Relomote
Remote JobsRelocation Jobs
Add companySaved
Relomote

Relomote is a job board for remote, hybrid, and relocation jobs — every listing AI-classified for the countries it actually hires from, or the visa and relocation support it offers.

LinkedInCrunchbase

Remote jobs by category

  • Remote Engineering & Development jobs
  • Remote Customer Support jobs
  • Remote Design jobs
  • Remote Marketing jobs
  • Remote Sales jobs
  • Remote Product jobs
  • Remote Data & Analytics jobs
  • Remote People & Talent jobs
  • Remote Writing & Content Creation jobs
  • Remote Finance jobs
  • Remote Legal & Compliance jobs
  • Remote Operations & Admin jobs
  • Remote Data Entry jobs
  • Remote Virtual Assistant jobs
  • Remote Education/Training jobs
  • Remote Healthcare/Clinical jobs
  • Remote Other jobs

Remote jobs by location

  • Work from anywhere jobs
  • Remote jobs in Africa
  • Remote jobs in Asia
  • Remote jobs in Europe
  • Remote jobs in Latin America
  • Remote jobs in Middle East
  • Remote jobs in North America
  • Remote jobs in Oceania
  • All remote jobs →

Relocation & visa sponsorship

  • Visa sponsorship jobs
  • Relocation package jobs
  • Relocate to Europe
  • Relocate to Germany
  • Relocate to Netherlands
  • Relocate to Spain
  • Relocate to Portugal
  • Relocate to Greece
  • Relocate to United Kingdom
  • Relocate to Canada
  • Relocate to Australia
  • Relocate to Sweden
  • Relocate to Switzerland
  • Relocate to Japan
  • Relocate to United Arab Emirates
  • All relocation jobs →

© 2026 RelomoteAboutPrivacyTerms

Contact [email protected] · Built by Mahmoud

Relomote
Remote JobsRelocation Jobs
Add companySaved
Globalhub2 Sita logo

Lead Specialist, Incident Response

Globalhub2 Sita
Posted 9 hours ago
🇪🇬Egypt🏠Remote📁Engineering & Development
Is this job info correct?

Overview WELCOME TO SITA At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry. You'll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don't just move the world forward-we're proud to be recognized as a Great Place to Work ® by 79% of our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow. Are you ready to love your job? The adventure begins right here, with you, at SITA. ABOUT THE ROLE & TEAM As the Digital Forensics & Incident Response (DFIR) Lead , you will be responsible for leading SITA's most critical cybersecurity investigations, taking ownership of high-severity incidents from initial detection through containment, eradication, recovery, and post-incident review. You will serve as the Incident Commander during major cyber events and act as the senior technical escalation point for complex investigations, digital forensics activities, and insider threat cases. As a key member of SITA's Enterprise Information Security Office (EISO) and part of the CSIRT Response Team , you will collaborate closely with Security Operations, CSIRT Threat, Cloud & Infrastructure, Product Security, Corporate IT, and customer-facing teams to strengthen SITA's detection, investigation, and incident response capabilities. Your work will help enhance cyber resilience across SITA, its customers, and the broader air transport ecosystem. This role combines deep technical expertise, operational leadership, and strategic influence to continuously improve incident response maturity, forensic readiness, investigative capabilities, and security operations effectiveness across the organization. WHAT YOU WILL DO Incident Response & Coordination Lead the response to high-severity and business-critical cybersecurity incidents across the full incident response lifecycle, including detection, containment, eradication, recovery, and post-incident improvement. Serve as Incident Commander, directing cross-functional response teams and coordinating activities across SOC, CSIRT Threat, Corporate IT, Cloud & Infrastructure, Product Engineering, Legal, Compliance, and Business stakeholders. Drive rapid decision-making during active incidents, ensuring effective communication, stakeholder alignment, and business impact mitigation. Deliver comprehensive incident reports, executive-level briefings, and post-incident reviews with clear recommendations and remediation plans. Develop, maintain, and continuously improve incident response process, playbooks, runbooks, and response procedures based on emerging threats and lessons learned. Lead tabletop exercises, simulations, and cyber crisis response activities to enhance organizational preparedness. Digital Forensics & Evidence Handling Conduct forensically sound acquisition, preservation, analysis, and reporting of evidence across endpoints, servers, cloud environments, networks, SaaS platforms, and enterprise applications. Ensure evidence handling, chain-of-custody processes, and investigative documentation meet legal, regulatory, and industry best-practice standards. Reconstruct attacker timelines, determine root cause, assess impact, and map adversary behaviours to the MITRE ATT&CK framework. Perform advanced investigations involving malware, ransomware, data exfiltration, account compromise, insider activity, and sophisticated persistent threats. Insider Threat & Risk Lead investigations involving insider threats, including unauthorized access, misuse of privileged accounts, intellectual property theft, data loss, fraud, and policy violations. Partner with HR, Legal, Compliance, and Regulatory teams to support sensitive investigations through forensic analysis, technical expertise, and defensible evidence collection. Assess insider threat risks and recommend preventive, detective, and corrective controls to strengthen organizational security posture. Contribute to the development of insider threat monitoring capabilities, governance frameworks, and risk mitigation strategies. Tooling, Automation & Telemetry Design and implement automation, scripts, and workflows to accelerate evidence collection, enrichment, triage, forensic analysis, and incident response activities. Leverage AI-driven analytics, machine learning, and automation capabilities to enhance threat detection, investigative efficiency, and response effectiveness across security platforms. Partner with platform owners and engineering teams to improve security telemetry, logging coverage, retention, and forensic visibility across on-premises, cloud, and hybrid environments. Qualifications ABOUT YOUR SKILLS Proven experience leading digital forensics and incident response investigations in large, complex enterprise environments, ideally within critical infrastructure, transportation, aviation, or other regulated industries. Strong hands-on experience with EDR/XDR, SIEM, SOAR, and forensic investigation tools, with the ability to lead complex investigations from initial detection through remediation. Experience conducting forensically sound evidence collection and analysis across endpoints, servers, cloud platforms, networks, identity systems, and SaaS environments. Proficiency in Python and/or PowerShell scripting and automation, with working knowledge of KQL and security analytics. Strong understanding of cyber adversary tactics, techniques, and procedures (TTPs), including practical application of the MITRE ATT&CK framework. Excellent analytical, communication, and stakeholder management skills, with the ability to lead teams and provide clear briefings to both technical and executive audiences. Nice-to-Have: Relevant Certifications such as GCFA, GNFA, GCIH, GREM, GCFE, CISSP, or OSCP. Experience leading cloud forensic and incident response investigations across Azure, AWS, and/or Google Cloud Platform (GCP). Experience with forensic frameworks and tools such as FTK, EnCase, Velociraptor, KAPE, Autopsy, or Volatility. Familiarity with regulatory, legal, and compliance requirements related to digital investigations, evidence handling, and incident reporting. Experience supporting cybersecurity operations within aviation, airport, transportation, operational technology (OT), or critical infrastructure environments. Experience leveraging automation, orchestration, and AI-enabled capabilities to enhance incident response and forensic investigation effectiveness. WHAT WE OFFER We're all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We're really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever. 🏡 Flex Week: Work from home up to 2 days/week (depending on your team's needs) ⏰ Flex Day: Make your workday suit your life and plans. 🌎 Flex-Location: Take up to 30 days a year to work from any location in the world. 🌿 Employee Wellbeing: We have got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs. 🚀 Professional Development: At SITA, we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning, Microsoft's Enterprise Skills Initiative, and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling, Harvard Business Publishing for people leadership, Stanford for strategic development and many others, we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way. 🙌 Competitive Benefits: Competitive benefits that make sense with both your local market and employment status. SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process. Starting Compensation Starting Compensation Compensation Note Hidden (-999)

Similar jobs

Similar jobs

Globalhub2 Sita logo

Senior Specialist, Incident Response

Globalhub2 Sita

🇪🇬Egypt9 hours ago
SL

Dynamics 365 Finance And Operations Developer

Systems Limited - Egypt

🇪🇬Egypt7 hours ago
PA

Quality Assurance & Training Specialist

Paymob

🇪🇬Egypt7 hours ago
Grow With Fusion logo

Real Estate Transaction Coordinator

Grow With Fusion

🌍Brazil, Egypt, Philippines6 hours ago
Detroit Data Company logo

Junior Data Developer

Detroit Data Company

🌍Egypt, Kenya, Nigeria7 hours ago
KH

Family Physician

Kyrios HCP Insights Community

🌍Egypt, Spain7 hours ago