img
SalarySR33,000 / Month
Contract TypeFull-time
Workplace typeOn-site
LocationRiyadh

Job Description

About the Role

Robert Walters is seeking a Senior DFIR & Incident Response Expert to join a growing cybersecurity team in Riyadh, Saudi Arabia. This full-time position is a hands-on technical and leadership role for an experienced investigator who will lead complex forensic investigations, coordinate DFIR activities, and help organizations respond to evolving cyber threats. The role requires 5-10 years of experience.

Role Context

The successful candidate will work across endpoint, cloud, and network environments, combining deep forensic expertise with advanced investigation techniques, automation, and AI-assisted workflows. This position plays a key role in identifying the root cause of incidents, reconstructing attacker activity, and translating technical findings into actionable recommendations for senior stakeholders.

Key Responsibilities

  • Lead end-to-end digital forensic investigations across endpoints, cloud platforms, and network infrastructure, from initial triage through root-cause analysis and reporting.
  • Coordinate and guide DFIR teams during active investigations, ensuring consistent methodologies, evidence integrity, and timely outcomes.
  • Analyze telemetry and logs from EDR/XDR, SIEM, DLP, identity platforms, and email security gateways to reconstruct detailed attack and user activity timelines.
  • Acquire and analyze forensic images from laptops, mobile devices, servers, and cloud repositories while maintaining a robust chain of custody.
  • Investigate forensic artifacts, including file systems, memory, Windows Registry, system logs, and configuration data, to establish incident details.
  • Correlate endpoint, network, and identity telemetry to develop a comprehensive understanding of attacker behavior, access patterns, and potential data exfiltration.
  • Develop AI-assisted workflows to automate evidence collection, pattern detection, and timeline generation, improving investigative efficiency.
  • Present technical findings through clear, chronological, and actionable reports for executives and cross-functional stakeholders.
  • Collaborate with legal, HR, and compliance teams while maintaining investigative accuracy and confidentiality.
  • Translate investigation outcomes into improvements for detection rules, access controls, security policies, and incident response processes.
  • Ensure investigative activities align with applicable cybersecurity and regulatory requirements, including NCA ECC and SAMA CSF.

Qualifications and Requirements

  • Saudi National is a mandatory requirement.
  • Proven experience leading or coordinating DFIR investigations and engagements.
  • Previous leadership experience, including guiding investigators or coordinating response activities.
  • Strong hands-on experience with forensic investigation tools such as FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms.
  • Solid understanding of network protocols, including TCP/IP, HTTP/S, and DNS, alongside practical SIEM log analysis experience.
  • Proficiency in Python, PowerShell, or Bash, with experience automating evidence collection, processing, or investigative workflows.
  • Deep technical knowledge of Windows, macOS, and Linux/Unix systems, including system-level and forensic artifacts.
  • Demonstrated experience using AI tools or developing AI-assisted workflows to improve investigative triage, pattern detection, or reporting.
  • Strong understanding of incident response methodologies, evidence preservation, and forensic investigation practices.
  • Familiarity with NCA ECC and SAMA CSF compliance requirements.

Preferred Certifications

Candidates with one or more of the following certifications are preferred:

  • SANS / GIAC - GCFA, GCFE, GNFA, GCIA, or equivalent.
  • IACIS CFCE.
  • EC-Council CHFI.
  • OffSec - OSDA, OSIR, or equivalent.

Requirements

  • For Saudis Only
  • Requires 5-10 Years experience

Similar Jobs