Kualitatem Inc. تعلن عن وظيفة أخصائي استجابة للحوادث والتحقيقات الرقمية في الرياض
Incident Response and Digital Forensic Investigations
🏢 Kualitatem Inc.
تفاصيل الوظيفة
تعلن شركة Kualitatem Inc. عن وظيفة Incident Response and Digital Forensic Investigations في الرياض.
المهام والمسؤوليات
- إجراء تحقيقات تتعلق بحوادث الأمن السيبراني والاستجابة لها.
- تحليل الحوادث لتحديد نطاق الهجوم وتأثيره ووسائل الاختراق المستخدمة.
- تنفيذ أنشطة احتواء الحوادث، والقضاء على التهديدات، واستعادة الأنظمة.
- إجراء تحليلات الأدلة الرقمية الجنائية مثل تحليل القرص والذاكرة والشبكة.
- جمع الأدلة الرقمية وحفظها وتحليلها وفقًا للإجراءات المعتمدة.
- إجراء تحليل البرمجيات الخبيثة والتحقيق في نشاط المهاجم على الأنظمة المخترقة.
- تطوير وصيانة إجراءات وأدلة الاستجابة للحوادث والتحقيقات الرقمية الجنائية (Playbooks).
- إعداد تقارير الحوادث ونتائج التحليل الجنائي وتحليل السبب الجذري (RCA).
- التنسيق مع الفرق الداخلية وأصحاب المصلحة أثناء التحقيق في الحوادث ومعالجة آثارها.
- تطوير وتحسين العمليات والإجراءات والسياسات المتعلقة بالتحقيق والاستجابة للحوادث والأدلة الرقمية.
- إعداد وتحديث منهجيات التحقيق وأدلة العمل الخاصة بـ DFIR.
- التنسيق مع الإدارات الداخلية لدعم أنشطة التحقيق والاستجابة للحوادث.
- ضمان التوافق مع المتطلبات التنظيمية ومتطلبات الامتثال بما في ذلك متطلبات الهيئة الوطنية للأمن السيبراني (NCA).
- التحقق من تصنيف الحوادث لضمان الامتثال لمتطلبات الإبلاغ التنظيمية.
الشروط والمتطلبات
- أن يكون المتقدم سعودي الجنسية.
- درجة البكالوريوس في الأمن السيبراني أو الأدلة الرقمية الجنائية أو علوم الحاسب أو تخصص ذي صلة.
- ما لا يقل عن 7 سنوات من الخبرة في مجال الاستجابة للحوادث السيبرانية والتحقيقات الرقمية الجنائية.
- يفضل الحصول على إحدى الشهادات المهنية التالية: CISSP, GCIA, GSEC, GCIH, CISM أو ما يعادلها.
المهارات المطلوبة
- معرفة قوية بتقنيات الهجوم السيبراني وسلوك التهديدات ومنهجيات التحقيق في الحوادث.
- خبرة في استخدام أدوات الأمن والأدلة الرقمية مثل: EDR, SIEM, EnCase, FTK, Volatility, Autopsy.
- معرفة بأطر الاستجابة للحوادث مثل NIST و MITRE ATT&CK.
- فهم إجراءات التعامل مع الأدلة الرقمية وسلسلة الحفظ (Chain of Custody).
- الإلمام بأطر التهديدات مثل MITRE.
- مهارات قوية في التحليل والتحقيق وإعداد التقارير والتواصل.
عرض النص الأصلي للإعلان
Minimum Qualifications:
- A bachelor’s degree in cybersecurity, digital forensics, computer science, or a related discipline.
- Obtaining one of the following professional certifications is preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.
Job Requirements:
- The applicant must be a Saudi.
- A bachelor’s degree in cybersecurity, digital forensics, computer science, or a related discipline.
- No less than 7 years of experience in the field of cyber incident response and digital forensic investigations.
- Strong knowledge of cyber attack techniques, threat behaviour, and incident investigation methodologies.
- Experience in using security and forensic tools such as: EDR, SIEM, EnCase, FTK, Volatility, Autopsy.
- Knowledge of incident response frameworks such as NIST and MITRE ATT&CK.
- Understanding of the procedures for handling digital evidence and the chain of custody.
- Familiarity with threat frameworks such as MITRE.
- Strong skills in analysis, investigation, report preparation and communication.
Principal Responsibilities:
- Carrying out investigations relating to cybersecurity incidents and responding to them.
- Analysing incidents to determine the scope of the attack, its impact, and the means of intrusion used.
- Carrying out incident containment activities, eliminating threats, and restoring systems.
- Conducting digital forensic analyses such as disk, memory and network analysis.
- Collecting, preserving and analysing digital evidence in accordance with the approved procedures.
- Conducting malware analysis and investigating attacker activity on compromised systems.
- Developing and maintaining incident response and digital forensic investigation procedures and guides (Playbooks).
- Preparing incident reports, forensic analysis results, and root cause analysis (RCA).
- Coordinating with internal teams and stakeholders during incident investigation and remediation of their effects.
- Developing and improving the processes, procedures and policies for investigation, incident response and digital forensics.
- Preparing and updating investigation methodologies and working guides specific to DFIR.
- Coordinating with internal departments to support investigations and incident response activities.
- Ensuring alignment with regulatory requirements and compliance requirements, including the requirements of the Cybersecurity Authority (NCA).
- Verifying the classification of incidents to ensure compliance with regulatory reporting requirements.
المصدر: LinkedIn - أُضيفت للموقع في 18 أغسطس 2026