×
Register Here to Apply for Jobs or Post Jobs. X

Senior DFIR Consultant

Job in Riyadh, Riyadh Region, Saudi Arabia
Listing for: Cipher | سايڤر
Full Time position
Listed on 2026-08-14
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 280000 - 480000 SAR Yearly SAR 280000.00 480000.00 YEAR
Job Description & How to Apply Below
  • Lead and perform end-to-end Digital Forensics and Incident Response (DFIR) engagements independently, including incident triage, containment, eradication, recovery, and post-incident reporting.
  • Conduct host, memory, network, cloud, and log-based forensic investigations to determine attack scope, root cause, attacker activities, and business impact.
  • Perform advanced threat hunting across enterprise environments using SIEM, EDR, forensic artifacts, and threat intelligence to proactively identify malicious activity.
  • Develop, maintain, and automate DFIR workflows, forensic tooling, and investigation pipelines using Python, Power Shell, Bash, and other scripting languages.
  • Build and maintain internal DFIR tools, forensic parsers, automation frameworks, and investigation infrastructure.
  • Collaborate with SOC, Detection Engineering, Threat Intelligence, Red Team, and IT teams to improve incident response capabilities and security posture.
  • Conduct incident response readiness and maturity assessments, identifying gaps in people, processes, and technology, and provide actionable recommendations.
  • Produce high-quality technical and executive reports, clearly communicating investigation findings, attack timelines, root cause analysis, and remediation recommendations in both English and Arabic.
  • Mentor and train team members on digital forensics, incident response methodologies, malware analysis, forensic artifacts, and investigation best practices.
Required Skills
  • Extensive hands-on experience conducting Digital Forensics and Incident Response investigations across Windows, Linux, cloud, and enterprise environments.
  • Strong experience with endpoint, memory, network, and log analysis using industry-standard forensic and DFIR tools.
  • Proficiency in Windows and Linux operating system internals, file systems, registry analysis, event logs, persistence mechanisms, authentication, and process analysis.
  • Experience with EDR platforms, SIEM technologies, and threat hunting methodologies.
  • Strong scripting and automation skills using Python, Power Shell, and Bash.
  • Experience developing custom forensic tools, parsers, or automation to improve investigation efficiency.
  • Strong understanding of malware behavior, attacker techniques, and post-exploitation activities.
  • Experience with Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.
  • Ability to perform comprehensive incident investigations, root cause analysis, and security maturity assessments.
  • Excellent analytical, problem-solving, and investigative skills.
  • Excellent bilingual communication and writing skills in English and Arabic.
Required Qualifications
  • Minimum of 6–8 years of hands-on experience in Digital Forensics and Incident Response.
  • Demonstrated experience leading complex incident response engagements from initial detection through remediation and lessons learned.
  • Strong experience with enterprise forensic and DFIR tools (e.g., Velociraptor, KAPE, Plaso, Hayabusa, Volatility, Timesketch, FTK, EnCase, X-Ways, Magnet AXIOM, Autopsy, or similar).
  • Experience with EDR platforms such as Microsoft Defender for Endpoint, Crowd Strike Falcon, Sentinel One, Cortex XDR, or similar.
  • Strong understanding of Windows, Linux, Active Directory, networking, cloud security, and enterprise attack techniques.
  • Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and modern attacker tradecraft.
  • Strong programming experience in at least one language.
  • Experience with Power Shell and Bash scripting for automation and forensic collection.
  • Comfortable using Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.
  • Strong communication skills and the ability to work collaboratively in a consulting environment.
  • Excellent English written and verbal communication skills.
  • Excellent Arabic written and verbal communication skills.
Preferred Qualifications
  • Experience performing cloud incident response across AWS, Azure, or Google Cloud Platform.
  • Experience with enterprise log analysis platforms such as Elasticsearch, Splunk, Microsoft Sentinel, or QRadar.
  • Experience with threat hunting and threat intelligence integration into DFIR investigations.
  • Experience performing malware analysis, reverse engineering, or memory forensics.
  • Experience building DFIR automation pipelines and forensic orchestration platforms.
  • Prior cybersecurity consulting background.
  • Prior offensive security, penetration testing, or purple team experience.
  • Active Git Hub account demonstrating DFIR tools, automation projects, or forensic research.
  • Demonstrated home lab or enterprise DFIR lab experience for testing investigations, malware, and attack simulations.
  • Relevant certifications such as GCFA, GCFE, GREM, GCIH, GNFA, GCFR, or equivalent industry-recognized DFIR certifications.
#J-18808-Ljbffr
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary