Incident Response Lead (DFIR), UAE
DeepSource Technologies
Dubai
The Role
This Dubai-based position centres on leading cybersecurity incident response activities across enterprise environments, covering triage, containment, eradication, and recovery. Day-to-day work includes conducting digital forensic investigations, performing root cause analysis, coordinating with SOC and IT teams, developing response playbooks, and supporting threat hunting initiatives.
Skills & Experience
Candidates need five to seven years in cybersecurity with strong hands-on DFIR expertise, including malware, ransomware, and phishing investigation. Proficiency with SIEM, EDR, and security monitoring tools is essential, alongside solid knowledge of Windows, Linux, and networking. Relevant certifications include GCFA, GCIH, GCFE, CHFI, CEH, CySA+, or Security+. Cloud IR experience and scripting skills in Python or PowerShell are advantageous.
Who It Suits
This role suits a seasoned DFIR professional who thrives under pressure, communicates clearly with both technical and business stakeholders, and takes ownership of complex investigations from detection through to remediation. Those with an appetite for continuous improvement and threat hunting will find the position particularly rewarding.





