Live opening · Posted 1 day ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Job Summary
The Senior Forensic Analyst leads forensic analysis for assigned projects, working closely with forensic leads and other analysts to perform both triage-level and advanced forensic investigations.
The role focuses on identifying threat actor behavior, unauthorized access, ransomware activity, and how a cyber intrusion occurred. The analyst will investigate digital evidence, identify Indicators of Compromise (IOCs) and attacker Tactics, Techniques, and Procedures (TTPs), and develop a clear timeline of the incident.
Roles & Responsibilities
Lead forensic analysis supporting ransomware and cyber-compromise investigations.
Perform forensic analysis of operating system artifacts and recover deleted data.
Conduct forensic investigations across Windows, Linux/Unix, Mac, and RAM/memory.
Analyze network and operating system logs, including:
Windows Event Logs
Unified Audit Logs
Firewall Logs
VPN Logs
Other security and system logs
Work with the Security Operations Center (SOC) and leverage data from Endpoint Detection and Response (EDR) solutions.
Identify Indicators of Compromise (IOCs) and attacker Tactics, Techniques, and Procedures (TTPs).
Prepare clear forensic findings and investigative updates, including a timeline of events.
Use incident-mapping frameworks such as MITRE ATT&CK and the Lockheed Martin Cyber Kill Chain.
Prepare and review forensic investigation reports, investigative updates, and appendices.
Perform peer reviews of reports prepared by other analysts.
Support the forensic lead in managing investigation timelines, delivery, and execution.
Work independently and prioritize tasks across multiple investigations.
Skills & Technical Knowledge
Strong knowledge of:
Windows disk forensics
Linux/Unix disk forensics
Memory/RAM forensics
Network Security Monitoring (NSM)
Network traffic analysis
Log analysis
Enterprise security controls
Forensic & Security Tools
Hands-on experience with tools such as:
EnCase
Axiom
FTK
X-Ways
SIFT
Splunk
Redline
Volatility
Wireshark
TCPDump
Open-source forensic tools
EDR platforms, preferably SentinelOne
Preferred Qualifications
Experience presenting technical findings to non-technical audiences.
Experience leading or mentoring forensic analysts.
Strong report-writing and documentation skills.
Experience handling PII, PHI, confidential, sensitive, and proprietary data.
Experience with cyber insurance investigations.
Strong analytical, problem-solving, and critical-thinking skills.
Excellent verbal and written communication skills.
Ability to work independently with minimal supervision.
Proficiency in Microsoft Office/Suite products.
Education & Experience
Required
Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related field with 4+ years of Incident Response or Digital Forensics experience.
OR
Master's/Advanced degree with 3+ years of relevant experience.
Certifications
Candidate must possess at least 2 of the following certifications:
Security+
Network+
SANS GCED
GCIH
GCFE
GCFA
CEH
CHFI
EnCE
Ideal Candidate Profile
The ideal candidate will have:
4+ years of DFIR / Digital Forensics experience
Ransomware / Cyber Incident Investigation
Windows & Linux Forensics
Memory Forensics
Network & Log Analysis
EDR/SOC experience
Forensic tools such as EnCase/FTK/Axiom/Volatility/Wireshark
MITRE ATT&CK / Cyber Kill Chain
At least 2 relevant certifications
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.