21 день назад
Senior Consultant - Incident Response (CPX)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Consultant - Incident Response (CPX) (Cybersecurity): Leading incident response engagements and digital forensic investigations in a critical cyber defence environment with an accent on threat hunting, multi-platform forensics, and stakeholder communication. Focus on analyzing host and network evidence, developing remediation plans for compromised organizations, and applying ATT&CK and AI security processes.
Location: MBZ City, Abu Dhabi, United Arab Emirates
Company
operates in a critical cyber defence environment focused on incident response, digital forensics, and cybersecurity operations.
What you will do
- Lead active incident response engagements and execute threat hunting in support of incident response and SOC activities.
- Conduct host and network-based forensic investigations across Windows, macOS, and Linux.
- Analyze system and network device logs, investigate malware, and research current threats and attack trends.
- Produce technical reports and briefs, explain findings to technical and non-technical stakeholders, and manage client communications.
- Contribute to process documentation, continuous service improvement, research activities, and internal knowledge-sharing sessions.
- Maintain the client-fostered DFIR Forensics Lab and act as a subject matter expert in at least one forensic or incident response specialization.
Requirements
- 3–5 years of experience in digital forensics and cyber incident response.
- Strong understanding of blue team operations, incident response management, digital forensics, enterprise infrastructure, network protocols, TCP/IP, Windows, Linux, and macOS.
- Experience with network analysis tools such as Bro/Zeek, RITA, or Suricata, as well as system and network log analysis.
- Knowledge of ATT&CK, targeted attacks, malware analysis, mobile devices, current vulnerabilities, and tactical and strategic remediation planning.
- Excellent spoken and written English, with strong stakeholder management and communication skills.
- At least one GIAC certification, such as GNFA, GCIH, GCIA, GCFE, GCFA, or GDAT; equivalent eLearnSecurity certification may also be accepted.
Nice to have
- Bachelor’s degree in Computer Science or Engineering.
- Subject matter expertise in host forensics, network forensics, mobile forensics, malware analysis, OT/ICS incident response, cloud forensics, or threat hunting.
Culture & Benefits
- Flexible schedule that can adapt to changing situations and opportunities.
- Work independently after an initial three-month period while collaborating with a skilled blue team.
- Opportunity to contribute to internal brown-bag sessions, research, and service improvement.
- Fast-paced, operationally critical cyber defence environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →