1 месяц назад
Lead Specialist, Incident Response (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Lead Specialist, Incident Response (Cybersecurity): Leading high-severity cybersecurity investigations across detection, containment, eradication, recovery, and post-incident review with an accent on digital forensics, insider-threat investigations, and incident command. Focus on reconstructing attacker timelines, preserving defensible evidence, improving forensic telemetry, and automating response workflows with Python, PowerShell, AI, and machine learning.
Location: Cairo, Egypt; hybrid work with work-from-home up to 2 days per week depending on team needs
Company
provides technology and communications solutions for airports, airlines, borders, and the broader air transport industry.
What you will do
- Lead high-severity and business-critical cybersecurity incidents through detection, containment, eradication, recovery, and post-incident improvement.
- Act as Incident Commander and coordinate SOC, CSIRT, IT, cloud, engineering, legal, compliance, and business stakeholders.
- Conduct digital forensics across endpoints, servers, cloud environments, networks, SaaS platforms, and enterprise applications.
- Investigate malware, ransomware, data exfiltration, account compromise, insider activity, and advanced persistent threats.
- Develop incident reports, executive briefings, playbooks, tabletop exercises, and cyber crisis response procedures.
- Design automation and improve telemetry, logging, retention, evidence collection, and forensic visibility using AI-driven analytics and machine learning.
Requirements
- Experience leading digital forensics and incident response investigations in large, complex enterprise environments.
- Hands-on experience with EDR/XDR, SIEM, SOAR, and forensic investigation tools.
- Experience collecting and analyzing evidence across endpoints, servers, cloud platforms, networks, identity systems, and SaaS environments.
- Proficiency in Python and/or PowerShell scripting and automation, with working knowledge of KQL and security analytics.
- Strong understanding of cyber adversary tactics, techniques, and procedures, including practical use of the MITRE ATT&CK framework.
- Excellent analytical, communication, stakeholder management, and technical and executive briefing skills.
Nice to have
- Certifications such as GCFA, GNFA, GCIH, GREM, GCFE, CISSP, or OSCP.
- Cloud forensics and incident response experience across Azure, AWS, or Google Cloud Platform.
- Experience with FTK, EnCase, Velociraptor, KAPE, Autopsy, or Volatility.
- Knowledge of regulatory, legal, and compliance requirements for digital investigations and evidence handling.
- Experience in aviation, airports, transportation, operational technology, or critical infrastructure.
Culture & Benefits
- Flexible workday options and up to 30 days per year working from any location in the world.
- Employee Assistance Program and personalized wellbeing support for employees and dependents.
- Professional development through LinkedIn Learning, Microsoft Enterprise Skills Initiative, Pluralsight, Harvard Business Publishing, Stanford, and other learning platforms.
- Benefits aligned with the local market and employment status.
- Inclusive and diverse international work environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →