📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة مستشار DFIR أول لدى سايڤر في الرياض

Senior DFIR Consultant
🏢 Cipher | سايڤر
🕒 نُشرت: (أمس) 📍 الرياض وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

تعلن شركة Cipher | سايڤر عن توفر وظيفة Senior DFIR Consultant في الرياض، السعودية.

المهام والمسؤوليات

  • قيادة وتنفيذ مهام التحقيق الرقمي والاستجابة للحوادث (DFIR) بشكل مستقل من البداية إلى النهاية، بما في ذلك الفرز الأولي، الاحتواء، الاستئصال، الاسترداد، وإعداد التقارير بعد الحادثة.
  • إجراء تحقيقات في أنظمة المضيفين، الذاكرة، الشبكة، السحابة، والسجلات لتحديد نطاق الهجوم، السبب الجذري، أنشطة المهاجم، والأثر التجاري.
  • إجراء صيد متقدم للتهديدات عبر بيئات المؤسسات باستخدام SIEM, EDR, والأدلة الجنائية ومعلومات التهديدات للكشف الاستباقي عن الأنشطة الخبيثة.
  • تطوير وصيانة وأتمتة سير عمل DFIR، أدوات التحقيق الرقمي، وخطوط أنابيب التحقيق باستخدام Python, PowerShell, Bash ولغات البرمجة النصية الأخرى.
  • بناء وصيانة أدوات DFIR داخلية، وأدوات تحليل الأدلة، وأطر الأتمتة، والبنية التحتية للتحقيق.
  • التعاون مع فرق SOC, Detection Engineering, Threat Intelligence, Red Team وIT لتحسين قدرات الاستجابة للحوادث والوضع الأمني.
  • إجراء تقييمات لجاهزية ونضج الاستجابة للحوادث، وتحديد الفجوات في الأشخاص والعمليات والتقنيات، وتقديم توصيات قابلة للتنفيذ.
  • إعداد تقارير فنية وإدارية عالية الجودة، مع توصيل واضح لنتائج التحقيق، الجداول الزمنية للهجوم، تحليل السبب الجذري، وتوصيات المعالجة باللغتين الإنجليزية والعربية.
  • توجيه وتدريب أعضاء الفريق على التحقيق الرقمي، منهجيات الاستجابة للحوادث، تحليل البرامج الضارة، الأدلة الجنائية، وأفضل ممارسات التحقيق.

المهارات المطلوبة

  • خبرة عملية واسعة في إجراء تحقيقات التحقيق الرقمي والاستجابة للحوادث عبر بيئات Windows, Linux, السحابة والمؤسسات.
  • خبرة قوية في تحليل نقاط النهاية، الذاكرة، الشبكة، والسجلات باستخدام أدوات DFIR القياسية في المجال.
  • إتقان أساسيات أنظمة تشغيل Windows وLinux، أنظمة الملفات، تحليل السجل، سجلات الأحداث، آليات الاستمرارية، المصادقة، وتحليل العمليات.
  • خبرة مع منصات EDR وتقنيات SIEM ومنهجيات صيد التهديدات.
  • مهارات قوية في البرمجة النصية والأتمتة باستخدام Python, PowerShell وBash.
  • خبرة في تطوير أدوات تحقيق رقمي مخصصة، أدوات تحليل، أو أتمتة لتحسين كفاءة التحقيق.
  • فهم قوي لسلوك البرامج الضارة، تقنيات المهاجمين، وأنشطة ما بعد الاستغلال.
  • خبرة في استخدام Git للتحكم بالإصدارات، التعاون، وصيانة أدوات DFIR والنصوص والتوثيق.
  • القدرة على إجراء تحقيقات حوادث شاملة، تحليل السبب الجذري، وتقييمات نضج الأمن.
  • مهارات تحليلية ممتازة في حل المشكلات والتحقيق.
  • مهارات ثنائية اللغة ممتازة في التواصل والكتابة باللغتين الإنجليزية والعربية.

المؤهلات المطلوبة

  • حد أدنى من 6-8 سنوات خبرة عملية في التحقيق الرقمي والاستجابة للحوادث.
  • خبرة مثبتة في قيادة مهام الاستجابة للحوادث المعقدة من الكشف الأولي حتى المعالجة والدروس المستفادة.
  • خبرة قوية مع أدوات DFIR المؤسسية (مثل Velociraptor, KAPE, Plaso, Hayabusa, Volatility, Timesketch, FTK, EnCase, X-Ways, Magnet AXIOM, Autopsy أو ما شابهها).
  • خبرة مع منصات EDR مثل Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Cortex XDR أو ما شابهها.
  • فهم قوي لأنظمة Windows, Linux, Active Directory, الشبكات، أمن السحابة، وتقنيات الهجوم المؤسسية.
  • فهم قوي لـ MITRE ATT&CK, Cyber Kill Chain, وأساليب المهاجمين الحديثة.
  • خبرة برمجية قوية في لغة برمجة واحدة على الأقل.
  • خبرة في استخدام PowerShell وBash للأتمتة وجمع الأدلة.
  • الراحة في استخدام Git للتحكم بالإصدارات، التعاون، وصيانة أدوات DFIR والنصوص والتوثيق.
  • مهارات تواصل قوية والقدرة على العمل collaboratively في بيئة استشارية.
  • مهارات ممتازة في اللغة الإنجليزية كتابةً وتحدثاً.
  • مهارات ممتازة في اللغة العربية كتابةً وتحدثاً.

المؤهلات المفضلة

  • خبرة في الاستجابة للحوادث السحابية عبر AWS, Azure أو Google Cloud Platform.
  • خبرة مع منصات تحليل سجلات المؤسسات مثل Elasticsearch, Splunk, Microsoft Sentinel أو QRadar.
  • خبرة في صيد التهديدات ودمج معلومات التهديدات في تحقيقات DFIR.
  • خبرة في تحليل البرامج الضارة، الهندسة العكسية، أو تحقيق الذاكرة.
  • خبرة في بناء خطوط أنابيب أتمتة DFIR ومنصات تنسيق التحقيق الرقمي.
  • خلفية سابقة في الاستشارات الأمنية السيبرانية.
  • خبرة سابقة في الأمن الهجومي، اختبار الاختراق، أو فريق الأرجواني (Purple Team).
  • حساب نشط على GitHub يوضح أدوات DFIR، مشاريع أتمتة، أو بحث في التحقيق الرقمي.
  • خبرة مثبتة في مختبر منزلي أو مختبر DFIR مؤسسي لاختبار التحقيقات والبرامج الضارة ومحاكاة الهجمات.
  • شهادات معتمدة ذات صلة مثل GCFA, GCFE, GREM, GCIH, GNFA, GCFR أو شهادات DFIR معترف بها في المجال.
عرض النص الأصلي للإعلان

Key Responsibilities

 

- Lead and perform end-to-end Digital Forensics and Incident Response (DFIR) engagements independently, including incident triage, containment, eradication, recovery, and post-incident reporting.

- Conduct host, memory, network, cloud, and log-based forensic investigations to determine attack scope, root cause, attacker activities, and business impact.

- Perform advanced threat hunting across enterprise environments using SIEM, EDR, forensic artifacts, and threat intelligence to proactively identify malicious activity.

- Develop, maintain, and automate DFIR workflows, forensic tooling, and investigation pipelines using Python, PowerShell, Bash, and other scripting languages.

- Build and maintain internal DFIR tools, forensic parsers, automation frameworks, and investigation infrastructure.

- Collaborate with SOC, Detection Engineering, Threat Intelligence, Red Team, and IT teams to improve incident response capabilities and security posture.

- Conduct incident response readiness and maturity assessments, identifying gaps in people, processes, and technology, and provide actionable recommendations.

- Produce high-quality technical and executive reports, clearly communicating investigation findings, attack timelines, root cause analysis, and remediation recommendations in both English and Arabic.

- Mentor and train team members on digital forensics, incident response methodologies, malware analysis, forensic artifacts, and investigation best practices.

 

Required Skills

 

- Extensive hands-on experience conducting Digital Forensics and Incident Response investigations across Windows, Linux, cloud, and enterprise environments.

- Strong experience with endpoint, memory, network, and log analysis using industry-standard forensic and DFIR tools.

- Proficiency in Windows and Linux operating system internals, file systems, registry analysis, event logs, persistence mechanisms, authentication, and process analysis.

- Experience with EDR platforms, SIEM technologies, and threat hunting methodologies.

- Strong scripting and automation skills using Python, PowerShell, and Bash.

- Experience developing custom forensic tools, parsers, or automation to improve investigation efficiency.

- Strong understanding of malware behavior, attacker techniques, and post-exploitation activities.

- Experience with Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.

- Ability to perform comprehensive incident investigations, root cause analysis, and security maturity assessments.

- Excellent analytical, problem-solving, and investigative skills.

- Excellent bilingual communication and writing skills in English and Arabic.

 

Required Qualifications

 

- Minimum of 6-8 years of hands-on experience in Digital Forensics and Incident Response.

- Demonstrated experience leading complex incident response engagements from initial detection through remediation and lessons learned.

- Strong experience with enterprise forensic and DFIR tools (e.g., Velociraptor, KAPE, Plaso, Hayabusa, Volatility, Timesketch, FTK, EnCase, X-Ways, Magnet AXIOM, Autopsy, or similar).

- Experience with EDR platforms such as Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Cortex XDR, or similar.

- Strong understanding of Windows, Linux, Active Directory, networking, cloud security, and enterprise attack techniques.

- Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and modern attacker tradecraft.

- Strong programming experience in at least one language.

- Experience with PowerShell and Bash scripting for automation and forensic collection.

- Comfortable using Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.

- Strong communication skills and the ability to work collaboratively in a consulting environment.

- Excellent English written and verbal communication skills.

- Excellent Arabic written and verbal communication skills.

 

Preferred Qualifications

 

- Experience performing cloud incident response across AWS, Azure, or Google Cloud Platform.

- Experience with enterprise log analysis platforms such as Elasticsearch, Splunk, Microsoft Sentinel, or QRadar.

- Experience with threat hunting and threat intelligence integration into DFIR investigations.

- Experience performing malware analysis, reverse engineering, or memory forensics.

- Experience building DFIR automation pipelines and forensic orchestration platforms.

- Prior cybersecurity consulting background.

- Prior offensive security, penetration testing, or purple team experience.

- Active GitHub account demonstrating DFIR tools, automation projects, or forensic research.

- Demonstrated home lab or enterprise DFIR lab experience for testing investigations, malware, and attack simulations.

- Relevant certifications such as GCFA, GCFE, GREM, GCIH, GNFA, GCFR, or equivalent industry-recognized DFIR certifications.

المصدر: LinkedIn - أُضيفت للموقع في 11 أغسطس 2026

وظائف أخرى لدى Cipher | سايڤر