img
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About Exequt MENA

Exequt MENA is a rapidly expanding consulting and technology services firm based in Riyadh, Saudi Arabia. The company specializes in cybersecurity, Identity and Access Management (IAM), cloud solutions, AI-driven platforms, and custom software engineering. Exequt partners with organizations across both public and private sectors to deliver significant digital transformation initiatives throughout the Kingdom of Saudi Arabia.

The Role: Cybersecurity Incident Response Specialist

Exequt MENA is seeking a full-time Cybersecurity Incident Response Specialist with 0-1 years of experience to join its team in Riyadh. This role involves investigating, containing, eradicating, and recovering from security incidents across various client environments, including endpoints, networks, identities, cloud platforms, and applications. The specialist will play a key role in helping clients respond to and learn from real-world cybersecurity threats.

Key Responsibilities

  • Investigate and respond to cybersecurity incidents such as ransomware, malware, phishing, account compromise, data theft, and lateral movement.
  • Perform incident triage, investigation, containment, eradication, and recovery procedures.
  • Conduct threat hunting activities and root-cause analysis for security incidents.
  • Execute basic digital forensics and malware analysis tasks.
  • Identify and analyze Indicators of Compromise (IOCs) and Indicators of Attack (IOAs), mapping attacks to the MITRE ATT&CK framework.
  • Investigate security events within Windows, Linux, Active Directory, and cloud environments.
  • Utilize Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR) platforms for security event investigation.
  • Develop and improve incident response playbooks and detection rules.
  • Prepare detailed incident reports, timelines, and remediation recommendations.
  • Support Security Operations Center (SOC)/Computer Security Incident Response Team (CSIRT) operations and critical incident response efforts.

Required Qualifications

  • 0-1 years of experience in Incident Response (IR), Digital Forensics and Incident Response (DFIR), Security Operations Center (SOC), or Threat Hunting.
  • Hands-on experience with security platforms such as Splunk, Microsoft Sentinel, QRadar, CrowdStrike, SentinelOne, Microsoft Defender, or Cortex XDR.
  • Strong knowledge of Windows/Linux operating systems and networking principles.
  • Proficiency in scripting languages such as PowerShell, Python, or Bash.
  • Strong understanding of the MITRE ATT&CK framework and common attack techniques.
  • Saudi Nationality is required for this position.

Preferred Skills and Attributes

  • Experience investigating specific types of incidents, including ransomware, phishing, credential theft, and endpoint compromise.

Compensation and Benefits

  • Performance-based compensation structure.
  • Bupa medical insurance (Golden Tier).
  • Ongoing training and mentorship from experienced leadership.
  • Exposure to high-impact projects with leading clients in Saudi Arabia.
  • A collaborative, growth-oriented company culture.

Requirements

  • For Saudis Only
  • No experience required

Similar Jobs