Our client is a eading technology and cybersecurity organisation focused on advanced security solutions across digital infrastructure, connected devices, embedded systems, and emerging technologies. Its expertise includes hardware and software security, vulnerability research, penetration testing, cryptography, and security assessments, helping organisations identify risks, strengthen systems, and protect critical technologies against increasingly sophisticated cyber threats.
Key Responsibilities
- Lead end-to-end digital forensic investigations across endpoints, cloud platforms, and networks, from initial triage through root-cause analysis.
- Investigate unauthorised access, data exfiltration, Indicators of Compromise (IoCs), and attacker activity.
- Lead and coordinate the DFIR team during active investigations, ensuring consistent processes, evidence integrity, and timely outcomes.
- Collect and analyse logs from EDR/XDR, SIEM, DLP, Identity Providers (IdP), and email security platforms to reconstruct attack timelines.
- Acquire forensic images from laptops, mobile devices, servers, and cloud environments, maintaining a complete chain of custody.
- Analyse forensic artifacts including file systems, memory, Windows Registry, system logs, and configuration data to establish what happened and when.
- Correlate endpoint, network, and identity data to build a complete picture of attacker behaviour and system access.
- Develop and implement AI-assisted investigation workflows to automate evidence collection, pattern detection, and timeline generation.
- Present technical findings in clear, concise reports and timelines for executives and non-technical stakeholders.
- Work with security teams to turn investigation findings into improvements to detection rules, access controls, security policies, and processes.
- Ensure all investigations and security operations comply with NCA ECC and SAMA CSF requirements.
Key Requirements:
- 7+ years of experience in digital forensics, incident response, or cybersecurity investigations.
- Proven experience leading or coordinating DFIR investigations. Previous leadership experience is mandatory.
- Bachelor's degree in Computer Science, Cybersecurity, Digital Forensics, or a related field.
- Strong hands-on experience with forensic tools such as FTK, X-Ways, Cellebrite, Magnet AXIOM, or equivalent.
- Strong understanding of TCP/IP, HTTP/S, DNS, network traffic, and SIEM-based log analysis.
- Practical scripting experience with Python, PowerShell, or Bash, particularly for automating evidence collection and analysis.
- Deep knowledge of Windows, macOS, and Linux/Unix at the system and forensic artifact level.
- Experience using AI tools and automation to improve investigation, triage, pattern detection, and reporting processes.
- Strong understanding of incident response, digital evidence handling, forensic investigation, and attack analysis.
- Excellent written and verbal communication skills in both English and Arabic.
- Confident communicator who can brief executives and senior stakeholders and work effectively with Legal, HR, Compliance, and Cybersecurity teams.
- Strong understanding of NCA ECC and SAMA CSF compliance requirements.