# Cybersecurity Incident Response & Digital Forensics (DFIR) Specialist

**Company:** [CCDS](null/companies/jW2GU1cjjZDfo4R2Wur6uh.md)
**Location:** Riyadh, Saudi Arabia
**Workplace:** on site
**Employment type:** Full-time

[Apply for this job](null/view/9ccba83f-f4bd-43c8-b657-23df3e68ead7)

## Description

**Location:** On-site – Riyadh, Saudi Arabia

**Contract/engagement:** Project-based managed cybersecurity services (13-month)

**Minimum experience:** 7+ years

### Role Purpose

Lead and execute cybersecurity incident response and digital forensic investigations while preserving evidence and meeting regulatory reporting requirements.

### Key Responsibilities

·      Investigate cybersecurity incidents and determine attack scope, impact, entry vectors, and affected assets.

·      Perform containment, eradication, recovery, root-cause analysis, and post-incident review activities.

·      Collect, preserve, and analyze digital evidence in accordance with approved chain-of-custody procedures.

·      Conduct disk, memory, network, endpoint, and malware analysis using appropriate forensic tools.

·      Develop and maintain incident-response and DFIR procedures, playbooks, investigation methods, and evidence-handling guides.

·      Prepare technical and executive incident reports, forensic findings, and RCA reports.

·      Coordinate with internal teams and stakeholders and ensure incident classification and reporting comply with NCA requirements.

## Requirements

### Technical and Professional Requirements

·      Saudi nationality is a must.

·      Bachelor’s degree in Cybersecurity, Digital Forensics, Computer Science, or a related field.

·      At least 7 years of experience in cyber incident response and digital forensic investigations.

·      Strong knowledge of attacker behavior, incident investigation methods, NIST incident response, and MITRE ATT&CK.

·      Hands-on experience with SIEM, EDR, EnCase, FTK, Volatility, Autopsy, or equivalent forensic and security tools.

·      Strong understanding of digital evidence handling and chain of custody.

### Personal Requirements

·      Calm and decisive during high-pressure incidents.

·      Strong investigative thinking, attention to detail, and professional judgment.

·      Clear technical writing and the ability to communicate findings to both executives and technical teams.

·      High integrity and strict respect for confidentiality.

### Professional Certifications

Preferred: CISSP, GCIA, GSEC, GCIH, CISM, or equivalent.
