We are seeking a skilled Digital Forensics and Incident Response (DFIR) Analyst to join our Security Consultancy and Forensic team. In this role, you will be responsible for conducting compromise assessments, incident response investigations, and forensic analysis across both Windows and Linux environments. The ideal candidate will have practical experience with open-source and industry-standard DFIR tools, a deep understanding of operating system internals, and the ability to produce detailed forensic and incident reports that clearly communicate technical findings.

Key Responsibilities

- Conduct compromise assessments to detect potential intrusions, persistence mechanisms, lateral movement, privilege escalation, and data exfiltration activities.
- Perform digital forensic investigations on Windows and Linux systems, ensuring thorough evidence collection and analysis.
- Collect, preserve, and analyze digital evidence following established forensic best practices to maintain integrity and admissibility.
- Correlate forensic findings with the MITRE ATT&CK framework to identify adversary tactics, techniques, and procedures (TTPs).
- Utilize Threat Intelligence platforms to enrich investigations, validate Indicators of Compromise (IOCs), and identify relevant threat actor activity.
- Respond promptly to security incidents including ransomware attacks, data breaches, unauthorized access, and other cyber threats.
- Prepare comprehensive forensic and incident response reports detailing technical findings, incident timelines, impact assessments, root cause analysis, and remediation recommendations.
- Collaborate closely with SOC, Threat Hunting, IT, and other teams to support containment, eradication, and recovery efforts during security incidents.
- Contribute to the continuous improvement of DFIR processes, forensic capabilities, investigation methodologies, tools, and incident response playbooks.

Required Qualifications

- Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field, or equivalent practical experience.
- Minimum of 2 years of hands-on experience in digital forensics and/or incident response.
- Strong understanding of Windows and Linux operating system internals and artifacts.
- Knowledge of network protocols, attack vectors, and adversary techniques.
- Familiarity with file systems such as NTFS and EXT4, as well as memory analysis.
- Experience using and interpreting outputs from tools including Velociraptor, KAPE, EZ Tools (Eric Zimmerman), UAC, log analysis tools, Volatility, and others.
- Working knowledge of threat intelligence, IOCs, and MITRE ATT&CK mapping.
- Excellent analytical and problem-solving skills with meticulous attention to detail.
- Strong written communication skills, capable of producing clear and concise technical investigation reports for both technical and non-technical audiences.
- Ability to work effectively under pressure and manage multiple investigations simultaneously.

Preferred Qualifications and Benefits

- Relevant certifications such as eCIR, CHFI, BTL1, or similar credentials.
- Experience with cloud forensics involving AWS, Azure, or Google Cloud Platform.
- Familiarity with SIEM tools like Splunk, ELK, or IBM QRadar, and endpoint telemetry solutions.
- Proficiency in scripting languages such as PowerShell or Python for automation purposes.
- Experience in documenting and presenting case findings to clients or executive leadership teams.

This role offers the opportunity to work in a dynamic environment where your expertise will directly contribute to strengthening organizational security posture and incident handling capabilities. If you are passionate about digital forensics and incident response and thrive in a collaborative, fast-paced setting, we encourage you to apply.

Job Details

Total Positions:
1 Post
Job Shift:
First Shift (Day)
Job Type:
Job Location:
Gender:
No Preference
Age:
18 - 65 Years
Minimum Education:
Bachelors
Career Level:
Mid-Level
Maximum Experience:
2 Years
Apply Before:
Oct 06, 2026
Posting Date:
Sep 30, 2026

Trillium Information Security Systems

· 11-50 employees - Rawalpindi

What is your Competitive Advantage?

Get quick competitive analysis and professional insights about yourself
Talk to our expert team of counsellors to improve your CV!
Try Rozee Premium
I found a job on Rozee!