📍 المملكة العربية السعودية تحديث مستمر على مدار الساعة

وظيفة محلل استجابة للحوادث الرقمية (سعودي) لدى Robert Walters في الرياض

Digital Incident Response (Saudi National)
🏢 Robert Walters
🕒 نُشرت: (اليوم) 📍 الرياض وظائف الهندسة والتقنية
التقديم على الوظيفة من المصدر الرسمي ↗

تفاصيل الوظيفة

يسعى عميلنا، وهو مؤسسة رائدة في مجال التكنولوجيا والأمن السيبراني متخصصة في الحلول الأمنية المتقدمة عبر البنية التحتية الرقمية والأجهزة المتصلة والأنظمة المضمنة والتقنيات الناشئة، إلى توظيف أخصائي استجابة للحوادث الرقمية (مواطن سعودي) في الرياض.

المهام والمسؤوليات

  • قيادة تحقيقات الطب الشرعي الرقمي من البداية إلى النهاية عبر نقاط النهاية والمنصات السحابية والشبكات، بدءًا من الفرز الأولي ووصولاً إلى تحليل السبب الجذري.
  • التحقيق في حالات الوصول غير المصرح به، وتسريب البيانات، ومؤشرات الاختراق (IoCs)، ونشاط المهاجمين.
  • قيادة وتنسيق فريق DFIR أثناء التحقيقات النشطة، مع ضمان اتساق العمليات وسلامة الأدلة وتحقيق النتائج في الوقت المناسب.
  • جمع وتحليل السجلات من منصات EDR/XDR وSIEM وDLP وموفري الهوية (IdP) ومنصات أمان البريد الإلكتروني لإعادة بناء الجداول الزمنية للهجوم.
  • الحصول على صور الطب الشرعي من أجهزة الكمبيوتر المحمولة والأجهزة المحمولة والخوادم والبيئات السحابية، مع الحفاظ على سلسلة الحضانة الكاملة.
  • تحليل القطع الأثرية للطب الشرعي بما في ذلك أنظمة الملفات والذاكرة وWindows Registry وسجلات النظام وبيانات التكوين لتحديد ما حدث ومتى.
  • ربط بيانات نقاط النهاية والشبكة والهوية لبناء صورة كاملة لسلوك المهاجم والوصول إلى النظام.
  • تطوير وتنفيذ سير عمل التحقيقات المدعومة بالذكاء الاصطناعي لأتمتة جمع الأدلة واكتشاف الأنماط وإنشاء الجداول الزمنية.
  • تقديم النتائج التقنية في تقارير وجداول زمنية واضحة وموجزة للإدارة التنفيذية وأصحاب المصلحة غير التقنيين.
  • العمل مع فرق الأمن لتحويل نتائج التحقيقات إلى تحسينات في قواعد الكشف وضوابط الوصول والسياسات الأمنية والعمليات.
  • ضمان امتثال جميع التحقيقات وعمليات الأمن لمتطلبات NCA ECC وSAMA CSF.

الشروط والمتطلبات

  • خبرة لا تقل عن 7 سنوات في مجال الطب الشرعي الرقمي أو الاستجابة للحوادث أو تحقيقات الأمن السيبراني.
  • خبرة مثبتة في قيادة أو تنسيق تحقيقات DFIR، مع خبرة سابقة في القيادة إلزامية.
  • درجة البكالوريوس في علوم الحاسب أو الأمن السيبراني أو الطب الشرعي الرقمي أو مجال ذي صلة.
  • خبرة عملية قوية في استخدام أدوات الطب الشرعي مثل FTK أو X-Ways أو Cellebrite أو Magnet AXIOM أو ما يعادلها.
  • فهم قوي لبروتوكولات TCP/IP وHTTP/S وDNS وحركة مرور الشبكة وتحليل السجلات المستندة إلى SIEM.
  • خبرة عملية في البرمجة باستخدام Python أو PowerShell أو Bash، خاصة لأتمتة جمع الأدلة وتحليلها.
  • معرفة عميقة بأنظمة Windows وmacOS وLinux/Unix على مستوى النظام والقطع الأثرية للطب الشرعي.
  • خبرة في استخدام أدوات الذكاء الاصطناعي والأتمتة لتحسين عمليات التحقيق والفرز واكتشاف الأنماط وإعداد التقارير.
  • فهم قوي للاستجابة للحوادث ومعالجة الأدلة الرقمية والتحقيق الجنائي وتحليل الهجمات.
  • مهارات ممتازة في التواصل الكتابي والشفهي باللغتين الإنجليزية والعربية.
  • قدرة على التواصل بثقة مع المدراء التنفيذيين وكبار أصحاب المصلحة والعمل بفعالية مع فرق الشؤون القانونية والموارد البشرية والامتثال والأمن السيبراني.
  • فهم قوي لمتطلبات الامتثال NCA ECC وSAMA CSF.
عرض النص الأصلي للإعلان

Our client is a eading technology and cybersecurity organisation focused on advanced security solutions across digital infrastructure, connected devices, embedded systems, and emerging technologies. Its expertise includes hardware and software security, vulnerability research, penetration testing, cryptography, and security assessments, helping organisations identify risks, strengthen systems, and protect critical technologies against increasingly sophisticated cyber threats.



Key Responsibilities

  • Lead end-to-end digital forensic investigations across endpoints, cloud platforms, and networks, from initial triage through root-cause analysis.
  • Investigate unauthorised access, data exfiltration, Indicators of Compromise (IoCs), and attacker activity.
  • Lead and coordinate the DFIR team during active investigations, ensuring consistent processes, evidence integrity, and timely outcomes.
  • Collect and analyse logs from EDR/XDR, SIEM, DLP, Identity Providers (IdP), and email security platforms to reconstruct attack timelines.
  • Acquire forensic images from laptops, mobile devices, servers, and cloud environments, maintaining a complete chain of custody.
  • Analyse forensic artifacts including file systems, memory, Windows Registry, system logs, and configuration data to establish what happened and when.
  • Correlate endpoint, network, and identity data to build a complete picture of attacker behaviour and system access.
  • Develop and implement AI-assisted investigation workflows to automate evidence collection, pattern detection, and timeline generation.
  • Present technical findings in clear, concise reports and timelines for executives and non-technical stakeholders.
  • Work with security teams to turn investigation findings into improvements to detection rules, access controls, security policies, and processes.
  • Ensure all investigations and security operations comply with NCA ECC and SAMA CSF requirements.

Key Requirements:

  • 7+ years of experience in digital forensics, incident response, or cybersecurity investigations.
  • Proven experience leading or coordinating DFIR investigations. Previous leadership experience is mandatory.
  • Bachelor's degree in Computer Science, Cybersecurity, Digital Forensics, or a related field.
  • Strong hands-on experience with forensic tools such as FTK, X-Ways, Cellebrite, Magnet AXIOM, or equivalent.
  • Strong understanding of TCP/IP, HTTP/S, DNS, network traffic, and SIEM-based log analysis.
  • Practical scripting experience with Python, PowerShell, or Bash, particularly for automating evidence collection and analysis.
  • Deep knowledge of Windows, macOS, and Linux/Unix at the system and forensic artifact level.
  • Experience using AI tools and automation to improve investigation, triage, pattern detection, and reporting processes.
  • Strong understanding of incident response, digital evidence handling, forensic investigation, and attack analysis.
  • Excellent written and verbal communication skills in both English and Arabic.
  • Confident communicator who can brief executives and senior stakeholders and work effectively with Legal, HR, Compliance, and Cybersecurity teams.
  • Strong understanding of NCA ECC and SAMA CSF compliance requirements.

المصدر: LinkedIn - أُضيفت للموقع في 13 أغسطس 2026

وظائف أخرى لدى Robert Walters