Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

SITA

Senior Specialist, Incident Response

Career Insights for Incident Analyst / Responder

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Illinois data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

An Incident Analyst or Responder investigates an IT-related incident: an unplanned interruption to a service, a reduction in the quality of a service, or an event that has not yet impacted the service to the customer. Works to restore a normal service operation as quickly as possible and to minimize the impact on business operations.

$121,929 / year median in Illinois

+10% projected growth

Explore Career

Job Description

Senior Specialist, Incident Response SITA • Cairo •
PERMANENT
Updated 08/27/2026 Job Description Job Summary Overview
WELCOME TO SITA
At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry. Youll find us in 95 of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We dont just move the world forward-were proud to be recognized as a Great Place to Work® by 79 of our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow. Are you ready to love your job? The adventure begins right here, with you, at
SITA. ABOUT THE ROLE & TEAM
As a Digital Forensics & Incident Response (DFIR) Specialist, you will play a key role in investigating cybersecurity incidents, performing digital forensic analysis, and supporting the containment and remediation of security threats across SITAs global environment. You will work closely with Security Operations, CSIRT Threat, Cloud & Infrastructure, Product Security, and Corporate IT teams to respond to threats, preserve evidence, and determine the root cause and impact of security incidents. As part of SITAs Enterprise Information Security Office (EISO) and CSIRT Response Team, you will help strengthen the organizations incident response capabilities, forensic readiness, and cyber resilience while supporting the protection of SITA, its customers, and the broader air transport ecosystem. This role is ideal for a proactive hands-on security professional with strong investigation and analytical skills who is passionate about incident response, digital forensics, and continuous improvement.
KEY RESPONSIBILITIES
Incident Response & Coordination Investigate security incidents across the full incident response lifecycle, including analysis, containment, eradication, recovery, and post-incident activities. Support the coordination of incident response activities with
SOC, CSIRT
Threat, Corporate IT, Cloud & Infrastructure, Product Engineering, and other stakeholders. Contribute to incident reports, technical findings, lessons learned, and remediation recommendations. Assist in maintaining and improving incident response processes, playbooks, and operational procedures. Digital Forensics & Evidence Handling Conduct forensic acquisition, preservation, analysis, and reporting of evidence from endpoints, servers, cloud environments, networks, and SaaS platforms. Maintain accurate documentation and evidence handling procedures in accordance with legal, regulatory, and industry best practices. Analyse artifacts to identify attacker activity, determine root cause, and assess business impact. Support investigations involving malware, ransomware, account compromise, data exfiltration, and unauthorized access. Insider Threat & Risk Assist with investigations involving insider threats, policy violations, misuse of privileged access, and potential data loss events. Support Legal, Compliance, HR, and other stakeholders by providing technical evidence and investigative findings. Help identify control improvements to reduce insider threat risks and strengthen overall security posture. Tooling, Automation & Telemetry Develop and maintain scripts and automation to support evidence collection, analysis, and incident response workflows. Utilize AI-driven capabilities and security analytics to improve investigative efficiency and response outcomes. Work with platform owners to improve logging, telemetry visibility, and forensic readiness across enterprise environments. Contribute to the ongoing enhancement of DFIR capabilities, tooling, and operational processes. Qualifications
ABOUT YOUR SKILLS
Experience in digital forensics, incident response, or cyber investigations within enterprise environments. Hands-on experience with EDR/XDR, SIEM, forensic investigation, and security monitoring tools. Experience analysing security incidents across endpoints, servers, cloud environments, networks, and identity platforms. Proficiency in Python and/or PowerShell, with working knowledge of KQL or similar query languages. Understanding of cyber threat actor tactics, techniques, and procedures (TTPs) and the
MITRE ATT&CK
framework. Strong analytical, problem-solving, and communication skills, with the ability to clearly document and present technical findings.
Nice-to-Have:
Relevant Certifications such as GCFA, GNFA, GCIH, GREM, GCFE, CISSP, or OSCP. Experience with cloud security and DFIR investigations across Azure, AWS, and/or GCP environments. Experience with forensic frameworks and tools such as FTK, EnCase, Velociraptor, KAPE, Autopsy, or Volatility. Experience working in aviation, transportation, critical infrastructure, or operational technology (OT) environments. Knowledge of security automation, orchestration, and AI-assisted investigation techniques to improve response efficiency.
WHAT WE OFFER
Were all about diversity. We operate in 200 countries and speak 60 different languages and cultures. Were really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what its like to join our team and take a step closer to your best life ever. 🏡
Flex Week:
Work from home up to 2 days/week (depending on your teams needs) ⏰
Flex Day:
Make your workday suit your life and plans. 🌎
Flex-Location:
Take up to 30 days a year to work from any location in the world. 🌿
Employee Wellbeing:
We have got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health - a personalized platform that supports a range of wellbeing needs. 🚀
Professional Development:
At SITA, we believe growth fuels innovation. Our learning ecosystem offers access to world-class platforms and programs designed to help you thrive. From LinkedIn Learning, Microsofts Enterprise Skills Initiative, and Airport Council International -available to all employees-to specialized solutions like Pluralsight for technology upskilling, Harvard Business Publishing for people leadership, Stanford for strategic development and many others, we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way. 🙌
Competitive Benefits:
Competitive benefits that make sense with both your local market and employment status. SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process.
Salary / Compensation
Note Hidden (-999) Job and company information not to be copied, shared, scraped, or otherwise disseminated without explicit consent of JSfirm, LLC.