
Incident Response Team Lead
- Riyadh
- Permanent
- Full-time
- Lead and manage the incident response team, setting priorities, assigning tasks, and ensuring timely resolution of incidents.
- Provide mentorship, coaching, and skills development for team members.
- Act as the central escalation point of contact for critical and complex incidents.
- Develop and manage incident response metrics, reporting, and performance KPIs.
- Provide executive briefings and updates during major security incidents
- Ensure incident response processes compliance with regulatory frameworks.
- Oversee incident response lifecycle.
- Coordinate technical and business stakeholders during incidents, ensuring clear communication and structured escalation.
- Lead root cause analysis, digital forensics, and threat hunting activities for critical incidents.
- Ensure proper documentation of incidents, including timelines, actions taken, and lessons learned.
- Develop, implement, and maintain incident response playbooks, runbooks, and escalation processes.
- Coordinate and lead tabletop exercises, red team/purple team simulations, and incident readiness drills.
- Collaborate with SOC, threat intelligence, vulnerability management, and IT/OT security teams to enhance detection and response capabilities.
- Bachelor’s degree in computer science, cyber security, or a related field. Master's degree is a plus.
- 3+ years of experience in cybersecurity, with a focus on incident response.
- Proven experience leading incident response teams and managing incidents effectively.
- Relevant certifications such as GCIA, GCIH, GCFA, GNFA, BTL1, OSDA, CDSA, or PSAA. CISSP is a plus.
- Strong expertise in incident response methodologies and frameworks.
- Excellent leadership, communication, and interpersonal skills.
- Ability to think critically and make sound decisions under pressure.
- Comprehensive training and development programs.
- Opportunity for career growth and advancement.
- Friendly and supportive work environment.