JD -Incident Response Specialist - Qatar
Experience Level: 8–10 Years
Role Overview
We are seeking an experienced L3 Incident Response (IR) professional with strong expertise in Microsoft Sentinel, Cloud Security, and Web Application attack remediation to join our cybersecurity team. The ideal candidate will lead detection, investigation, and response activities for complex security incidents, ensuring rapid containment and remediation of threats across multi-cloud and enterprise environments.
Key Responsibilities
- Lead end-to-end response to cybersecurity incidents, including triage, containment, eradication, recovery, root cause analysis, and post-incident reviews.
- Investigate and remediate Cloud Security incidents (e.g., compromised IAM roles, unauthorized resource creation, cloud storage misconfigurations, and container escapes).
- Respond to and mitigate complex Web Application attacks (e.g., OWASP Top 10, API abuse, injection flaws, and web shell deployments) in coordination with application and DevOps teams.
- Conduct threat hunting and forensic investigations across endpoints, networks, identity systems, and multi-cloud platforms (Azure, AWS, GCP).
- Design, develop, and optimize detection rules, analytics, and automated response playbooks in Microsoft Sentinel and cloud-native security tools (e.g., Microsoft Defender for Cloud).
- Analyze and correlate security events across SIEM, EDR, cloud audit logs (e.g., AWS CloudTrail, Azure Activity Logs), and network telemetry.
- Develop automation solutions using KQL, PowerShell, Python, and SOAR technologies to improve detection and response efficiency.
- Coordinate major incident investigations and collaborate with SOC, Threat Intelligence, Vulnerability Management, Engineering, customers, and other stakeholders.
- Prepare incident reports, executive summaries, forensic findings, and remediation recommendations, while delivering executive-level briefings.
- Ensure compliance with security policies, regulatory requirements, and evidence preservation standards.
Required Skills & Qualifications
- Experience: 8–10 years in cybersecurity, with at least 3–4 years dedicated to Incident Response.
- Cloud Security & Forensics Expertise: Deep hands-on knowledge of cloud architectures (Azure, AWS, GCP), identity and access management (IAM) structures, API activity logging, and Cloud Incident Response/Forensics (e.g., tracing cloud trails and container runtimes).
- Microsoft Sentinel Expertise: Hands-on experience in configuring, tuning, and managing Sentinel, including advanced KQL queries and playbook development.
- Web Application Security Expertise: Deep understanding of web application vulnerabilities, HTTP traffic analysis, WAF logs, and techniques used to compromise web apps and APIs.
- Core Tooling: Strong knowledge of SIEM, SOAR, EDR, and cloud security posture management (CSPM).
- Frameworks & Methodologies: Familiarity with the MITRE ATT&CK and MITRE ATT&CK for Cloud frameworks and threat-hunting methodologies.
- Scripting: Proficiency in PowerShell, Python, and KQL for analysis and automation.
- Communication: Excellent analytical, problem-solving, and cross-functional communication skills.
- Preferred Certifications:
- Offensive/Practical Security: OSCP (OffSec Certified Professional) or equivalent offensive security credentials.
- Incident Response/Cloud/Forensics: GCFA, GCIH, CCSP, AWS/Azure Security Engineer Associate/Expert, or Microsoft Certified: Security Operations Analyst.
Nice-to-Have
- DevSecOps Integration: Experience working closely with developers to secure CI/CD pipelines and infrastructure-as-code (IaC).
- Threat Intelligence & Malware Analysis: Exposure to reverse engineering or deeper artifact analysis for cloud-based malware.
- Compliance Knowledge: Familiarity with NIST CSF, NIST 800-61, CIS Controls, ISO 27001, and PCI-DSS.