обновлено 7 дней назад
Senior Specialist, Incident Response (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Specialist, Incident Response (Cybersecurity): Investigating cybersecurity incidents and conducting digital forensic analysis across endpoints, servers, cloud environments, networks, and SaaS platforms with an accent on evidence preservation, root-cause analysis, and incident containment. Focus on analyzing malware, ransomware, account compromise, insider threats, and data exfiltration while developing automation and improving enterprise telemetry.
Location: Cairo, Egypt; hybrid work with up to 2 days per week from home
Company
provides technology and communications solutions for airports, airlines, borders, and the global air transport industry.
What you will do
- Investigate security incidents across containment, eradication, recovery, and post-incident activities.
- Coordinate incident response with SOC, CSIRT Threat, Corporate IT, Cloud & Infrastructure, Product Engineering, and other stakeholders.
- Acquire, preserve, analyze, and report on forensic evidence from endpoints, servers, cloud environments, networks, and SaaS platforms.
- Investigate malware, ransomware, account compromise, data exfiltration, unauthorized access, and insider-threat cases.
- Develop scripts and automation for evidence collection, analysis, and response workflows.
- Improve enterprise logging, telemetry visibility, forensic readiness, and DFIR tooling.
Requirements
- Experience in digital forensics, incident response, or cyber investigations in enterprise environments.
- Hands-on experience with EDR/XDR, SIEM, forensic investigation, and security monitoring tools.
- Experience analyzing incidents across endpoints, servers, cloud environments, networks, and identity platforms.
- Proficiency in Python and/or PowerShell and working knowledge of KQL or similar query languages.
- Understanding of cyber threat actor tactics, techniques, procedures, and the MITRE ATT&CK framework.
- Strong analytical, problem-solving, documentation, and technical communication skills.
Nice to have
- GCFA, GNFA, GCIH, GREM, GCFE, CISSP, or OSCP certification.
- Cloud security and DFIR experience across Azure, AWS, and/or GCP.
- Experience with FTK, EnCase, Velociraptor, KAPE, Autopsy, or Volatility.
- Experience in aviation, transportation, critical infrastructure, or operational technology environments.
- Knowledge of security automation, orchestration, and AI-assisted investigation techniques.
Culture & Benefits
- Hybrid work with up to 2 work-from-home days per week, depending on team needs.
- Flexible working hours and the option to work from any location worldwide for up to 30 days per year.
- Employee Assistance Program and personalized wellbeing support.
- Access to professional development platforms and learning programs.
- Competitive benefits aligned with the local market and employment status.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →