📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة وظائف تناسب سيرتك الذاتيةمجاناً قناة تيليجرام

وظيفة خبير أول في DFIR والاستجابة للحوادث لدى Robert Walters في الرياض

Senior DFIR & Incident Response Expert - Saudi National
🕒 نُشرت: (منذ 16 يوماً) 📍 الرياض وظائف الهندسة والتقنية

تفاصيل الوظيفة

تعلن شركة Robert Walters عن توفر فرصة وظيفية في الرياض للسعوديين فقط، لوظيفة خبير أول في التحقيق الرقمي والاستجابة للحوادث (Senior DFIR & Incident Response Expert).

المهام والمسؤوليات

  • قيادة تحقيقات الطب الشرعي الرقمي الشاملة (End-to-End) عبر نقاط النهاية والمنصات السحابية والبنية التحتية للشبكات، من التقييم الأولي إلى تحليل السبب الجذري وإعداد التقارير.
  • تنسيق وتوجيه فرق DFIR أثناء التحقيقات النشطة، مع ضمان اتساق المنهجيات وسلامة الأدلة وتحقيق النتائج في الوقت المناسب.
  • تحليل بيانات التتبع والسجلات من أنظمة EDR/XDR و SIEM و DLP ومنصات الهوية وبوابات أمان البريد الإلكتروني لإعادة بناء جداول زمنية مفصلة لنشاط المهاجمين والمستخدمين.
  • الحصول على صور الطب الشرعي من أجهزة الكمبيوتر المحمولة والأجهزة المحمولة والخوادم والمستودعات السحابية وتحليلها مع الحفاظ على سلسلة عهدة موثقة.
  • التحقيق في أدلة الطب الشرعي الرقمي، بما في ذلك أنظمة الملفات والذاكرة وسجل نظام Windows وسجلات النظام وبيانات التكوين، لتحديد ما حدث ومتى.
  • ربط بيانات النقاط الطرفية والشبكات والهوية لتطوير فهم شامل لسلوك المهاجم وأنماط الوصول واحتمالية تسريب البيانات.
  • تطوير سير عمل مدعوم بالذكاء الاصطناعي لأتمتة جمع الأدلة واكتشاف الأنماط وتوليد الجداول الزمنية، مما يحسن كفاءة التحقيق.
  • تقديم النتائج التقنية من خلال تقارير واضحة وقابلة للتنفيذ زمنياً للمديرين التنفيذيين وأصحاب المصلحة عبر الأقسام.
  • التعاون مع فرق الشؤون القانونية والموارد البشرية والامتثال مع الحفاظ على دقة التحقيق وسريته.
  • ترجمة نتائج التحقيق إلى تحسينات في قواعد الكشف وعناصر التحكم في الوصول وسياسات الأمان وعمليات الاستجابة للحوادث.
  • ضمان توافق أنشطة التحقيق مع متطلبات الأمن السيبراني والتنظيمية ذات الصلة، بما في ذلك NCA ECC و SAMA CSF.

الشروط والمتطلبات

  • درجة البكالوريوس في علوم الحاسب أو الأمن السيبراني أو الطب الشرعي الرقمي أو تخصص ذي صلة.
  • الجنسية السعودية (شرط أساسي).
  • خبرة لا تقل عن 7 سنوات في الطب الشرعي الرقمي أو الاستجابة للحوادث أو تحقيقات الأمن السيبراني.
  • خبرة مثبتة في قيادة أو تنسيق تحقيقات ومهام DFIR.
  • خبرة قيادية سابقة، بما في ذلك توجيه المحققين أو تنسيق أنشطة الاستجابة (أمر أساسي).
  • خبرة عملية قوية في استخدام أدوات التحقيق الجنائي مثل FTK و X-Ways و Cellebrite و Axiom أو ما يعادلها.
  • فهم متين لبروتوكولات الشبكات (TCP/IP و HTTP/S و DNS) إلى جانب خبرة عملية في تحليل سجلات SIEM.
  • إتقان استخدام Python أو PowerShell أو Bash، مع خبرة في أتمتة جمع الأدلة أو معالجتها أو سير عمل التحقيق.
  • معرفة تقنية عميقة بأنظمة Windows و macOS و Linux/Unix، بما في ذلك الأدلة على مستوى النظام والطب الشرعي.
  • خبرة مثبتة في استخدام أدوات الذكاء الاصطناعي أو تطوير سير عمل مدعوم بالذكاء الاصطناعي لتحسين فرز التحقيق أو اكتشاف الأنماط أو إعداد التقارير.
  • فهم قوي لمنهجيات الاستجابة للحوادث والحفاظ على الأدلة وممارسات الطب الشرعي الرقمي.
  • الإلمام بمتطلبات الامتثال NCA ECC و SAMA CSF.
  • الشهادات المفضلة: إحدى الشهادات التالية أو ما يعادلها: SANS/GIAC (GCFA, GCFE, GNFA, GCIA)، IACIS CFCE، EC-Council CHFI، OffSec (OSDA, OSIR).
عرض النص الأصلي للإعلان

We are seeking an experienced Expert Digital Forensics & Incident Response (DFIR) professional to join a growing cybersecurity team in Riyadh. This is a hands-on technical and leadership role for an experienced investigator who can lead complex forensic investigations, coordinate DFIR activities and help organisations respond to evolving cyber threats.

The successful candidate will work across endpoint, cloud and network environments, combining deep forensic expertise with advanced investigation techniques, automation and AI-assisted workflows. You will play a key role in identifying the root cause of incidents, reconstructing attacker activity and translating technical findings into actionable recommendations for senior stakeholders.

Key Responsibilities

  • Lead end-to-end digital forensic investigations across endpoints, cloud platforms and network infrastructure, from initial triage through root-cause analysis and reporting.
  • Coordinate and guide DFIR teams during active investigations, ensuring consistent methodologies, evidence integrity and timely outcomes.
  • Analyse telemetry and logs from EDR/XDR, SIEM, DLP, identity platforms and email security gateways to reconstruct detailed attack and user activity timelines.
  • Acquire and analyse forensic images from laptops, mobile devices, servers and cloud repositories while maintaining a robust chain of custody.
  • Investigate forensic artefacts, including file systems, memory, Windows Registry, system logs and configuration data, to establish what happened and when.
  • Correlate endpoint, network and identity telemetry to develop a comprehensive understanding of attacker behaviour, access patterns and potential data exfiltration.
  • Develop AI-assisted workflows to automate evidence collection, pattern detection and timeline generation, improving investigative efficiency.
  • Present technical findings through clear, chronological and actionable reports for executives and cross-functional stakeholders.
  • Collaborate with legal, HR and compliance teams while maintaining investigative accuracy and confidentiality.
  • Translate investigation outcomes into improvements to detection rules, access controls, security policies and incident response processes.
  • Ensure investigative activities align with applicable cybersecurity and regulatory requirements, including NCA ECC and SAMA CSF.

Requirements & Qualifications

Education

  • Bachelor's degree in Computer Science, Cybersecurity, Digital Forensics or a related discipline.

Professional Experience

  • Saudi National is a must
  • 7+ years of experience in digital forensics, incident response or cybersecurity investigations.
  • Proven experience leading or coordinating DFIR investigations and engagements.
  • Previous leadership experience, including guiding investigators or coordinating response activities, is essential.
  • Strong hands-on experience with forensic investigation tools such as FTK, X-Ways, Cellebrite, Axiom or equivalent platforms.
  • Solid understanding of network protocols, including TCP/IP, HTTP/S and DNS, alongside practical SIEM log analysis experience.
  • Proficiency in Python, PowerShell or Bash, with experience automating evidence collection, processing or investigative workflows.
  • Deep technical knowledge of Windows, macOS and Linux/Unix systems, including system-level and forensic artefacts.
  • Demonstrated experience using AI tools or developing AI-assisted workflows to improve investigative triage, pattern detection or reporting.
  • Strong understanding of incident response methodologies, evidence preservation and forensic investigation practices.
  • Familiarity with NCA ECC and SAMA CSF compliance requirements.

Preferred Certifications

Candidates with one or more of the following certifications are highly preferred:

  • SANS / GIAC - GCFA, GCFE, GNFA, GCIA or equivalent.
  • IACIS CFCE.
  • EC-Council CHFI.
  • OffSec - OSDA, OSIR or equivalent.

المصدر: LinkedIn - أُضيفت للموقع في 23 سبتمبر 2026
رقم الإعلان لدى المصدر: 4468990210