About Exequt
Exequt is a rapidly expanding consulting and technology services firm. We specialize in cybersecurity, Identity and Access Management (IAM), cloud solutions, AI-driven platforms, and custom software engineering. Our firm partners with both public and private sector organizations to deliver high-impact digital transformation initiatives across the Kingdom of Saudi Arabia.
The Role: Cybersecurity Incident Response Specialist
Exequt is seeking a Cybersecurity Incident Response Specialist to join our team in Riyadh, Saudi Arabia. This full-time role focuses on investigating, containing, eradicating, and recovering from security incidents across various client environments, including endpoints, networks, identities, cloud platforms, and applications. The specialist will play a critical role in helping clients effectively respond to and learn from real-world cyber threats.
Key Responsibilities
- Investigate and respond to cybersecurity incidents such as ransomware, malware, phishing, account compromise, data theft, and lateral movement.
- Perform incident triage, investigation, containment, eradication, and recovery procedures.
- Conduct threat hunting activities and perform root-cause analysis for security incidents.
- Execute basic digital forensics and malware analysis tasks.
- Identify and analyze Indicators of Compromise (IOCs) and Indicators of Attack (IOAs), mapping attacks to the MITRE ATT&CK framework.
- Investigate security events within Windows, Linux, Active Directory, and cloud environments.
- Utilize Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR)/Extended Detection and Response (XDR) platforms for security event investigation.
- Develop and improve incident response playbooks and detection rules.
- Prepare detailed incident reports, timelines, and remediation recommendations.
- Support Security Operations Center (SOC)/Computer Security Incident Response Team (CSIRT) operations and critical incident response efforts.
Required Qualifications and Skills
- Strong experience in Incident Response (IR), Digital Forensics and Incident Response (DFIR), Security Operations Center (SOC), or Threat Hunting.
- Hands-on experience with security platforms such as Splunk, Microsoft Sentinel, QRadar, CrowdStrike, SentinelOne, Microsoft Defender, or Cortex XDR.
- Strong knowledge of Windows and Linux operating systems, as well as networking principles.
- Proficiency in scripting languages such as PowerShell, Python, or Bash.
- Strong understanding of the MITRE ATT&CK framework and common attack techniques.
- Saudi Nationality is required for this position.
Preferred Experience
- Experience investigating specific incident types including ransomware, phishing, credential theft, and endpoint compromise.
Work Environment and Compensation
This is a full-time position based in Riyadh, Saudi Arabia. Compensation for this role is structured on a performance-based model. We are looking for a dedicated professional who thrives on investigating and neutralizing security threats to join our team.
عن Exequt
Exequt هي شركة استشارية وخدمات تكنولوجية تتوسع بسرعة. نتخصص في الأمن السيبراني، إدارة الهوية والوصول (IAM)، الحلول السحابية، منصات تعتمد على الذكاء الاصطناعي، وهندسة البرمجيات المخصصة. تتعاون شركتنا مع كل من القطاعات العامة والخاصة لتنفيذ مبادرات التحول الرقمي عالية التأثير عبر المملكة العربية السعودية.
الدور: مختص ردّ على حوادث الأمن السيبراني
تبحث شركة Exequt عن مختص ردّ على حوادث الأمن السيبراني للانضمام إلى فريقنا في الرياض، المملكة العربية السعودية. يركّز هذا الدور بدوام كامل على التحقيق في الحوادث والتعامل معها واخمادها والتعافي منها عبر بيئات عمل العملاء المختلفة، بما في ذلك نقاط النهاية، والشبكات، والهويات، والمنصات السحابية، والتطبيقات. سيؤدي الاختصاصي دوراً حيوياً في مساعدة العملاء على الاستجابة الفعالة والتعلم من التهديدات السيبرانية الواقعية.
المسؤوليات الرئيسية
- التحقيق في الحوادث السيبرانية والردّ عليها مثل فدية، البرمجيات الخبيثة، التصيد الاحتيالي، اختراق الحساب، سرقة البيانات، والحركة الجانبية.
- تنفيذ إجراءات فرز الحوادث والتحقيق والاحتواء والإبادة والتعافي.
- إجراء أنشطة صيد التهديدات وتحليل السبب الجذري للحوادث الأمنية.
- تنفيذ مهام علم الأدلة الرقمية وتحليل البرمجيات الخبيثة بشكل أساسي.
- تحديد وتحليل مؤشرات الاختراق (IOCs) ومؤشرات الهجوم (IOAs)، وربط الهجمات بإطار MITRE ATT&CK.
- التحقيق في أحداث الأمان ضمن أنظمة Windows وLinux وActive Directory وبيئات السحابة.
- استخدام أنظمة إدارة معلومات وأحداث الأمن (SIEM) ومنصات الكشف والاستجابة للنقاط الطرفية (EDR)/الكشف والاستجابة الموسّع (XDR) للتحقيق في أحداث الأمن.
- تطوير وتحسين كتيبات الاستجابة للحوادث وقواعد الكشف.
- إعداد تقارير تفصيلية عن الحوادث والجداول الزمنية وتوصيات التخفيف.
- دعم عمليات مركز عمليات الأمن (SOC)/فريق الاستجابة لحوادث الأمن المعلوماتي (CSIRT) وجهود الاستجابة للحوادث الحرجة.
المؤهلات والمهارات المطلوبة
- خبرة قوية في الاستجابة للحوادث (IR)، الأدلة الرقمية والاستجابة للحوادث (DFIR)، مركز عمليات الأمن (SOC)، أو صيد التهديدات.
- خبرة عملية في منصات الأمن مثل Splunk، Microsoft Sentinel، QRadar، CrowdStrike، SentinelOne، Microsoft Defender، أو Cortex XDR.
- معرفة قوية بأنظمة Windows وLinux التشغيلية، وكذلك مبادئ الشبكات.
- إتقان لغات البرمجة النصية مثل PowerShell، Python، أو Bash.
- فهم قوي لإطار MITRE ATT&CK وتقنيات الهجوم الشائعة.
- الجنسية السعودية مطلوبة لهذه الوظيفة.
الخبرة المفضلة
- خبرة في التحقيق في أنواع حوادث محددة بما في ذلك ransomware، التصيد الاحتيالي، سرقة بيانات الاعتماد، واختراق نقاط النهاية.
بيئة العمل والتعويض
هذه وظيفة بدوام كامل مقرها الرياض، المملكة العربية السعودية. يتم تنظيم التعويض لهذه الوظيفة على نموذج قائم على الأداء. نحن نبحث عن محترف مDedicated يعمل على التحقيق في التهديدات الأمنية ومنعها للانضمام إلى فريقنا.