Senior Specialist, Incident Response (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Specialist, Incident Response (Cybersecurity): Investigating cybersecurity incidents and performing digital forensic analysis to contain and remediate security threats across a global environment with an accent on root cause determination and evidence preservation. Focus on analyzing artifacts from endpoints and cloud environments, developing automation for evidence collection, and strengthening cyber resilience.
Location: Cairo, Egypt (Hybrid: work from home up to 2 days/week)
Company
provides technology and communication innovations that power the global air travel industry, operating in 95% of international airports.
What you will do
- Manage the full incident response lifecycle, including analysis, containment, eradication, recovery, and post-incident activities.
- Perform forensic acquisition and analysis of evidence from endpoints, servers, cloud environments, networks, and SaaS platforms.
- Investigate insider threats, policy violations, misuse of privileged access, and potential data loss events.
- Develop and maintain Python and PowerShell scripts to automate evidence collection and response workflows.
- Collaborate with SOC, CSIRT, and Cloud teams to improve logging, telemetry visibility, and forensic readiness.
- Document technical findings and provide remediation recommendations to strengthen the overall security posture.
Requirements
- Proven experience in digital forensics and incident response (DFIR) within enterprise environments.
- Hands-on expertise with EDR/XDR, SIEM, and security monitoring tools.
- Proficiency in Python, PowerShell, and query languages like KQL.
- Deep understanding of the MITRE ATT&CK framework and cyber threat actor TTPs.
- Must be based in Cairo, Egypt to comply with hybrid work requirements.
Nice to have
- Relevant certifications such as GCFA, GNFA, GCIH, GREM, GCFE, CISSP, or OSCP.
- Experience with cloud security and DFIR investigations across Azure, AWS, and/or GCP.
- Proficiency with forensic tools like FTK, EnCase, Velociraptor, KAPE, Autopsy, or Volatility.
- Experience working in aviation, transportation, critical infrastructure, or operational technology (OT) environments.
- Knowledge of security automation, orchestration, and AI-assisted investigation techniques.
Culture & Benefits
- Flexible work options including Flex Week (up to 2 days WFH) and Flex Day to suit personal plans.
- Flex-Location perk allowing up to 30 days per year to work from any location globally.
- Employee wellbeing support through the Employee Assistance Program (EAP) and Champion Health platform.
- Extensive professional development via LinkedIn Learning, Pluralsight, Harvard Business Publishing, and Stanford.
- Inclusive, diverse global environment operating across 200 countries with a focus on equality.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →