Description
The incident response analyst is responsible for investigating, containing, eradicating, and supporting the recovery of cybersecurity incidents across customer and enterprise environments. The role plays a critical part in minimizing business impact from cyber threats by coordinating response activities, performing technical investigations, and supporting the continuous improvement of incident response capabilities.
The role collaborates closely with security operations, threat intelligence, digital forensics, and customer IT teams to identify attack vectors, contain threats, and strengthen organizational resilience against future incidents.
Responsibilities
Incident investigation & response
- Respond to security incidents within defined SLAs and escalation procedures.
- Perform detailed investigations to determine nature of the attack, scope of compromise, impacted systems, attack vectors, and potential business impact.
- Analyze indicators of compromise (IOCs) and attacker activity.
- Identify containment, eradication, and recovery actions required to mitigate incidents.
- Coordinate incident response activities with internal and customer stakeholders.
Threat analysis & root cause investigation
- Conduct in-depth analysis of security incidents and suspicious activities.
- Identify vulnerabilities, attack techniques, and security gaps contributing to incidents.
- Perform root cause analysis to determine how incidents occurred and identify preventive controls.
- Analyze attacker tactics, techniques, and procedures (TTPs) using industry frameworks such as MITRE ATT&CK.
Incident coordination & escalation
- Manage incident response activities across multiple technical teams.
- Escalate incidents requiring digital forensics support, specialized technical expertise, and malware analysis.
- Coordinate communication between technical teams, management, and customer stakeholders.
- Support crisis management activities during major incidents.
Documentation & reporting
- Prepare detailed incident reports documenting findings, impact assessments, root cause analysis, and remediation recommendations.
- Maintain investigation records and evidence documentation.
- Support development of executive-level incident summaries and post-incident reviews.
Process improvement & readiness
- Support the development and enhancement of incident response playbooks, response procedures, and investigation methodologies.
- Participate in tabletop exercises and incident simulations.
- Identify opportunities to improve response effectiveness and operational readiness.
Our culture & code of conduct
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behaviour across everything we do - from how we work with each other to how we engage with clients and partners globally.
Requirements
- Bachelor's degree or intermediate diploma (minimum) from a recognised institution.
- Minimum 3 years experience in cybersecurity / information security, including 1 or more years in incident response.
- At least one valid NCSC-approved IR certification like ECIH, CCIM, Blue Team Level 2, or another equivalent certification in the same field that is approved by the NCSC.
- Practical skills in log analysis, endpoint and network investigation, malware triage, and use of IR tooling.
- Exposure to SIEM/SOAR and EDR platforms is preferable.
- Experience in an MSSP or SOC environment is preferable.
الوصف
المحلل المختص باستجابة الحوادث مسؤول عن التحقيق والاحتواء والتخلص ودعم استعادة الأمن السيبراني للحوادث عبر بيئات العملاء والمؤسسات. يلعب الدور دوراً حيوياً في تقليل تأثير الأعمال من التهديدات السيبرانية من خلال تنسيق أنشطة الاستجابة، إجراء التحقيقات التقنية، ودعم التحسين المستمر لقدرات الاستجابة للحوادث.
يت collaborations مع فرق عمليات الأمن، واستخبارات التهديدات، والعلوم الجنائية الرقمية، وفِرق تكنولوجيا المعلومات لدى العملاء لتحديد مسارات الهجوم، احتواء التهديدات، وتقوية المرونة التنظيمية ضد الحوادث المستقبلية.
المسؤوليات
التحقيق في الحوادث والاستجابة لها
- الاستجابة للحوادث الأمنية ضمن اتفاقيات مستوى خدمة محددة وإجراءات التصعيد.
- إجراء تحقيقات تفصيلية لتحديد طبيعة الهجوم ونطاق الاختراق والأنظمة المتأثرة ومسارات الهجوم والتأثير التجاري المحتمل.
- تحليل مؤشرات الاختراق ونشاط المهاجم.
- تحديد إجراءات الاحتواء والتخلص والتعافي اللازمة للتخفيف من الحوادث.
- تنسيق أنشطة استجابة الحوادث مع أصحاب المصلحة الداخليين والعملاء.
تحليل التهديدات والتحقيق في الأسباب الجذرية
- إجراء تحليل عميق لحوادث الأمن والأنشطة المشبوهة.
- تحديد الثغرات والتقنيات الهجومية والفجوات الأمنية التي تسهم في الحوادث.
- إجراء تحليل السبب الجذري لتحديد كيفية حدوث الحوادث وتحديد الضوابط الوقائية.
- تحليل أساليب وتقنيات وإجراءات المهاجمين (TTPs) باستخدام أطر صناعية مثل MITRE ATT&CK.
التنسيق والتصعيد في الحوادث
- إدارة أنشطة استجابة الحوادث عبر فرق تقنية متعددة.
- تصعيد الحوادث التي تتطلب دعم التحريات الرقمية، والخبرة الفنية المتخصصة، وتحليل البرمجيات الخبيثة.
- تنسيق الاتصال بين الفرق التقنية والإدارة وأصحاب المصلحة من العملاء.
- دعم إجراءات إدارة الأزمات خلال الحوادث الكبرى.
التوثيق والتقارير
- إعداد تقارير تفصيلية للحوادث توثق النتائج وتقييمات التأثير وتحليل الأسباب الجذرية وتوصيات التصحيح.
- الحفاظ على سجلات التحقيق ووثائق الأدلة.
- دعم تطوير ملخصات الحوادث على مستوى الإدارة ومراجعات ما بعد الحوادث.
تحسين العملية والتأهب
- دعم تطوير وتحديث دفاتر استجابة الحوادث وإجراءات الاستجابة ومنهجيات التحقيق.
- المشاركة في تمارين الطاولة ومحاكاة الحوادث.
- تحديد فرص تحسين فاعلية الاستجابة وجاهزية التشغيل.
ثقافتنا ومدونة السلوك
في ZainTECH، نفخر بثقافة قائمة على التعاون والابتكار والنزاهة غير القابلة للتنازل. نبحث عن أفراد يشاركوننا هذه القيم ويرغبون في التركيز على العمل مع العملاء والتميز الأخلاقي. من المتوقع أن يلتزم جميع الموظفين بمدونة السلوك لدينا، التي تعمل كإطار توجيهي للسلوك المسؤول في كل ما نقوم به - من كيفية العمل مع بعضنا البعض إلى كيف نتفاعل مع العملاء والشركاء عالميًا.
المتطلبات
- درجة البكالوريوس أو الدبلوم المتوسط (على الأقل) من مؤسسة معترف بها.
- خبرة لا تقل عن 3 سنوات في الأمن السيبراني / أمن المعلومات، بما في ذلك سنة واحدة أو أكثر في استجابة الحوادث.
- على الأقل شهادة IR معتمدة من NCSC مثل ECIH، CCIM، Blue Team Level 2، أو شهادة مكافئة أخرى في نفس المجال معتمدة من NCSC.
- مهارات عملية في تحليل السجلات، والتحقيق في نقاط النهاية والشبكة، وفرز البرمجيات الخبيثة، واستخدام أدوات IR.
- يفضَّل وجود خبرة في منصات SIEM/SOAR وEDR.
- يفضَّل وجود خبرة في بيئة MSSP أو SOC.