Security Engineer (DFIR Lab)
by G42 in Cybersecurity
The Security Engineer (DFIR Lab) role at CPX in Abu Dhabi is responsible for managing, maintaining, and securing the Digital Forensics and Incident Response (DFIR) Lab infrastructure, including hardware, software, processes, and documentation. The role ensures optimal availability, performance, security, privacy, and data integrity of the DFIR Lab environment to support forensic investigations and cyber incident response engagements. Responsibilities include deploying, configuring, and maintaining forensic and incident response tools such as EnCase, Magnet Axiom, FTK, FTK Imager, Cellebrite, THOR, Velociraptor, KAPE, IDA Pro, and Security Onion, as well as configuring forensic workstations, laptops, war laptops, servers, and storage systems. The role manages lab asset inventories, licensing, renewals, budgeting contributions, access controls, logging, audit trails, and monitoring solutions. It involves developing scripts or automation to streamline DFIR workflows, maintaining SOPs, documenting forensic processes and lab configurations, collaborating with customers during assessments and incident response engagements, and executing lab tasks in support of DFIR operations. The position requires strong experience with Linux systems, networking devices, virtualization using VMware ESXi, storage technologies, cloud-based environments, evidence handling, forensic hardware such as write blockers and specialized cables, and familiarity with security monitoring, EDR, NDR, intrusion detection, and log management within a secure technical lab environment.