Senior Incident Response Specialist
Indexed description
Responsibilities
- Monitor and investigate security alerts generated by SIEM, EDR, IDS/IPS, firewalls, and other security tools.
- Perform cyber incident triage by determining severity, scope, urgency, and business impact.
- Lead technical investigations and coordinate incident response activities across multiple teams.
- Execute containment, eradication, and recovery activities during cyber incidents.
- Perform real-time incident handling, forensic evidence collection, malware analysis, and threat correlation.
- Collect and preserve digital evidence following forensic best practices.
- Analyze host, network, firewall, IDS/IPS, and application logs to identify attack patterns.
- Perform malware analysis and identify Indicators of Compromise (IOCs).
- Investigate compromised systems and recommend remediation measures.
- Maintain complete incident records from detection through closure.
- Prepare incident reports, executive summaries, and post-incident ("After Action") reports.
- Develop technical guidance, incident response playbooks, and standard operating procedures.
- Coordinate with Threat Intelligence teams to validate threats and enrich investigations.
- Monitor external threat intelligence feeds and emerging cyber threats.
- Recommend proactive improvements to security controls based on investigation findings.
- Collaborate with infrastructure, application, SOC, legal, and business teams during incidents.
- Support vendor evaluations and provide technical input into cybersecurity solutions.
- Participate in developing technical specifications, RFPs, and SLAs.
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Technology, Computer Engineering, or a related discipline.
- Minimum 10 years of experience in Cybersecurity, with at least 7 years specializing in Incident Response, Security Operations Center (SOC), or Cyber Defense.
- Proven experience in managing the complete Incident Response lifecycle, including preparation, detection, analysis, containment, eradication, recovery, and post-incident reviews.
- Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, ArcSight, or equivalent for security monitoring, log analysis, and incident investigation.
- Strong expertise in Endpoint Detection and Response (EDR) solutions, including Microsoft Defender for Endpoint, CrowdStrike Falcon, Carbon Black, SentinelOne, or similar technologies.
- Experience conducting digital forensic investigations, evidence collection, malware analysis, and root cause analysis while maintaining forensic integrity and chain of custody.
- Solid understanding of cyber threat intelligence concepts, attacker tactics, techniques, and procedures (TTPs), with practical application of the MITRE ATT&CK Framework.
- Proficiency in analyzing security logs from multiple sources, including operating systems, applications, network devices, cloud platforms, and security appliances to identify Indicators of Compromise (IOCs).
- Working knowledge of scripting and automation using PowerShell, Python, or Bash to support investigations, automate repetitive tasks, and enhance incident response processes.
- Preferred Certifications:Security+, CEH, CISSP, GICSP, CCNA Security, or equivalent (not mandatory but an advantage).
- Strong analytical, problem-solving, and decision-making skills with the ability to perform effectively under pressure during critical cybersecurity incidents.
- Excellent communication, stakeholder management, and report-writing skills, with the ability to prepare technical investigation reports, executive summaries, and post-incident recommendations, while collaborating effectively with cross-functional teams and external vendors.
- Excellent written and verbal communication skills in English & Arabic.
- Career progression and growth through challenging projects and work.
- Employee engagement and wellness campaigns activities throughout the year.
- Excellent learning and development opportunities.
- Inclusive and diverse working environment.
- Flexible working environment.
- Open door policy.
Present in the Middle East since 2004, Help AG was strategically acquired by e& (formerly Etisalat Group) in Feb 2020, hence creating a cybersecurity and digital transformation powerhouse in the region.
Help AG has firmly established itself as the region's trusted IT security advisor by remaining vendor-agnostic, trustworthy, independent, and cybersecurity focused. With best-of-breed technologies from industry-leading vendor partners, expertly qualified service delivery teams and a state-of-the-art consulting practice, Help AG delivers unmatched value to its customers by strengthening their cyber defenses and safeguarding their business.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search