Cybersecurity Incident Réponse Specialist
Exequt · Riyadh, Riyadh Region, Saudi Arabia
IT Services and IT Consulting · 11-50 employees
About the role
The specialist will investigate, contain, and remediate security incidents across various environments including cloud, network, and endpoints. They are also responsible for developing incident response playbooks and conducting threat hunting to improve organizational security posture.
What they look for
Requirements
Candidates must have strong experience in incident response, DFIR, and threat hunting, along with proficiency in SIEM/EDR platforms and scripting languages. The role specifically requires Saudi nationality.
Benefits
Full description
About ExeQut
ExeQut is a fast-growing consulting and technology services firm specializing in cybersecurity, IAM, cloud, AI-driven platforms, and custom software engineering. We partner with public and private sector organizations to deliver high-impact digital transformation initiatives across the Kingdom of Saudi Arabia.
Position Summary
ExeQut is hiring a Cybersecurity Incident Response Specialist to investigate, contain, eradicate, and recover from security incidents across endpoints, networks, identities, cloud, and applications — helping clients respond to and learn from real-world threats.
What You Will Do
- Investigate and respond to cybersecurity incidents including ransomware, malware, phishing, account compromise, data theft, and lateral movement
- Perform incident triage, investigation, containment, eradication, and recovery
- Conduct threat hunting and root-cause analysis
- Perform basic digital forensics and malware analysis
- Identify and analyze IOCs/IOAs and map attacks to MITRE ATT&CK
- Investigate Windows, Linux, Active Directory, and cloud environments
- Work with SIEM and EDR/XDR platforms to investigate security events
- Develop and improve incident response playbooks and detection rules
- Prepare detailed incident reports, timelines, and remediation recommendations
- Support SOC/CSIRT operations and critical incident response
Required Qualifications
- Strong experience in Incident Response / DFIR / SOC / Threat Hunting
- Hands-on experience with Splunk, Microsoft Sentinel, QRadar, CrowdStrike, SentinelOne, Microsoft Defender, or Cortex XDR
- Strong Windows/Linux and networking knowledge
- Knowledge of PowerShell, Python, or Bash
- Strong understanding of MITRE ATT&CK and common attack techniques
- Saudi Nationality required
Preferred Qualifications
- Experience investigating ransomware, phishing, credential theft, and endpoint compromise
What We Offer
- Performance-based compensation structure
- Bupa medical insurance (Golden Tier)
- Ongoing training and mentorship from experienced leadership
- Exposure to high-impact projects with leading clients in Saudi Arabia
- A collaborative, growth-oriented culture
If you're a hands-on incident response specialist who thrives on investigating and neutralizing real security threats, we'd love to have you on board — let's build something great together!