- Lead and participate in all phases of the incident response lifecycle, including preparation, detection and analysis, containment, eradication, recovery, and post incident activity.
- Conduct in-depth digital forensic investigations to identify the root cause, scope, and impact of security incidents.
- Collect, preserve, and analyze digital evidence from various sources (e.g., endpoints, networks, cloud environments).
- Utilize forensic tools and techniques to reconstruct events, identify attacker methodologies, and attribute threats.
- Develop and implement incident containment and eradication strategies.
- Prepare detailed incident reports, including technical findings, remediation recommendations, and lessons learned.
- Collaborate with internal teams (e.g., IT, legal, compliance) and external partners (e.g., law enforcement, third-party vendors) during incident response efforts.
- Contribute to the development and improvement of DFIR processes, playbooks, and tools.
- Stay current with the latest threat intelligence, attack techniques, and forensic methodologies.
- Provide training and mentorship to junior team members. Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Digital Forensics, or a related field (or equivalent practical experience).
- Minimum of 3-5 years of experience in digital forensics and incident response.
- Strong understanding of operating systems (Windows, Linux, macOS), network protocols, and cloud platforms.
- Proficiency with industry-standard forensic tools (e.g., EnCase, FTK, X-Ways, Volatility) and incident response platforms.
- Experience with scripting languages (e.g., Python, PowerShell) for automation and analysis.
- In-depth knowledge of common attack vectors, malware analysis, and threat intelligence.
- Excellent analytical, problem-solving, and critical thinking skills.
- Strong written and verbal communication skills, with the ability to present complex technical information clearly and concisely. Preferred Certifications (one or more of the following)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Examiner (GCFE)
- GIAC Reverse Engineering Malware (GREM)
- CompTIA CySA+
- EC-Council Certified Incident Handler (ECIH) Skills
- Technical Skills:
- Digital evidence collection and preservation
- Malware analysis
- Network forensics
- Host forensics
- Memory forensics
- Cloud forensics
- Log analysis
- Threat hunting
- Vulnerability management
- Soft Skills:
- Calmness under pressure
- Attention to detail
- Problem-solving
- Communication (written and verbal)
- Teamwork and collaboration
- Adaptability
- Critical thinkin
CybergateActive opening
DFIR Analyst
Apply to this job
Free credits included. Sign up to start applying with Jobfinder.
digital forensicsincident responsemalware analysiswindows forensicslinuxpythonpowershellthreat intelligence
CybergateDFIR Analyst
Apply to this job