Lead Consultant - Incident Response

🏢 CPX Affiliate
📍 Abu Dhabi, United Arab EmiratesFull-timeHybrid
📅 Posted: 2w ago🔄 Updated: 2w ago
CV%
✨ AI Summary
The Lead Consultant - Incident Response is a senior role requiring extensive experience in cyber security blue team operations and incident response. Responsibilities include leading active incident response engagements, executing threat hunting activities, performing host and network-based forensics across multiple operating systems, and contributing to process improvement. The role demands strong technical expertise in various security domains, excellent reporting and communication skills, and the ability to work independently and collaboratively. A GIAC certification is a must, with desirable experience in EDR, threat hunting, network forensics, and cloud security.
Required Skills
Other
analysis of system and network devices logsblue team operationsnetwork forensicscurrent threats vulnerabilities and attack trendsMicrosoft Windowsstatic and dynamic malware analysisEDR tools
Information Technology
Threat HuntingIT Infrastructure
Requirements
Requires a minimum of 6 years of experience in incident response and related cyber security operations. Must have strong technical skills in blue team operations, threat hunting, network protocols, operating systems (Windows, Linux, OSX), digital forensics, log analysis, malware analysis, enterprise systems, targeted attacks, and the ATT&CK framework. GIAC certification is required. Experience with EDR tools, threat-hunting tools, and network forensics is desirable, as is knowledge of cloud security infrastructure.
Description
OverviewAs a Principal Consultant – Incident Response, you live and breathe blue team operations. Your technical expertise in endpoint and network threat detection and defence is complemented by your integrity and passion for cyber security and technology in general. You work well in a team of highly motivated and skilled blue teamers, but you can also achieve your work independently in different engagements and scenarios. You enjoy taking on new challenges in a fast paced and dynamic working environment. You are a team player who is always willing to help out where required, with a humble and positive attitudeResponsibilitiesServe as technical lead on active incident response engagements and across different IR Retainer customersAchieve tasks independently within the team after initial 2-3 monthsExecute threat hunting activities in support of incident response and proactive environment assessmentsCarry out host-based assessments using EDR tools and network assessments utilizing full packet data to determine the extent and scope of possible compromisePerform host and/or network-based forensics across Windows, Mac, and Linux platforms.Execute digital forensic investigations supporting cyber incident response engagementsContribute to process documentation and continuous service improvement activitiesCollaboration with customers to enhance defensive security posture and existing security controlsFlexible schedule that is open to changing situations and opportunitiesProduce detailed reports and technical briefs, effectively communicate tasks, methodology and guidance to customersExplain technical findings in a manner that can be easily understood by technical and non-technical staffDemonstrate industry thought leadership through blog posts, internal brown-bag sessionsYou must be a team player, with a humble and approachable nature who is willing to go the extra mileQualificationsTechnical Skills:Strong understanding of blue team operations and threat huntingSound understanding of network protocols, TCP/IP, etc.Sound understanding of Microsoft WindowsSound understanding of Linux and OSXSound forensic skills across multiple operating systemsStrong understanding of network analysis tools like Bro/Zeek, Rita, or SuricataAbility to perform analysis of system and network devices logsSound understanding of the capabilities of static and dynamic malware analysisSound understanding of enterprise systems, technologies, and infrastructureStrong understanding of targeted attacks and ability to create customized tactical and strategic remediation plans for compromised organizationsStrong understanding of current threats, vulnerabilities, and attack trendsStrong understanding of the ATT&CK frameworkExcellent organizational skills, ability to prioritize, and ability to work independentlyAny other responsibilities as required by the Line ManagerSkills/Certifications (Technical & Non-Technical)Good attention to detail and reporting accuracyEnglish language skills, both spoken and writtenGIAC Certified in a minimum of one discipline: GNFA, GCIH, GCIA, GCFE, GCFA, GDAT, etc. Or equivalent (eLearn Security, etc.)Previous experience working with EDR tools and threat-hunting toolsPrevious experience performing network forensics is desirableKnowledge about cloud security infrastructure (AWS, Azure, Oracle, others) is desirableExcellent organizational skills, ability to prioritize, and ability to work independentlyMinimum Work Experience - 6 yearsEducation - Bachelor's degree in Computer Science or Engineering is desirable but not mandatory
✨ Premium Match Details
Deep-dive CV analysis, customized Cover Letters, and Interview prep!
📊 Match Analysis
Insights against your active CV
📊
Personalized Match Analysis
Upload your CV to see exact matching percentages, detailed skills mapping, and gap analysis for this role.
🎯 Overalli74%
⚡ Skillsi85%
View Breakdown
Ontology Match: 85.0
Matched:✓ Requirements Matching✓ Ontology Skills Mapping
📜 Eligibilityi49%
View Breakdown
Local: 19600%
🏗️ Career Fiti91%
View Breakdown
Seniority: 91.0
📋 Requirementsi67%
View Breakdown
Domain: 67.0
🔥 Motivationi78%
View Breakdown
Title Fit: 78.00