Cybersecurity Incident Management Specialist
flynas · Riyadh, Saudi Arabia
Apply & track with Apply EdgeJob PurposeResponsible for coordinating and managing the end-to-end cybersecurity incident response lifecycle, including incident assessment, classification, investigation, escalation, containment, eradication, recovery, and closure. The role coordinates with internal stakeholders, cybersecurity service providers, and relevant third parties to ensure timely and effective response to cybersecurity incidents, while maintaining accurate incident records, supporting applicable regulatory reporting requirements, tracking corrective actions, and contributing to lessons learned and continuous improvement of cybersecurity incident response capabilities. Operational Responsibilities
- Receive and assess potential cybersecurity incidents escalated through cybersecurity monitoring capabilities, the SOC/MSSP, employees, third parties, or other authorized reporting channels.
- Validate, classify, prioritize, and manage cybersecurity incidents according to approved incident classification criteria, severity levels, business impact, and escalation requirements.
- Coordinate end-to-end cybersecurity incident response activities, including investigation, containment, eradication, recovery, and closure, with relevant internal teams, service providers, and third parties.
- Coordinate with the SOC/MSSP and relevant cybersecurity teams to obtain required technical analysis, indicators of compromise (IOCs), threat intelligence, logs, and other information necessary for incident investigation and response.
- Escalate critical and high-severity cybersecurity incidents according to the approved escalation matrix and ensure timely communication with relevant management and stakeholders.
- Coordinate with IT, system owners, business units, Legal, Data Protection, Business Continuity, Communications, Human Resources, and other relevant functions based on the nature and impact of the incident.
- Maintain complete and accurate incident records, including classification, impact, investigation activities, decisions, actions taken, evidence, communications, timelines, and resolution details.
- Ensure appropriate preservation and handling of incident-related evidence and support digital forensic activities when required.
- Support assessment of cybersecurity incidents against applicable NCA and other regulatory reporting and notification requirements, and coordinate the preparation of required incident information and regulatory submissions.
- Conduct and coordinate post-incident reviews and Root Cause Analysis (RCA) for applicable cybersecurity incidents.
- Identify corrective and preventive actions arising from incidents, root cause analyses, and lessons learned, assign them to relevant owners, and track their implementation through closure.
- Validate that agreed recovery and remediation activities have been completed before recommending incident closure.
- Maintain and periodically review cybersecurity incident response procedures, playbooks, contact lists, escalation matrices, and supporting documentation.
- Participate in cybersecurity incident response exercises and simulations and document identified gaps and improvement actions.
- Monitor incident response performance against defined SLAs, KPIs, and other performance measures and prepare periodic incident management reports and dashboards.
- Identify recurring incident patterns, affected assets, attack vectors, control weaknesses, and other trends to support continuous improvement of cybersecurity controls.
- Support coordination with external incident response, digital forensics, threat intelligence, and other specialized service providers when required.