Job Description

Overview

As a Lead Incident Responder in the Incident Response & Forensics Team within a high-impact and operationally critical cyber defence environment, you live and breathe blue team operations. Your technical expertise in digital forensics and cyber incident response is well complemented by your integrity and passion for cyber security and technology in general.

You work well in a team of highly motivated and skilled blue teamers, but you can also achieve your work independently in different engagements and scenarios.

You enjoy taking on new challenges in a fast paced and dynamic working environment. You are a team player who is always willing to help out where required, with a humble and positive attitude.

Responsibilities

Serve as technical & coordination lead on active incident response engagements

English communication skills and stakeholder management skills are a MUST, to coordinate technical staff and communicate investigation progress to clients

Execute and coordinate threat hunting activities in support of incident response engagements and SOC activities

Perform host and/or network-based forensics across Windows, Mac, and Linux platforms.

Execute digital forensic investigations supporting cyber incident response engagements

Contribute to process documentation and continuous service improvement activities

Lead the production of detailed reports and technical briefs, effectively communicate tasks, methodology and guidance to customers

Perform Quality Assurance activities over reports created by more junior members of the team

Explain technical findings in a manner that can be easily understood by technical and non-technical staff

Demonstrate industry thought leadership through creating and developing internal brown-bag sessions

Lead team research activities in search of service improvement tasks

Help maintain the client-fostered DFIR Forensics Lab

Be the team’s subject matter expert on at least two of the following verticals: host forensics, network forensics, mobile forensics, malware analysis, OT/ICS Incident Response, cloud forensics, threat hunting

Ability to achieve tasks independently within the team after initial 2 months. Flexible schedule that is open to changing situations and opportunities, as is typical with incident response. You must be a team player, with a humble and approachable nature who is willing to go the extra mile.

Technical Skills : -

Strong understanding of blue team operations and threat hunting

Sound understanding of network protocols, TCP/IP etc. Sound understanding of Microsoft Windows

Sound understanding of Linux and OSX

Sound forensic skills across multiple operating systems

Strong understanding of network analysis tools like Bro/Zeek, Rita or Suricata

Ability to perform analysis of system and network devices logs

Sound understanding of the capabilities of static and dynamic malware analysis

Sound understanding of enterprise systems, technologies, and infrastructure

Strong understanding of targeted attacks and able to create customized tactical and strategic remediation plans for compromised organizations

Strong understanding of current threats, vulnerabilities, and attack trends

Strong understanding of ATT&CK framework

Sound understanding of AI security processes & ability to use AI properly within IR investigations

Excellent organisational skills, ability to prioritise, and ability to work independently

Qualifications

Certifications/Qualifications/Skills : -

Good attention to detail and reporting accuracy, excellent stakeholder management & communication skills; excellent English language skills, both spoken and written

GIAC Certified in a minimum of one discipline (two desired): GNFA, GCIH, GCIA, GCFE, GCFA, GDAT, etc

Or equivalent (eLearnSecurity .etc)

Previous experience performing digital forensics is A MUST

Previous experience performing malware analysis is desirable

Bachelor's degree in Computer Science or Engineering desirable, but not mandatory


Job Details

Role Level: Not Applicable Work Type: Full-Time
Country: United Arab Emirates City: Abu Dhabi
Company Website: https://cpx.net/ Job Function: Cybersecurity
Company Industry/
Sector:
Other

What We Offer


About the Company

Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.

Report

Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together. Applicants are advised to research the bonafides of the prospective employer independently. We do NOT endorse any requests for money payments and strictly advice against sharing personal or bank related information. We also recommend you visit Security Advice for more information. If you suspect any fraud or malpractice, email us at abuse@talentmate.com.


ad 1
Talentmate Instagram Talentmate Facebook Talentmate YouTube Talentmate LinkedIn