- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 2 days ago
- Work mode
- In office
- Education
- Bachelor's degree
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
Help AG is seeking a skilled leader to head its Digital Forensics and Incident Response (DFIR) team, responsible for managing incident response activities both onsite and offsite. This role involves guiding clients through security incident handling by utilizing diverse security technologies and best practice digital forensic techniques to detect, validate, and neutralize IT security threats.
Key Responsibilities
- Supervise and mentor the DFIR team, handling day-to-day leadership duties.
- Coordinate incident response efforts across unfamiliar settings, covering triage, containment, eradication, and recovery phases.
- Perform comprehensive forensic investigations to identify causes behind security breaches and incidents.
- Formulate and update standardized and bespoke incident response policies and procedures tailored to client needs.
- Work collaboratively with IT, legal, and management teams for seamless incident response coordination.
- Analyze logs and data from varied security devices—antivirus software, IDS/IPS, firewalls, switches, VPNs, and others.
- Conduct forensic examinations on artifacts such as RAM dumps, packet captures, system logs, and disk images.
- Reverse engineer malware, creating detection signatures and indicators of compromise.
- Develop custom incident response tools, scripts, and detection content to enhance threat identification.
- Investigate adversary tactics, develop advanced detection rules, and lead proactive threat hunting initiatives.
- Apply established incident response frameworks like SANS methodologies.
- Provide remote technical support for managed security services via phone and electronic communication.
- Be prepared for onsite client engagement during active security incidents, including international deployments.
- Maintain acute awareness of evolving threats and cybersecurity trends.
- Promote excellence within the team through knowledge sharing, writing technical articles, and contributing to internal and external reports.
- Prepare and deliver detailed client reports emphasizing accuracy and actionable insights.
- Offer expert consultation and guidance to junior incident response and forensic team members.
- Continuously update skills in line with latest industry advancements and emerging threats.
- Perform other related responsibilities as required.
Qualifications & Expertise
- Bachelor’s degree in Computer Science, Information Systems, Electrical Engineering, or related fields.
- Over 10 years experience in information security domains, including operations, intrusion detection, incident management, malware and threat analysis, reverse engineering.
- Minimum 2-3 years in a senior or lead analyst role, with proven leadership and mentoring capabilities for security professionals.
- Possession of certifications such as CISSP, GCIA, GCIH, GCFA, GCFE, GREM, or OSCP.
- Proficient in at least four areas including security event analysis, network security operations, reverse engineering, malware analysis, forensic investigations on various OS platforms, penetration testing, and directory service administration.
- Strong grasp of IT security best practices, attack vectors, and mitigation techniques.
- Documented experience in incident response processes, stakeholder management, and adherence to protocols.
- Capability in evaluating logs from security infrastructures like firewalls and IDS/IPS.
- Expertise using digital forensics tools and scripting custom utilities to aid investigations.
- Experience in reverse engineering malware across multiple programming languages (x86/x64, C, C#, Go), and crafting Yara, Snort, and Sigma rules.
- Advanced understanding of Red Team methodologies and enterprise-scale adversary detection.
- Strong scripting skills in languages such as Python, PowerShell, and Bash.
- Comprehensive knowledge of TCP/IP, network architecture, and security products.
- Awareness of attack techniques including scanning, man-in-the-middle, sniffing, denial-of-service, and abnormal activities like worms, Trojans, and viruses.
- Proven experience managing response to advanced persistent threats and ransomware incidents using established IR frameworks.
Employee Benefits
- Health insurance coverage through a leading global medical provider.
- Opportunities for career advancement via challenging projects.
- Participation in wellness and employee engagement initiatives throughout the year.
- Access to outstanding learning and development programs.
- Annual paid flight tickets.
- A supportive, inclusive, and diverse workplace environment.
- Flexible and hybrid work options available.
- Open door policy encouraging transparency and communication.
About Help AG
As the cybersecurity division of e&, Help AG is a trusted partner throughout the Middle East dedicated to enabling governments, enterprises, and critical sectors to innovate securely. The company integrates strategic consultancy, managed security services, and technology expertise to enhance cyber resilience and promote secure digital transformation in sovereign environments.
Minimum education
Bachelor's Degree
Industry
Cybersecurity