# Incident Response Lead (DFIR) -Dubai, UAE

**Company:** [DeepSource Technologies](http://jobs.workable.com/companies/bSz5yPYQuy7zGF2AaBwdRp.md)
**Location:** Mumbai, India
**Workplace:** on site
**Employment type:** Full-time

[Apply for this job](http://jobs.workable.com/view/9df6e7a1-b5d4-47e2-b04c-942df136d06e)

## Description

We are seeking an experienced **Incident Response Lead** to manage and coordinate cybersecurity incident response activities. The ideal candidate will have hands-on experience in **Digital Forensics and Incident Response (DFIR)**, investigating security incidents, conducting root cause analysis, and leading containment, eradication, and recovery efforts in enterprise environments.

### Key Responsibilities

-   Lead the investigation and response to cybersecurity incidents.
-   Perform incident triage, analysis, containment, eradication, and recovery.
-   Conduct digital forensic investigations and root cause analysis.
-   Coordinate with SOC, Security Engineering, IT, and business teams during security incidents.
-   Develop and maintain incident response playbooks and procedures.
-   Analyze malware, phishing attacks, ransomware, and other cyber threats.
-   Prepare incident reports and provide recommendations to prevent future incidents.
-   Support threat hunting and continuous improvement of incident response capabilities.
-   Ensure compliance with organizational security policies and industry best practices.

## Requirements

-   **5–7 years of experience** in Cybersecurity.
-   Hands-on experience in **Incident Response and Digital Forensics (DFIR)**.
-   Experience investigating security incidents in an enterprise environment.
-   Knowledge of malware analysis, ransomware, phishing, and threat detection.
-   Experience with SIEM, EDR, and security monitoring tools.
-   Strong understanding of Windows, Linux, networking, and security fundamentals.
-   Excellent analytical, troubleshooting, and communication skills.

### Nice to Have

-   Certifications such as **GCFA, GCIH, GCFE, CHFI, CEH, CySA+, or Security+**.
-   Experience with cloud security incident response (Azure, AWS, or GCP).
-   Scripting experience (PowerShell or Python).
