Assistant Manager - Digital Forensics and Incident Response
Red Sea Global · Riyad
Job description
About the role
Red Sea Global is seeking an Assistant Manager to lead its Digital Forensics and Incident Response (DFIR) function. You will oversee incident triage, containment, recovery, forensic investigations, malware analysis, threat hunting, and post‑incident reporting across corporate, cloud, and operational technology environments.
Key responsibilities
- Configure, tune, and operate DFIR tooling, including endpoint detection and response, forensic acquisition platforms, and log/telemetry sources.
- Ensure incident response and forensic practices comply with internal policies, regulatory requirements, and standards such as ISO 27001, NIST SP 800‑61, and national guidelines.
- Maintain and test the incident response plan, playbooks, severity classifications, and escalation matrix.
- Lead timely triage, containment, eradication, and recovery of security incidents, meeting agreed service levels.
- Manage forensic evidence acquisition, chain of custody, and defensible preservation for legal or regulatory use.
- Develop detection use cases and hunting hypotheses, feeding findings back into monitoring and alerting capabilities.
- Oversee technical investigations of malware, intrusion, insider threats, and data exfiltration across host, memory, network, identity, and cloud artifacts.
- Produce high‑quality incident reports, executive summaries, and post‑incident reviews, tracking corrective actions to closure.
- Conduct proactive threat‑hunting activities using threat intelligence and frameworks such as MITRE ATT&CK.
- Validate DFIR readiness through tabletop exercises, attack simulations, and purple‑team testing.
Required profile
- Proven experience managing DFIR operations in a corporate or OT environment.
- Strong understanding of information security policies, regulatory compliance, and international standards.
- Demonstrated ability to lead incident response teams and coordinate cross‑functional stakeholders.
- Excellent analytical and communication skills for reporting and presenting findings.
Required skills
- Endpoint Detection and Response (EDR) platforms
- Digital forensic acquisition and analysis tools
- Malware analysis and reverse engineering
- Threat hunting using MITRE ATT&CK framework
- Log and telemetry analysis
- Incident response tooling and playbook development
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in Saudi Arabia.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 17 hours ago
Expires 1 month from now
5 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Red Sea Global
Riyad