About the Role
Geidea, established in 2008, is a leading provider of digital payment solutions focused on innovation and customer service. The company is seeking a skilled Cybersecurity Defense DFIR Specialist to join its team in Riyadh, Saudi Arabia. This role is integral to identifying, investigating, and responding to cyber incidents across the organization, enhancing security posture and resilience through collaboration with SOC and threat intelligence teams.
Role Purpose and Responsibilities
The primary objective of this position is to manage the full lifecycle of incident response, from identification through to recovery. The specialist will conduct rapid triage and analysis of security alerts, logs, network traffic, and endpoint telemetry. Key responsibilities include documenting incident timelines and findings, providing actionable recommendations, and performing forensic acquisition and analysis of various systems and devices. This role also involves preserving digital evidence and providing feedback to improve detection capabilities and incident response playbooks.
- Lead or support incident response activities, including identification, containment, eradication, and recovery.
- Perform rapid triage and analysis of security alerts, logs, network traffic, and endpoint telemetry.
- Document incident timelines, technical findings, and provide actionable recommendations.
- Conduct forensic acquisition and analysis of endpoints, servers, cloud systems, and mobile devices.
- Perform disk, memory, and malware analysis to identify attacker activity and assess impact.
- Preserve and maintain the chain-of-custody for all digital evidence.
- Provide feedback to SOC and detection engineering teams to enhance alerting and response playbooks.
Qualifications and Experience
Candidates should possess a Bachelor’s degree in Computer Science, Information Technology, Telecommunications, Electronics & Electrical, or a related field. A minimum of 3 years of experience in cybersecurity operations, including roles within SOC, DFIR, or cyber defense, is required. Relevant certifications such as CompTIA Security+, GCIH, GCFE, or GCFA are preferred. The role also requires a strong understanding of security concepts, best practice security frameworks (NIST, SAMA CSF, OWASP, ISO 27001, PCI-DSS), and cybersecurity incident response principles.
- Bachelor’s degree in Computer Science, Information Technology, Telecommunications, Electronics & Electrical, or a related field.
- 3+ years of experience in cybersecurity operations (SOC, DFIR, cyber defense).
- Relevant certifications (*, CompTIA Security+, GCIH, GCFE, GCFA).
- In-depth knowledge of cyber-attacks, threat vectors, and incident management.
- Thorough understanding of security frameworks including NIST, SAMA CSF, OWASP, ISO 27001, and PCI-DSS.
- Experience with Cybersecurity Incident Response.
Technical Proficiency
Proficiency in Security Information and Event Management (SIEM) systems is essential. Experience with EDR, IDS/IPS, DLP, and SOAR solutions is also required. Knowledge of Cloud Security principles and experience with platforms such as AWS, OCI, GCP, or Azure is necessary. Familiarity with Email Security best practices and experience in packet analysis are also key technical requirements for this role.
- Proficiency in Security Information and Event Management (SIEM) systems.
- Experience with EDR, IDS/IPS, DLP, and SOAR solutions.
- Knowledge of Cloud Security principles and experience with AWS, OCI, GCP, or Azure.
- Familiarity with Email Security best practices.
- Experience in packet analysis.
- Understanding of IS security controls and monitoring systems.
Key Skills and Competencies
Beyond technical skills, the role requires strong analytical and problem-solving abilities. Effective communication skills are important for documenting findings and providing recommendations to stakeholders. A solid understanding of cyber-attacks, techniques, and threat vectors is fundamental. Familiarity with IS security controls and monitoring systems, and how business drivers impact security policy, is also expected.
- Cybersecurity Incident Response
- Digital Forensics
- Threat Analysis
- Incident Management
- Understanding of Cyber-attacks and techniques
- Understanding of Threat vectors
- Knowledge of NIST, SAMA CSF, OWASP, ISO 27001, and PCI-DSS frameworks
- Communication Skills
- Problem-solving Skills
Work Location and Type
This is a full-time position based in Riyadh, Saudi Arabia. The role requires 2-5 years of relevant experience.