About Fortinet
Fortinet is dedicated to enabling a trusted digital world by protecting people, devices, and data globally. The company's Fortinet Security Fabric platform provides broad, integrated, and automated protections across the entire digital attack surface, securing critical assets from the data center to the cloud and home office. Fortinet serves over 615,000 customers, including the world’s largest enterprises, service providers, and government organizations. The Fortinet NSE Training Institute also offers extensive cybersecurity training and career opportunities.
Role Overview
Fortinet is seeking a Lead Consultant – FortiGuard Incident Response to join its team in Saudi Arabia. This full-time position reports to the Director of Operations for FortiGuard Security Consulting Services. The consultant will lead and manage incident response engagements, mentor junior security consultants, and contribute to threat research. The role requires a deep understanding of threat actor tactics, techniques, procedures, and tools, as well as proficiency with FortiEDR tooling to provide rapid situational awareness and guidance to clients and team members.
Key Responsibilities
- Lead incident response engagements and provide mentoring and training to junior analysts.
- Serve as the primary client contact during investigations, delivering clear technical and executive-level updates.
- Drive continuous process improvement for customer-facing incident response services.
- Conduct host-based analysis and forensic functions across Windows, Linux, and Mac OS X systems.
- Review firewall, web, database, and other log sources to identify evidence of malicious activity.
- Utilize the FortiEDR Platform to conduct investigations for rapid detection and analysis of security threats.
- Perform memory forensics and file analysis as required.
- Contribute to threat intelligence consumption and generation within the FortiGuard threat intelligence ecosystem.
- Perform basic reverse engineering of malicious tools used by threat actors.
- Develop comprehensive and informative reports and presentations for both executive and technical audiences.
- Maintain availability during nights and weekends as needed for incident response engagements.
Required Qualifications and Experience
- 5-10 years of experience in incident response and forensics.
- Strong knowledge in malware hunting and analysis, reverse engineering, multiple scripting languages, forensics, and threat actors’ TTPs.
- Demonstrated ability to work under tight timelines.
Required Skills
- Strong consulting skills for client-facing engagements.
- Deep technical skills in cybersecurity and incident response.
- Proficiency in leveraging FortiEDR tooling.
- Ability to quickly glean situational awareness from complex security incidents.
Work Environment
This role involves working directly with a world-class incident response and forensics team. It is a hands-on, customer-facing position requiring direct interaction with clients. The successful candidate will contribute to a dynamic environment focused on security consulting services.
نبذة عن Fortinet
تكرّس شركة Fortinet جهودها لتمكين عالم رقمي موثوق به من خلال حماية الأفراد والأجهزة والبيانات على مستوى العالم. توفر منصة Fortinet Security Fabric الخاصة بالشركة حمايات واسعة ومكتملة وآلية عبر كامل سطح الهجوم الرقمي، مما يضمن تأمين الأصول الحيوية من مركز البيانات إلى السحابة والمكتب المنزلي. تخدم Fortinet أكثر من 615,000 عميل، بما في ذلك أكبر المؤسسات ومزودي الخدمات والمؤسسات الحكومية في العالم. كما يقدم معهد التدريب Fortinet NSE تدريباً شاملاً في مجال الأمن السيبراني وفرصاً مهنية واسعة.
نظرة عامة على الدور الوظيفي
تبحث Fortinet عن استشاري رئيسي – الاستجابة للحوادث في FortiGuard للانضمام إلى فريقها في المملكة العربية السعودية. يتبع هذا المنصب الكامل لمدير العمليات لخدمات FortiGuard الاستشارية الأمنية. سيقود الاستشاري مهام الاستجابة للحوادث ويديرها، ويوجه استشاريي الأمن المبتدئين، ويسهم في أبحاث التهديدات. يتطلب الدور فهماً عميقاً لتكتيكات وأساليب وإجراءات وأدوات الجهات التهديدية، بالإضافة إلى الإتقان في استخدام أدوات FortiEDR لتوفير وعي سريع بالظروف وتوجيه للعملاء وأعضاء الفريق.
المسؤوليات الرئيسية
- قيادة مهام الاستجابة للحوادث وتوفير التوجيه والتدريب للمحللين المبتدئين.
- العمل كجهة الاتصال الرئيسية للعميل أثناء التحقيقات، وتقديم تحديثات واضحة على المستويين التقني والتنفيذي.
- دفع التحسين المستمر للعمليات لخدمات الاستجابة للحوادث الموجهة للعملاء.
- إجراء التحليلات القائمة على المضيف والوظائف الجنائية الرقمية عبر أنظمة التشغيل Windows وLinux وMac OS X.
- مراجعة جدران الحماية والويب وقواعد البيانات ومصادر السجلات الأخرى لتحديد أدلة النشاط الخبيث.
- استخدام منصة FortiEDR لإجراء التحقيقات للكشف السريع عن التهديدات الأمنية وتحليلها.
- إجراء التحقيق الجنائي الرقمي للذاكرة وتحليل الملفات حسب الحاجة.
- المساهمة في استهلاك وتوليد معلومات التهديدات ضمن منظومة معلومات التهديدات FortiGuard.
- إجراء الهندسة العكسية الأساسية للأدوات الخبيثة التي تستخدمها الجهات التهديدية.
- إعداد تقارير وعروض تقديمية شاملة ومفيدة لكل من الجمهور التنفيذي والتقني.
- الحفاظ على الجاهزية والتوفر خلال الليالي وعطلات نهاية الأسبوع حسب الحاجة لمهام الاستجابة للحوادث.
المؤهلات والخبرات المطلوبة
- خبرة من 5 إلى 10 سنوات في مجال الاستجابة للحوادث والتحقيق الجنائي الرقمي.
- معرفة قوية بصيد البرمجيات الخبيثة وتحليلها، والهندسة العكسية، ولغات البرمجة النصية المتعددة، والتحقيق الجنائي الرقمي، وتكتيكات وأساليب وإجراءات (TTPs) الجهات التهديدية.
- قدرة مثبتة على العمل وفق جداول زمنية ضيقة.
المهارات المطلوبة
- مهارات استشارية قوية للمهام الموجهة للعملاء.
- مهارات تقنية عميقة في الأمن السيبراني والاستجابة للحوادث.
- كفاءة وإتقان في الاستفادة من أدوات FortiEDR.
- القدرة على استخلاص الوعي الموقفي بسرعة من الحوادث الأمنية المعقدة.
بيئة العمل
يتضمن هذا الدور العمل بشكل مباشر مع فريق عالمي المستوى للاستجابة للحوادث والتحقيق الجنائي الرقمي. إنه منصب عملي ومواجه للعملاء يتطلب تفاعلاً مباشراً معهم. سيساهم المرشح الناجح في بيئة ديناميكية تركز على خدمات الاستشارات الأمنية.