وظيفة مستشار DFIR أول لدى سايڤر في الرياض
تفاصيل الوظيفة
تعلن شركة Cipher | سايڤر عن توفر وظيفة Senior DFIR Consultant في الرياض، السعودية.
المهام والمسؤوليات
- قيادة وتنفيذ مهام التحقيق الرقمي والاستجابة للحوادث (DFIR) بشكل مستقل من البداية إلى النهاية، بما في ذلك الفرز الأولي، الاحتواء، الاستئصال، الاسترداد، وإعداد التقارير بعد الحادثة.
- إجراء تحقيقات في أنظمة المضيفين، الذاكرة، الشبكة، السحابة، والسجلات لتحديد نطاق الهجوم، السبب الجذري، أنشطة المهاجم، والأثر التجاري.
- إجراء صيد متقدم للتهديدات عبر بيئات المؤسسات باستخدام SIEM, EDR, والأدلة الجنائية ومعلومات التهديدات للكشف الاستباقي عن الأنشطة الخبيثة.
- تطوير وصيانة وأتمتة سير عمل DFIR، أدوات التحقيق الرقمي، وخطوط أنابيب التحقيق باستخدام Python, PowerShell, Bash ولغات البرمجة النصية الأخرى.
- بناء وصيانة أدوات DFIR داخلية، وأدوات تحليل الأدلة، وأطر الأتمتة، والبنية التحتية للتحقيق.
- التعاون مع فرق SOC, Detection Engineering, Threat Intelligence, Red Team وIT لتحسين قدرات الاستجابة للحوادث والوضع الأمني.
- إجراء تقييمات لجاهزية ونضج الاستجابة للحوادث، وتحديد الفجوات في الأشخاص والعمليات والتقنيات، وتقديم توصيات قابلة للتنفيذ.
- إعداد تقارير فنية وإدارية عالية الجودة، مع توصيل واضح لنتائج التحقيق، الجداول الزمنية للهجوم، تحليل السبب الجذري، وتوصيات المعالجة باللغتين الإنجليزية والعربية.
- توجيه وتدريب أعضاء الفريق على التحقيق الرقمي، منهجيات الاستجابة للحوادث، تحليل البرامج الضارة، الأدلة الجنائية، وأفضل ممارسات التحقيق.
المهارات المطلوبة
- خبرة عملية واسعة في إجراء تحقيقات التحقيق الرقمي والاستجابة للحوادث عبر بيئات Windows, Linux, السحابة والمؤسسات.
- خبرة قوية في تحليل نقاط النهاية، الذاكرة، الشبكة، والسجلات باستخدام أدوات DFIR القياسية في المجال.
- إتقان أساسيات أنظمة تشغيل Windows وLinux، أنظمة الملفات، تحليل السجل، سجلات الأحداث، آليات الاستمرارية، المصادقة، وتحليل العمليات.
- خبرة مع منصات EDR وتقنيات SIEM ومنهجيات صيد التهديدات.
- مهارات قوية في البرمجة النصية والأتمتة باستخدام Python, PowerShell وBash.
- خبرة في تطوير أدوات تحقيق رقمي مخصصة، أدوات تحليل، أو أتمتة لتحسين كفاءة التحقيق.
- فهم قوي لسلوك البرامج الضارة، تقنيات المهاجمين، وأنشطة ما بعد الاستغلال.
- خبرة في استخدام Git للتحكم بالإصدارات، التعاون، وصيانة أدوات DFIR والنصوص والتوثيق.
- القدرة على إجراء تحقيقات حوادث شاملة، تحليل السبب الجذري، وتقييمات نضج الأمن.
- مهارات تحليلية ممتازة في حل المشكلات والتحقيق.
- مهارات ثنائية اللغة ممتازة في التواصل والكتابة باللغتين الإنجليزية والعربية.
المؤهلات المطلوبة
- حد أدنى من 6-8 سنوات خبرة عملية في التحقيق الرقمي والاستجابة للحوادث.
- خبرة مثبتة في قيادة مهام الاستجابة للحوادث المعقدة من الكشف الأولي حتى المعالجة والدروس المستفادة.
- خبرة قوية مع أدوات DFIR المؤسسية (مثل Velociraptor, KAPE, Plaso, Hayabusa, Volatility, Timesketch, FTK, EnCase, X-Ways, Magnet AXIOM, Autopsy أو ما شابهها).
- خبرة مع منصات EDR مثل Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Cortex XDR أو ما شابهها.
- فهم قوي لأنظمة Windows, Linux, Active Directory, الشبكات، أمن السحابة، وتقنيات الهجوم المؤسسية.
- فهم قوي لـ MITRE ATT&CK, Cyber Kill Chain, وأساليب المهاجمين الحديثة.
- خبرة برمجية قوية في لغة برمجة واحدة على الأقل.
- خبرة في استخدام PowerShell وBash للأتمتة وجمع الأدلة.
- الراحة في استخدام Git للتحكم بالإصدارات، التعاون، وصيانة أدوات DFIR والنصوص والتوثيق.
- مهارات تواصل قوية والقدرة على العمل collaboratively في بيئة استشارية.
- مهارات ممتازة في اللغة الإنجليزية كتابةً وتحدثاً.
- مهارات ممتازة في اللغة العربية كتابةً وتحدثاً.
المؤهلات المفضلة
- خبرة في الاستجابة للحوادث السحابية عبر AWS, Azure أو Google Cloud Platform.
- خبرة مع منصات تحليل سجلات المؤسسات مثل Elasticsearch, Splunk, Microsoft Sentinel أو QRadar.
- خبرة في صيد التهديدات ودمج معلومات التهديدات في تحقيقات DFIR.
- خبرة في تحليل البرامج الضارة، الهندسة العكسية، أو تحقيق الذاكرة.
- خبرة في بناء خطوط أنابيب أتمتة DFIR ومنصات تنسيق التحقيق الرقمي.
- خلفية سابقة في الاستشارات الأمنية السيبرانية.
- خبرة سابقة في الأمن الهجومي، اختبار الاختراق، أو فريق الأرجواني (Purple Team).
- حساب نشط على GitHub يوضح أدوات DFIR، مشاريع أتمتة، أو بحث في التحقيق الرقمي.
- خبرة مثبتة في مختبر منزلي أو مختبر DFIR مؤسسي لاختبار التحقيقات والبرامج الضارة ومحاكاة الهجمات.
- شهادات معتمدة ذات صلة مثل GCFA, GCFE, GREM, GCIH, GNFA, GCFR أو شهادات DFIR معترف بها في المجال.
عرض النص الأصلي للإعلان
Key Responsibilities
- Lead and perform end-to-end Digital Forensics and Incident Response (DFIR) engagements independently, including incident triage, containment, eradication, recovery, and post-incident reporting.
- Conduct host, memory, network, cloud, and log-based forensic investigations to determine attack scope, root cause, attacker activities, and business impact.
- Perform advanced threat hunting across enterprise environments using SIEM, EDR, forensic artifacts, and threat intelligence to proactively identify malicious activity.
- Develop, maintain, and automate DFIR workflows, forensic tooling, and investigation pipelines using Python, PowerShell, Bash, and other scripting languages.
- Build and maintain internal DFIR tools, forensic parsers, automation frameworks, and investigation infrastructure.
- Collaborate with SOC, Detection Engineering, Threat Intelligence, Red Team, and IT teams to improve incident response capabilities and security posture.
- Conduct incident response readiness and maturity assessments, identifying gaps in people, processes, and technology, and provide actionable recommendations.
- Produce high-quality technical and executive reports, clearly communicating investigation findings, attack timelines, root cause analysis, and remediation recommendations in both English and Arabic.
- Mentor and train team members on digital forensics, incident response methodologies, malware analysis, forensic artifacts, and investigation best practices.
Required Skills
- Extensive hands-on experience conducting Digital Forensics and Incident Response investigations across Windows, Linux, cloud, and enterprise environments.
- Strong experience with endpoint, memory, network, and log analysis using industry-standard forensic and DFIR tools.
- Proficiency in Windows and Linux operating system internals, file systems, registry analysis, event logs, persistence mechanisms, authentication, and process analysis.
- Experience with EDR platforms, SIEM technologies, and threat hunting methodologies.
- Strong scripting and automation skills using Python, PowerShell, and Bash.
- Experience developing custom forensic tools, parsers, or automation to improve investigation efficiency.
- Strong understanding of malware behavior, attacker techniques, and post-exploitation activities.
- Experience with Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.
- Ability to perform comprehensive incident investigations, root cause analysis, and security maturity assessments.
- Excellent analytical, problem-solving, and investigative skills.
- Excellent bilingual communication and writing skills in English and Arabic.
Required Qualifications
- Minimum of 6-8 years of hands-on experience in Digital Forensics and Incident Response.
- Demonstrated experience leading complex incident response engagements from initial detection through remediation and lessons learned.
- Strong experience with enterprise forensic and DFIR tools (e.g., Velociraptor, KAPE, Plaso, Hayabusa, Volatility, Timesketch, FTK, EnCase, X-Ways, Magnet AXIOM, Autopsy, or similar).
- Experience with EDR platforms such as Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Cortex XDR, or similar.
- Strong understanding of Windows, Linux, Active Directory, networking, cloud security, and enterprise attack techniques.
- Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and modern attacker tradecraft.
- Strong programming experience in at least one language.
- Experience with PowerShell and Bash scripting for automation and forensic collection.
- Comfortable using Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.
- Strong communication skills and the ability to work collaboratively in a consulting environment.
- Excellent English written and verbal communication skills.
- Excellent Arabic written and verbal communication skills.
Preferred Qualifications
- Experience performing cloud incident response across AWS, Azure, or Google Cloud Platform.
- Experience with enterprise log analysis platforms such as Elasticsearch, Splunk, Microsoft Sentinel, or QRadar.
- Experience with threat hunting and threat intelligence integration into DFIR investigations.
- Experience performing malware analysis, reverse engineering, or memory forensics.
- Experience building DFIR automation pipelines and forensic orchestration platforms.
- Prior cybersecurity consulting background.
- Prior offensive security, penetration testing, or purple team experience.
- Active GitHub account demonstrating DFIR tools, automation projects, or forensic research.
- Demonstrated home lab or enterprise DFIR lab experience for testing investigations, malware, and attack simulations.
- Relevant certifications such as GCFA, GCFE, GREM, GCIH, GNFA, GCFR, or equivalent industry-recognized DFIR certifications.
وظائف أخرى لدى Cipher | سايڤر
سايڤر (Cipher) تعلن عن وظيفة مدير حسابات فنية في الرياض
وظيفة أخصائي التحكم في الوصول للأمن السيبراني لدى سايڤر في الرياض
وظيفة مدير مشاريع أول لدى سايڤر في الجبيل
وظيفة أخصائي مخاطر الأمن السيبراني لدى سايڤر في الجبيل