinel, QRadar, CrowdStrike, SentinelOne, Microsoft Defender, or Cortex XDR.
  • Strong knowledge of Windows and Linux operating systems, as well as networking principles.
  • Proficiency in scripting languages such as PowerShell, Python, or Bash.
  • Strong understanding of the MITRE ATT&CK framework and common attack techniques.
  • Saudi Nationality is required for this position.

Preferred Experience

  • Experience investigating specific incident types including ransomware, phishing, credential theft, and endpoint compromise.

Work Environment and Compensation

This is a full-time position based in Riyadh, Saudi Arabia. Compensation for this role is structured on a performance-based model. We are looking for a dedicated professional who thrives on investigating and neutralizing security threats to join our team.


متطلبات الوظيفة

  • للسعوديين فقط
  • لا تتطلب خبرة

وظائف مشابهة