Digital Forensics & Incident Response Specialist
Holding Group · Doha
Posted Aug 20, 2026Source: indeed
View & apply on the employer's site ↗
Original posting on indeed. You apply directly with the employer — we never auto-apply.
Job description
We are seeking a highly skilled **Digital Forensics \& Incident Response (DFIR) Specialist** to join our Cybersecurity team. The successful candidate will be responsible for investigating cybersecurity incidents, conducting digital forensic examinations, identifying the root cause and scope of security breaches, and supporting the organization in containing, eradicating, and recovering from cyber threats.
The role requires a strong technical background in digital forensics, incident response, malware analysis, threat hunting, and cybersecurity investigations, with the ability to work effectively under pressure during high\-severity security incidents.
**Key Responsibilities**
* Conduct **digital forensic investigations** across endpoints, servers, networks, cloud environments, and other digital assets.
* Respond to and investigate cybersecurity incidents, including malware infections, phishing attacks, ransomware, unauthorized access, data breaches, insider threats, and account compromise.
* Perform forensic acquisition, preservation, examination, and analysis of digital evidence while maintaining appropriate **chain\-of\-custody** procedures.
* Analyze Windows, Linux, macOS, mobile, network, and cloud artifacts to determine the nature, scope, timeline, and impact of security incidents.
* Perform **timeline analysis and evidence correlation** to reconstruct attacker activities and identify the root cause of incidents.
* Conduct malware and suspicious\-file analysis to determine malicious behavior, indicators of compromise (IOCs), and potential attack techniques.
* Perform threat hunting and proactively search for indicators of compromise and signs of advanced persistent threats (APTs).
* Analyze security logs, endpoint telemetry, network traffic, authentication records, and SIEM/EDR data to identify malicious activity.
* Develop and maintain **Indicators of Compromise (IOCs), Tactics, Techniques and Procedures (TTPs), and forensic investigation procedures**.
* Support containment, eradication, and recovery activities in coordination with SOC, Infrastructure, Network, Cloud, and IT teams.
* Provide technical support during **high\-severity and critical cybersecurity incidents**.
* Prepare detailed forensic investigation reports documenting findings, evidence, attack timelines, root cause, impact, and recommended remediation.
* Maintain accurate documentation of investigative activities and evidence handling.
* Support legal, regulatory, audit, and compliance requirements related to cybersecurity investigations when required.
* Participate in **incident response exercises, tabletop exercises, simulations, and cyber crisis drills**.
* Continuously improve DFIR processes, playbooks, procedures, and investigation capabilities.
* Evaluate and recommend forensic, incident response, threat intelligence, and security investigation tools.
* Stay current with emerging threats, attack techniques, vulnerabilities, malware families, and digital forensic methodologies.
**Required Qualifications**
* Bachelor’s degree in **Cybersecurity, Digital Forensics, Computer Science, Information Technology, Information Security**, or a related discipline.
* **5\+ years of experience** in digital forensics, incident response, SOC operations, cybersecurity investigations, or a related field.
* Strong practical experience conducting **digital forensic investigations and cybersecurity incident response**.
* Strong knowledge of Windows and Linux operating systems and their forensic artifacts.
* Experience with endpoint, network, memory, disk, and log analysis.
* Strong understanding of **TCP/IP, DNS, HTTP/HTTPS, Active Directory, authentication mechanisms, and enterprise network architecture**.
* Experience with SIEM, EDR/XDR, network monitoring, threat intelligence, and forensic investigation platforms.
* Knowledge of common attack techniques and frameworks such as **MITRE ATT\&CK**.
* Experience investigating malware, phishing, credential compromise, ransomware, privilege escalation, lateral movement, and data exfiltration.
* Strong analytical, investigative, problem\-solving, and report\-writing skills.
* Ability to work effectively during high\-pressure and time\-sensitive security incidents.
Work Location: In person
Is this role a fit for you?
Upload any CV — a short AI chat builds your profile, scores how well you fit roles like this across the Gulf, and tailors an ATS-ready CV to each. Free to start. No job promises — you always apply yourself.
Start free — get matchedSimilar roles
- Digital Marketing Executive
AccorHotel · Doha - Qatar
- Project Manager (Digital Transformation and Strategy) - Banking
VAM Systems · Doha - Qatar
- Senior Manager- Risk Consulting- Digital Risk
Ernst & Young AE · Qatar - Qatar
- Digital Applications Administrator - IBM APP CONNECT: IBM ACE
VAM Systems · Qatar - Qatar
- Digital Marketing Expert, Social Media Marketing Specialist
CARMEL GROUP · Birkath Al Awamer - Qatar
Listing aggregated from indeed. Built for the Gulf. No job or interview promises — we make your search faster and your CV stronger.