SITE سايت

Digital Forensics & Incident Response (DFIR) Analyst

SITE سايت

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
2+ yrs
Salary
Openings
1
Posted
10 hours ago
Work mode
In office
Education
Bachelor's degree
Resume
Required to apply

Where you'll work

Job description

Overview

This position involves leading efforts in investigating cybersecurity incidents, conducting digital forensic examinations, and supporting the organization's incident response tasks to safeguard critical assets. The role emphasizes Digital Forensics, Incident Response, collecting evidence, analyzing malware, hunting threats, and root cause investigations aimed at identifying, managing, eliminating, and recovering from security breaches while ensuring forensic data remains intact and improving the overall security framework.

Key Responsibilities

  • Lead investigations on cybersecurity events through comprehensive incident examination, host and network analysis, and breach studies across various systems including endpoints, servers, cloud infrastructures, and networks.
  • Manage or assist in all phases of incident response from detection to resolution and post-incident review.
  • Collect, preserve, and image digital evidence maintaining strict chain of custody for forensic integrity.
  • Analyze system memory and dumps to detect malicious codes, persistence methods, and attacker behavior patterns.
  • Perform forensic investigations on disks, Windows, Linux systems, and network data to assess incident scope and impact.
  • Examine malware, ransomware episodes, phishing attempts, insider threats, and account breaches through thorough malware analysis and triaging.
  • Conduct root cause and timeline analyses to reconstruct attack sequences and deduce attack methods.
  • Extract and evaluate indicators of compromise or attack and study adversarial tactics, techniques, and procedures to bolster threat hunting and investigation efforts.
  • Apply forensic tools like Volatility, Autopsy, FTK, EnCase, and utilize SIEM and Endpoint Detection and Response platforms for deep analysis of artifacts, memories, logs, and traffic.
  • Analyze logs across multiple systems and security devices to detect malicious activities and support forensic examinations.
  • Collaborate with security operations, threat intelligence, IT, and cloud teams during investigations and response measures.
  • Create detailed case reports, executive summaries, forensic findings, timelines, and recommended remediation strategies.
  • Refine and maintain incident response workflows, forensic protocols, investigation methodologies, and evidence handling standards.
  • Drive continuous development of the organization's digital forensics, incident response, threat hunting, and cyber incident handling capabilities.

Qualifications

  • Bachelor’s degree in Cybersecurity, IT, Computer Science, Digital Forensics, or related areas.
  • Preferred possession of relevant cybersecurity certifications.
  • At least two years of practical experience in digital forensics and incident response, with expertise in conducting incident investigations, evidence collection, memory and disk forensics, malware analysis, threat hunting, root cause and timeline analysis, IOC extraction, log scrutiny, and using tools such as Volatility, Autopsy, FTK, EnCase, and enterprise SIEM/EDR solutions.

Job Details

This is a project-based role with SITE. The compensation includes a monthly salary along with several benefits for employees, such as social and mobile allowances and comprehensive medical insurance covering the employee, their family, and parents.

Additional Benefits

  • Social allowance
  • Mobile communication allowance
  • Medical insurance covering the employee, family, and parents

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help