Назад
Company hidden
обновлено 7 дней назад

Senior Specialist, Incident Response (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Egypt
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Specialist, Incident Response (Cybersecurity): Investigating cybersecurity incidents and conducting digital forensic analysis across endpoints, servers, cloud environments, networks, and SaaS platforms with an accent on evidence preservation, root-cause analysis, and incident containment. Focus on analyzing malware, ransomware, account compromise, insider threats, and data exfiltration while developing automation and improving enterprise telemetry.

Location: Cairo, Egypt; hybrid work with up to 2 days per week from home

Company

hirify.global provides technology and communications solutions for airports, airlines, borders, and the global air transport industry.

What you will do

  • Investigate security incidents across containment, eradication, recovery, and post-incident activities.
  • Coordinate incident response with SOC, CSIRT Threat, Corporate IT, Cloud & Infrastructure, Product Engineering, and other stakeholders.
  • Acquire, preserve, analyze, and report on forensic evidence from endpoints, servers, cloud environments, networks, and SaaS platforms.
  • Investigate malware, ransomware, account compromise, data exfiltration, unauthorized access, and insider-threat cases.
  • Develop scripts and automation for evidence collection, analysis, and response workflows.
  • Improve enterprise logging, telemetry visibility, forensic readiness, and DFIR tooling.

Requirements

  • Experience in digital forensics, incident response, or cyber investigations in enterprise environments.
  • Hands-on experience with EDR/XDR, SIEM, forensic investigation, and security monitoring tools.
  • Experience analyzing incidents across endpoints, servers, cloud environments, networks, and identity platforms.
  • Proficiency in Python and/or PowerShell and working knowledge of KQL or similar query languages.
  • Understanding of cyber threat actor tactics, techniques, procedures, and the MITRE ATT&CK framework.
  • Strong analytical, problem-solving, documentation, and technical communication skills.

Nice to have

  • GCFA, GNFA, GCIH, GREM, GCFE, CISSP, or OSCP certification.
  • Cloud security and DFIR experience across Azure, AWS, and/or GCP.
  • Experience with FTK, EnCase, Velociraptor, KAPE, Autopsy, or Volatility.
  • Experience in aviation, transportation, critical infrastructure, or operational technology environments.
  • Knowledge of security automation, orchestration, and AI-assisted investigation techniques.

Culture & Benefits

  • Hybrid work with up to 2 work-from-home days per week, depending on team needs.
  • Flexible working hours and the option to work from any location worldwide for up to 30 days per year.
  • Employee Assistance Program and personalized wellbeing support.
  • Access to professional development platforms and learning programs.
  • Competitive benefits aligned with the local market and employment status.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →