Red Sea Global

Assistant Manager - Digital Forensics and Incident Response

Red Sea Global

Riyadh, Riyadh Province, Saudi Arabia · Full Time

Be the first to apply

Experience
6+ yrs
Salary
Openings
1
Posted
3 days ago
Work mode
In office
Education
Bachelor’s degree
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About Red Sea Global

Red Sea Global (RSG) is a visionary developer committed to forging a sustainable future through transformative projects that align with Saudi Arabia's Vision 2030 and global regenerative tourism goals. The company emphasizes positive social and environmental impact.

Job Purpose

This role leads and manages RSG's Digital Forensics and Incident Response (DFIR) operations. Responsibilities include handling incident triage, containment, recovery, forensic investigations, malware and artifact examination, threat hunting, and post-incident reporting across corporate, cloud, and operational technology environments. The role ensures efficient detection, investigation, and resolution of security incidents within defined service levels, maintaining forensic evidence integrity and aligning practices with organizational strategies and regulatory standards.

Key Responsibilities

  • Oversee configuration, tuning, and daily management of DFIR tools such as endpoint detection and response systems, forensic platforms, and log/telemetry sources used for investigations.
  • Ensure adherence of incident response and forensics processes to RSG's security policies, relevant regulations, and international standards including NCA ECC, PDPL, ISO 27001, and NIST SP 800-61.
  • Develop and maintain the incident response plan, playbooks, severity classifications, and escalation protocols, keeping them updated and tested according to evolving threats.
  • Coordinate rapid triage, containment, eradication, and recovery of incidents based on business impact and within agreed service levels.
  • Manage forensic evidence collection and handling, ensuring chain of custody, integrity confirmation, and defensible preservation for legal or disciplinary purposes.
  • Create detection use cases and threat hunting hypotheses based on investigations, integrating findings into monitoring and alerting systems.
  • Lead technical investigations into malware, intrusions, insider threats, and data exfiltration involving analysis of host, memory, network, identity, and cloud artifacts with documented root cause analysis.
  • Ensure high-quality and timely incident reports, executive summaries, and post-incident reviews, tracking actionable findings and corrective measures through to completion.
  • Conduct proactive threat hunting across multiple telemetry domains using intelligence tied to frameworks like MITRE ATT&CK.
  • Validate DFIR readiness via tabletop exercises, attack simulations, purple-team engagements, and confirming feasible response and recovery objectives.
  • Drive automation of investigative and response workflows using scripting and orchestration playbooks to improve detection and recovery efficiency.
  • Maintain comprehensive documentation of all DFIR processes, configurations, and procedures, and communicate them effectively to relevant parties.
  • Integrate cyber threat intelligence into detection and response processes, including indicator ingestion, enrichment, and retrospective analyses.
  • Manage vendor and service provider relationships for DFIR tools and incident response services, ensuring compliance with service levels and best practices.
  • Oversee knowledge transfer from external resources to RSG, ensuring operational ownership and documented handover.
  • Serve as escalation contact for high-severity or legally sensitive incidents, validating risks, ensuring approvals and notifications, and leading corrective and preventive actions.

Managerial Duties

  • Contribute to department cybersecurity strategy from a DFIR perspective to ensure alignment with RSG's vision, mission, and risk appetite.
  • Set objectives, KPIs, and annual plans for DFIR operations focusing on incident response, forensics, threat hunting, and reporting, ensuring performance targets are met.
  • Assist in budget development and monitor expenditures for DFIR initiatives, tools, and services to promote cost-effective operations.
  • Implement and enforce DFIR policies and standards, oversee performance monitoring, KPI reporting, and initiate corrective measures as needed.
  • Ensure proper staffing, training, and deployment of the DFIR team including on-call schedules, fostering talent development and succession planning.

Required Qualifications and Experience

  • Bachelor’s degree required in Computer Science, Information Security, Information Systems, Software Engineering, or related technical field.
  • Master’s degree preferred in Information Security, Cybersecurity Management, or MBA focused on IT/Security.
  • At least 6 years in cybersecurity, with a minimum of 3 years of practical experience in digital forensics and incident response in an enterprise setting.
  • Preferred certifications include GCFA, GCFE, GCIH, GNFA, GREM, or CISSP.
  • Fluent in both written and spoken Arabic and English.
  • Must be able to participate in a 24/7 on-call escalation rotation for security incidents and be willing to travel onsite for evidence gathering if necessary.

Additional Information

Red Sea Global offers a unique opportunity to be part of a pioneering company driving sustainable growth and innovation in Saudi Arabia and beyond.

Minimum education

Bachelor's Degree

How they work

Communication Problem Solving Attention to Detail Leadership

Languages

Apple Servicenow
🤖
Online · instant AI help
Broxer