Senior DFIR & Incident Response Expert Saudi National
Robert Walters• Riyadh, Saudi Arabia
TypeFull time
LocationRiyadh, Saudi Arabia
Posted1d ago
Job description
About the Role;">Robert Walters is seeking a Senior DFIR & Incident Response Expert to join a growing cybersecurity team in Riyadh, Saudi Arabia. This full-time position is a hands-on technical and leadership role for an experienced investigator who will lead complex forensic investigations, coordinate DFIR activities, and help organizations respond to evolving cyber threats. The role requires 5-10 years of experience.
Role Context
********;">The successful candidate will work across endpoint, cloud, and network environments, combining deep forensic expertise with advanced investigation techniques, automation, and AI-assisted workflows. This position plays a key role in identifying the root cause of incidents, reconstructing attacker activity, and translating technical findings into actionable recommendations for senior stakeholders.
Key Responsibilities
• Lead end-to-end digital forensic investigations across endpoints, cloud platforms, and network infrastructure, from initial triage through root-cause analysis and reporting.
• Coordinate and guide DFIR teams during active investigations, ensuring consistent methodologies, evidence integrity, and timely outcomes.
• Analyze telemetry and logs from EDR/XDR, SIEM, DLP, identity platforms, and email security gateways to reconstruct detailed attack and user activity timelines.
• Acquire and analyze forensic images from laptops, mobile devices, servers, and cloud repositories while maintaining a robust chain of custody.
• Investigate forensic artifacts, including file systems, memory, Windows Registry, system logs, and configuration data, to establish incident details.
• Correlate endpoint, network, and identity telemetry to develop a comprehensive understanding of attacker behavior, access patterns, and potential data exfiltration.
• Develop AI-assisted workflows to automate evidence collection, pattern detection, and timeline generation, improving investigative efficiency.
• Present technical findings through clear, chronological, and actionable reports for executives and cross-functional stakeholders.
• Collaborate with legal, HR, and compliance teams while maintaining investigative accuracy and confidentiality.
• Translate investigation outcomes into improvements for detection rules, access controls, security policies, and incident response processes.
• Ensure investigative activities align with applicable cybersecurity and regulatory requirements, including NCA ECC and SAMA CSF.
Qualifications and Requirements
• Saudi National is a mandatory requirement.
• Proven experience leading or coordinating DFIR investigations and engagements.
• Previous leadership experience, including guiding investigators or coordinating response activities.
• Strong hands-on experience with forensic investigation tools such as FTK, X-Ways, Cellebrite, Axiom, or equivalent platforms.
• Solid understanding of network protocols, including TCP/IP, HTTP/S, and DNS, alongside practical SIEM log analysis experience.
• Proficiency in Python, PowerShell, or Bash, with experience automating evidence collection, processing, or investigative workflows.
• Deep technical knowledge of Windows, macOS, and Linux/Unix systems, including system-level and forensic artifacts.
• Demonstrated experience using AI tools or developing AI-assisted workflows to improve investigative triage, pattern detection, or reporting.
• Strong understanding of incident response methodologies, evidence preservation, and forensic investigation practices.
• Familiarity with NCA ECC and SAMA CSF compliance requirements.
Preferred Certifications
**********;">Candidates with one or more of the following certifications are preferred:
• SANS / GIAC - GCFA, GCFE, GNFA, GCIA, or equivalent.
• IACIS CFCE.
• EC-Council CHFI.
• OffSec - OSDA, OSIR, or equivalent.