Apply Edge Start your job search

Senior DFIR Consultant

Cipher | سايڤر · Riyadh, Saudi Arabia

Apply & track with Apply Edge
Key Responsibilities - Lead and perform end-to-end Digital Forensics and Incident Response (DFIR) engagements independently, including incident triage, containment, eradication, recovery, and post-incident reporting.- Conduct host, memory, network, cloud, and log-based forensic investigations to determine attack scope, root cause, attacker activities, and business impact.- Perform advanced threat hunting across enterprise environments using SIEM, EDR, forensic artifacts, and threat intelligence to proactively identify malicious activity.- Develop, maintain, and automate DFIR workflows, forensic tooling, and investigation pipelines using Python, PowerShell, Bash, and other scripting languages.- Build and maintain internal DFIR tools, forensic parsers, automation frameworks, and investigation infrastructure.- Collaborate with SOC, Detection Engineering, Threat Intelligence, Red Team, and IT teams to improve incident response capabilities and security posture.- Conduct incident response readiness and maturity assessments, identifying gaps in people, processes, and technology, and provide actionable recommendations.- Produce high-quality technical and executive reports, clearly communicating investigation findings, attack timelines, root cause analysis, and remediation recommendations in both English and Arabic.- Mentor and train team members on digital forensics, incident response methodologies, malware analysis, forensic artifacts, and investigation best practices. Required Skills - Extensive hands-on experience conducting Digital Forensics and Incident Response investigations across Windows, Linux, cloud, and enterprise environments.- Strong experience with endpoint, memory, network, and log analysis using industry-standard forensic and DFIR tools.- Proficiency in Windows and Linux operating system internals, file systems, registry analysis, event logs, persistence mechanisms, authentication, and process analysis.- Experience with EDR platforms, SIEM technologies, and threat hunting methodologies.- Strong scripting and automation skills using Python, PowerShell, and Bash.- Experience developing custom forensic tools, parsers, or automation to improve investigation efficiency.- Strong understanding of malware behavior, attacker techniques, and post-exploitation activities.- Experience with Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.- Ability to perform comprehensive incident investigations, root cause analysis, and security maturity assessments.- Excellent analytical, problem-solving, and investigative skills.- Excellent bilingual communication and writing skills in English and Arabic. Required Qualifications - Minimum of 6–8 years of hands-on experience in Digital Forensics and Incident Response.- Demonstrated experience leading complex incident response engagements from initial detection through remediation and lessons learned.- Strong experience with enterprise forensic and DFIR tools (e.g., Velociraptor, KAPE, Plaso, Hayabusa, Volatility, Timesketch, FTK, EnCase, X-Ways, Magnet AXIOM, Autopsy, or similar).- Experience with EDR platforms such as Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, Cortex XDR, or similar.- Strong understanding of Windows, Linux, Active Directory, networking, cloud security, and enterprise attack techniques.- Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and modern attacker tradecraft.- Strong programming experience in at least one language.- Experience with PowerShell and Bash scripting for automation and forensic collection.- Comfortable using Git for version control, collaboration, and maintaining DFIR tools, scripts, and documentation.- Strong communication skills and the ability to work collaboratively in a consulting environment.- Excellent English written and verbal communication skills.- Excellent Arabic written and verbal communication skills. Preferred Qualifications - Experience performing cloud incident response across AWS, Azure, or Google Cloud Platform.- Experience with enterprise log analysis platforms such as Elasticsearch, Splunk, Microsoft Sentinel, or QRadar.- Experience with threat hunting and threat intelligence integration into DFIR investigations.- Experience performing malware analysis, reverse engineering, or memory forensics.- Experience building DFIR automation pipelines and forensic orchestration platforms.- Prior cybersecurity consulting background.- Prior offensive security, penetration testing, or purple team experience.- Active GitHub account demonstrating DFIR tools, automation projects, or forensic research.- Demonstrated home lab or enterprise DFIR lab experience for testing investigations, malware, and attack simulations.- Relevant certifications such as GCFA, GCFE, GREM, GCIH, GNFA, GCFR, or equivalent industry-recognized DFIR certifications.