Responsibilities
- Collect, transmit, and store digital evidence in a forensically sound manner
- Analyze digital evidence to detect indicators of compromise and adversary actions
- Create incident timelines and theories regarding how compromises occurred
- Determine the root causes of incidents
- Engage in negotiations with threat actors when required, such as during ransom situations
- Participate in incident recovery tasks, including restoring data from backups, reimaging workstations and servers, and rebuilding network infrastructure
- Develop and deliver incident reports that outline key details for stakeholders, including insured executives, breach coach attorneys, and At-Bay claims management staff
- Formulate and present recommendations to help affected insureds reduce the risk of future incidents
- Design and deliver incident response training and simulations for targeted insureds
Requirements
- Previous experience in digital forensics and incident response
- Strong verbal and written communication abilities
- Hands-on experience in digital forensics and incident response, including areas such as Business Email Compromise, Ransomware, digital evidence collection and analysis, cyber threat intelligence development and analysis, leading or participating in digital evidence investigations, intrusion detection or cyber threat hunting, malware analysis, and incident recovery activities like data restoration from backups and using decryptor tools
- Practical experience in information technology operations, such as in a Network Operations Center, Security Operations Center, or Incident Response Team
- Bachelor's degree or equivalent qualification
- At least 2 years of experience in cybersecurity operations, incident response, incident recovery, or another security discipline
- Willingness to travel as needed to perform job duties
Nice to Have
- Significant undergraduate or graduate coursework in computer science, computer engineering, information systems, or cybersecurity
- Background in law enforcement or government or military with experience leading complex technical investigations
- Knowledge of cloud environments and cloud security products and services from major providers like AWS, Azure, and Google
- Experience at a top-10 cyber consulting firm or leading digital forensics and incident response provider
- One or more industry cybersecurity certifications, such as GCIH, Security+, or CISSP
Work Arrangement
Remote (Country) — USA, Nationwide
Other
Willingness to travel as needed to perform job functions