We are seeking a skilled Digital Forensics and Incident Response (DFIR) Analyst to join our Security Consultancy and Forensic team. The successful candidate will play a critical role in conducting compromise assessments, incident response investigations, and forensic analysis across both Windows and Linux environments. This position requires hands-on experience with a variety of open-source and industry-standard DFIR tools, a deep understanding of operating system internals, and the ability to produce detailed forensic and incident reports that clearly communicate findings to diverse audiences.
Key Responsibilities
- Conduct compromise assessments to detect potential intrusions, persistence mechanisms, lateral movement, privilege escalation, and data exfiltration activities.
- Perform digital forensic investigations on Windows and Linux systems, ensuring thorough evidence collection and analysis.
- Collect, preserve, and analyze digital evidence in line with established forensic best practices.
- Correlate forensic findings with the MITRE ATT&CK framework to identify adversary tactics, techniques, and procedures (TTPs).
- Utilize Threat Intelligence platforms to enrich investigations, validate Indicators of Compromise (IOCs), and identify relevant threat actor activity.
- Respond promptly to security incidents such as ransomware attacks, data breaches, unauthorized access, and other cyber threats.
- Prepare comprehensive forensic and incident response reports detailing technical findings, incident timelines, impact assessments, root-cause analysis, and remediation recommendations.
- Collaborate closely with SOC, Threat Hunting, IT, and other teams to support containment, eradication, and recovery efforts during security incidents.
- Contribute to the continuous improvement of DFIR processes, forensic capabilities, investigation methodologies, tools, and incident response playbooks.
Required Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field, or equivalent practical experience.
- Minimum of 2 years of hands-on experience in digital forensics and/or incident response.
- Strong understanding of Windows and Linux operating system internals and artifacts.
- Knowledge of network protocols, attack vectors, and adversary techniques.
- Familiarity with file systems such as NTFS and EXT4, as well as memory analysis.
- Experience using and interpreting outputs from DFIR tools including Velociraptor, KAPE, EZ Tools (Eric Zimmerman), UAC, Log Analysis Tools, and Volatility.
- Working knowledge of threat intelligence, IOCs, and MITRE ATT&CK framework mapping.
- Excellent analytical and problem-solving skills with a keen attention to detail.
- Strong written communication skills, capable of producing clear and concise technical investigation reports for both technical and non-technical stakeholders.
- Ability to manage multiple cases simultaneously and work effectively under pressure.
Preferred Qualifications and Additional Benefits
- Relevant certifications such as eCIR, CHFI, or BTL1.
- Experience with cloud forensics involving AWS, Azure, or Google Cloud Platform.
- Familiarity with SIEM tools like Splunk, ELK, or IBM QRadar, and endpoint telemetry.
- Proficiency in scripting languages such as PowerShell or Python for automation purposes.
- Experience in documenting and presenting case findings to clients or executive leadership.
This role offers an excellent opportunity to work in a dynamic environment focused on advanced cybersecurity investigations and incident response. Candidates who are proactive, detail-oriented, and eager to contribute to a collaborative security team will thrive in this position.