
Senior Incident Response Specialist
Job description
Job Description
Help AG is looking for a talented and experienced Senior Incident Response Specialist who will be responsible for identifying, analyzing, containing, investigating, and responding to cybersecurity incidents across the enterprise. The role involves coordinating incident response activities, conducting forensic investigations, analyzing security events, and working closely with internal stakeholders to minimize business impact while enhancing the organization's cyber resilience.
Responsibilities
- Monitor and investigate security alerts generated by SIEM, EDR, IDS/IPS, firewalls, and other security tools.
- Perform cyber incident triage by determining severity, scope, urgency, and business impact.
- Lead technical investigations and coordinate incident response activities across multiple teams.
- Execute containment, eradication, and recovery activities during cyber incidents.
- Perform real-time incident handling, forensic evidence collection, malware analysis, and threat correlation.
- Collect and preserve digital evidence following forensic best practices.
- Analyze host, network, firewall, IDS/IPS, and application logs to identify attack patterns.
- Perform malware analysis and identify Indicators of Compromise (IOCs).
- Investigate compromised systems and recommend remediation measures.
- Maintain complete incident records from detection through closure.
- Prepare incident reports, executive summaries, and post-incident ("After Action") reports.
- Develop technical guidance, incident response playbooks, and standard operating procedures.
- Coordinate with Threat Intelligence teams to validate threats and enrich investigations.
- Monitor external threat intelligence feeds and emerging cyber threats.
- Recommend proactive improvements to security controls based on investigation findings.
- Collaborate with infrastructure, application, SOC, legal, and business teams during incidents.
- Support vendor evaluations and provide technical input into cybersecurity solutions.
- Participate in developing technical specifications, RFPs, and SLAs.
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, Information Technology, Computer Engineering, or a related discipline.
- Minimum 10 years of experience in Cybersecurity, with at least 7 years specializing in Incident Response, Security Operations Center (SOC), or Cyber Defense.
- Proven experience in managing the complete Incident Response lifecycle, including preparation, detection, analysis, containment, eradication, recovery, and post-incident reviews.
- Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, ArcSight, or equivalent for security monitoring, log analysis, and incident investigation.
- Strong expertise in Endpoint Detection and Response (EDR) solutions, including Microsoft Defender for Endpoint, CrowdStrike Falcon, Carbon Black, SentinelOne, or similar technologies.
- Experience conducting digital forensic investigations, evidence collection, malware analysis, and root cause analysis while maintaining forensic integrity and chain of custody.
- Solid understanding of cyber threat intelligence concepts, attacker tactics, techniques, and procedures (TTPs), with practical application of the MITRE ATT&CK Framework.
- Proficiency in analyzing security logs from multiple sources, including operating systems, applications, network devices, cloud platforms, and security appliances to identify Indicators of Compromise (IOCs).
- Working knowledge of scripting and automation using PowerShell, Python, or Bash to support investigations, automate repetitive tasks, and enhance incident response processes.
- Preferred Certifications:Security+, CEH, CISSP, GICSP, CCNA Security, or equivalent (not mandatory but an advantage).
- Strong analytical, problem-solving, and decision-making skills with the ability to perform effectively under pressure during critical cybersecurity incidents.
- Excellent communication, stakeholder management, and report-writing skills, with the ability to prepare technical investigation reports, executive summaries, and post-incident recommendations, while collaborating effectively with cross-functional teams and external vendors.
-
Excellent written and verbal communication skills in English & Arabic.
Benefits
- Career progression and growth through challenging projects and work.
- Employee engagement and wellness campaigns activities throughout the year.
- Excellent learning and development opportunities.
- Inclusive and diverse working environment.
- Flexible working environment.
- Open door policy.
About Us
Help AG, the cybersecurity arm of e&, is the Middle East's trusted cybersecurity partner, enabling governments, enterprises and critical industries to innovate with confidence. Combining strategic consulting, advanced managed security services and deep technology expertise, Help AG helps organisations strengthen cyber resilience, secure AI adoption and build trusted sovereign digital environments. With regional expertise and a customer-first approach, Help AG delivers end-to-end cybersecurity capabilities designed to protect critical operations, manage evolving risks and support secure digital transformation. Through continuous innovation, trusted partnerships and measurable outcomes, Help AG enables organisations to remain resilient, prepared and confident in a complex digital world.