Senior DFIR Consultant
Job in
Riyadh, Riyadh Region, Saudi Arabia
Listed on 2026-08-14
Listing for:
Cipher | سايڤر
Full Time
position Listed on 2026-08-14
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
- Lead and perform end-to-end Digital Forensics and Incident Response (DFIR) engagements independently, including incident triage, containment, eradication, recovery, and post-incident reporting.
- Conduct host, memory, network, cloud, and log-based forensic investigations to determine attack scope, root cause, attacker activities, and business impact.
- Perform advanced threat hunting across enterprise environments using SIEM, EDR, forensic artifacts, and threat intelligence to proactively identify malicious activity.
- Develop, maintain, and automate DFIR workflows, forensic tooling, and investigation pipelines using Python, Power Shell, Bash, and other scripting languages.
- Build and maintain internal DFIR tools, forensic parsers, automation frameworks, and investigation infrastructure.
- Collaborate with SOC, Detection Engineering, Threat Intelligence, Red Team, and IT teams to improve incident response capabilities and security posture.
- Conduct incident response readiness and maturity assessments, identifying gaps in people, processes, and technology, and provide actionable recommendations.
- Produce high-quality technical and executive reports, clearly communicating investigation findings, attack timelines, root cause analysis, and remediation recommendations in both English and Arabic.
- Mentor and train team members on digital forensics, incident response methodologies, malware analysis, forensic artifacts, and investigation best practices.
- Extensive hands-on experience conducting Digital Forensics and Incident Response investigations across Windows, Linux, cloud, and enterprise environments.
- Strong experience with endpoint, memory, network, and log analysis using industry-standard forensic and DFIR tools.
- Proficiency in Windows and Linux operating system internals, file systems, registry analysis, event logs, persistence mechanisms, authentication, and process analysis.
- Experience with EDR platforms, SIEM technologies, and threat hunting methodologies.
- Strong scripting and automation skills using Python, Power Shell, and Bash.
- Experience developing custom forensic tools, parsers, or automation to improve investigation efficiency.
- Strong understanding of malware behavior, attacker techniques, and post-exploitation activities.
- Experience with Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.
- Ability to perform comprehensive incident investigations, root cause analysis, and security maturity assessments.
- Excellent analytical, problem-solving, and investigative skills.
- Excellent bilingual communication and writing skills in English and Arabic.
- Minimum of 6–8 years of hands-on experience in Digital Forensics and Incident Response.
- Demonstrated experience leading complex incident response engagements from initial detection through remediation and lessons learned.
- Strong experience with enterprise forensic and DFIR tools (e.g., Velociraptor, KAPE, Plaso, Hayabusa, Volatility, Timesketch, FTK, EnCase, X-Ways, Magnet AXIOM, Autopsy, or similar).
- Experience with EDR platforms such as Microsoft Defender for Endpoint, Crowd Strike Falcon, Sentinel One, Cortex XDR, or similar.
- Strong understanding of Windows, Linux, Active Directory, networking, cloud security, and enterprise attack techniques.
- Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and modern attacker tradecraft.
- Strong programming experience in at least one language.
- Experience with Power Shell and Bash scripting for automation and forensic collection.
- Comfortable using Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.
- Strong communication skills and the ability to work collaboratively in a consulting environment.
- Excellent English written and verbal communication skills.
- Excellent Arabic written and verbal communication skills.
- Experience performing cloud incident response across AWS, Azure, or Google Cloud Platform.
- Experience with enterprise log analysis platforms such as Elasticsearch, Splunk, Microsoft Sentinel, or QRadar.
- Experience with threat hunting and threat intelligence integration into DFIR investigations.
- Experience performing malware analysis, reverse engineering, or memory forensics.
- Experience building DFIR automation pipelines and forensic orchestration platforms.
- Prior cybersecurity consulting background.
- Prior offensive security, penetration testing, or purple team experience.
- Active Git Hub account demonstrating DFIR tools, automation projects, or forensic research.
- Demonstrated home lab or enterprise DFIR lab experience for testing investigations, malware, and attack simulations.
- Relevant certifications such as GCFA, GCFE, GREM, GCIH, GNFA, GCFR, or equivalent industry-recognized DFIR certifications.
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×