Назад
Company hidden
1 месяц назад

Lead Specialist, Incident Response (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Egypt
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Specialist, Incident Response (Cybersecurity): Leading high-severity cybersecurity investigations across detection, containment, eradication, recovery, and post-incident review with an accent on digital forensics, insider-threat investigations, and incident command. Focus on reconstructing attacker timelines, preserving defensible evidence, improving forensic telemetry, and automating response workflows with Python, PowerShell, AI, and machine learning.

Location: Cairo, Egypt; hybrid work with work-from-home up to 2 days per week depending on team needs

Company

hirify.global provides technology and communications solutions for airports, airlines, borders, and the broader air transport industry.

What you will do

  • Lead high-severity and business-critical cybersecurity incidents through detection, containment, eradication, recovery, and post-incident improvement.
  • Act as Incident Commander and coordinate SOC, CSIRT, IT, cloud, engineering, legal, compliance, and business stakeholders.
  • Conduct digital forensics across endpoints, servers, cloud environments, networks, SaaS platforms, and enterprise applications.
  • Investigate malware, ransomware, data exfiltration, account compromise, insider activity, and advanced persistent threats.
  • Develop incident reports, executive briefings, playbooks, tabletop exercises, and cyber crisis response procedures.
  • Design automation and improve telemetry, logging, retention, evidence collection, and forensic visibility using AI-driven analytics and machine learning.

Requirements

  • Experience leading digital forensics and incident response investigations in large, complex enterprise environments.
  • Hands-on experience with EDR/XDR, SIEM, SOAR, and forensic investigation tools.
  • Experience collecting and analyzing evidence across endpoints, servers, cloud platforms, networks, identity systems, and SaaS environments.
  • Proficiency in Python and/or PowerShell scripting and automation, with working knowledge of KQL and security analytics.
  • Strong understanding of cyber adversary tactics, techniques, and procedures, including practical use of the MITRE ATT&CK framework.
  • Excellent analytical, communication, stakeholder management, and technical and executive briefing skills.

Nice to have

  • Certifications such as GCFA, GNFA, GCIH, GREM, GCFE, CISSP, or OSCP.
  • Cloud forensics and incident response experience across Azure, AWS, or Google Cloud Platform.
  • Experience with FTK, EnCase, Velociraptor, KAPE, Autopsy, or Volatility.
  • Knowledge of regulatory, legal, and compliance requirements for digital investigations and evidence handling.
  • Experience in aviation, airports, transportation, operational technology, or critical infrastructure.

Culture & Benefits

  • Flexible workday options and up to 30 days per year working from any location in the world.
  • Employee Assistance Program and personalized wellbeing support for employees and dependents.
  • Professional development through LinkedIn Learning, Microsoft Enterprise Skills Initiative, Pluralsight, Harvard Business Publishing, Stanford, and other learning platforms.
  • Benefits aligned with the local market and employment status.
  • Inclusive and diverse international work environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →