img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About Red Sea Global

Red Sea Global (RSG) is a purpose-driven developer focused on positively shaping the places people live, work, and travel. The company's programs contribute to achieving Vision 2030 and advancing regenerative tourism globally. This full-time role is based in Riyadh, Saudi Arabia.

Role Summary

The Assistant Manager Digital Forensics and Incident Response will manage and oversee RSG's Digital Forensics and Incident Response (DFIR) function. This includes incident triage, containment, recovery, digital forensic investigations, malware and artifact analysis, threat hunting, and post-incident reporting across RSG's corporate, cloud, and operational technology environments. The role ensures security incidents are detected, investigated, and resolved within agreed service levels, with evidence preserved in a defensible manner, and DFIR practices aligned with RSG's organizational strategy, risk appetite, and applicable national and international standards.

Key Responsibilities

  • Manage the configuration, tuning, and daily operation of DFIR tooling, including endpoint detection and response, forensic acquisition and analysis platforms, and log/telemetry sources.
  • Ensure incident response and forensic practices comply with RSG's information security policies, regulatory requirements, and national/international standards (*, NCA ECC, PDPL, ISO 27001, NIST SP 800-61).
  • Manage the development and maintenance of the incident response plan, playbooks, severity classification, and escalation matrix.
  • Ensure timely triage, containment, eradication, and recovery of security incidents, prioritized by business impact and closed within agreed service levels.
  • Manage forensic evidence acquisition and handling, ensuring chain of custody, integrity verification, and defensible preservation.
  • Oversee technical investigations of malware, intrusion, insider, and data exfiltration cases, including host, memory, network, identity, and cloud artifact analysis.
  • Manage the quality and timeliness of incident reports, executive summaries, and post-incident reviews, tracking actionable findings and corrective actions.
  • Oversee proactive threat hunting across endpoint, network, cloud, and identity telemetry, using threat intelligence and adversary techniques mapped to frameworks like MITRE ATT&CK.
  • Ensure DFIR readiness through tabletop exercises, attack simulation, purple-team testing, and formal validation of response and recovery objectives.
  • Manage the automation of investigation and response actions through orchestration playbooks and scripting.
  • Ensure all DFIR processes, technical configurations, and standard operating procedures are documented, maintained, and communicated.
  • Oversee the integration of cyber threat intelligence into detection, hunting, and response workflows.
  • Oversee vendor and service-provider relationships for DFIR technologies and retained incident response services.
  • Act as an escalation point for high-severity, sensitive, or legally significant incidents, validating risk and ensuring appropriate approvals and notifications.

Managerial Responsibilities

  • Provide input into the Department's cybersecurity strategy from the DFIR Section perspective.
  • Develop Section objectives, KPIs, and annual operational plans for incident response, digital forensics, threat hunting, and investigation reporting.
  • Contribute to budget preparation and monitor financial performance of DFIR-related initiatives.
  • Implement and ensure adherence to Section policies, standards, and procedures for incident response and digital forensics.
  • Ensure effective staffing, development, and deployment of the DFIR team, including on-call and shift coverage.

Qualifications and Requirements

  • 5-10 years of relevant experience.
  • Participation in a defined 24/7 on-call escalation rota for security incidents.
  • Readiness to travel to site for evidence acquisition when required.

Requirements

  • Requires 2-5 Years experience

Similar Jobs