Brisbane, Queensland, Australia Remote (Country) Full-time

Datacom is hiring a Digital Forensic Specialist

About the Role

Our Purpose

At Datacom, we're all about connecting people and technology to solve challenges, create opportunities, and uncover new possibilities for the communities we call home.

Our Team

Our Cybersecurity Defence Operations Centre (CDOC) spans Australia & New Zealand, offering a comprehensive suite of cybersecurity services including managed SOC/SIEM/EDR/XDR, threat intelligence, and digital forensics & incident response (DFIR). We're a battle-tested team of Cybersecurity Analysts, Platforms Engineers, Automation Specialists, Solutions Delivery Engineers, Threat Intel Analysts, Threat Hunters, & Incident Responders who've been protecting commercial and government customers for over a decade.

We collaborate with industry leaders to deliver top-tier services and provide you with a cutting-edge technical skillset, certifications, and experience.

About The Role

We're on the hunt for a highly skilled and motivated professional to join our Cybersecurity Incident Response Team (CSIRT) as a Senior Cybersecurity Incident Responder. Our CSIRT team delivers proactive and reactive expertise to help organizations navigate major cybersecurity incidents.

In this role, you'll be responsible for leading digital forensics & incident response (DFIR) engagements across Australia or New Zealand. This includes delivering tabletop exercises, compromise assessments & threat hunting, breach readiness assessments, threat intelligence briefings, & threat modelling. We need someone with extensive experience investigating and responding to critical cybersecurity incidents, backed by stellar communication, analytical, and problem-solving skills.

Due to the nature of our client, you must be an Australian Citizen and be able to achieve Australian Government NV1 clearance to be successful in your application for this role.

What You'll Do

As a Senior Cybersecurity Incident Responder, you will:

  • Conduct thorough investigations into major security incidents, determining root causes, impact, and mitigation strategies. Providing expertise and support to contain, eradicate, and recover from such security incidents.
  • Conduct analysis of affected systems utilising forensic techniques to thoroughly examine system events and adversary activities.
  • Utilise security tooling such as EDR, SIEM, XDR, & Identity technologies to assist your investigation of confirmed or suspected compromises.
  • Undertake log & correlation analysis and construct a timeline of adversary activities.
  • Identify intrusion vectors & root causes and develop recommendation actions to prevent similar incidents.
  • Collect digital forensics evidence from affected systems in accordance with industry standards for image acquisition and preservation of digital evidence.
  • Produce comprehensive, detailed DFIR reports outlining the investigative steps undertaken, your findings, and recommendations.
  • Support the coordination of containment, eradication and recovery efforts based on available information and established processes.
  • Analysis of incident response effort, with feedback from the customer and third parties as part of Post Incident Reviews (PIRs) and Lessons Learned.
  • Deliver proactive incident response services which include tabletop exercises, threat hunting, compromise assessments, breach readiness assessments, threat intelligence briefings, and threat modelling.
  • Communicate with senior stakeholders within Datacom and our customers.
  • Work with other members of the CSIRT team, to develop the technical capabilities of the CSIRT - including improving the processes and technology to deliver successful outcomes to customers and stakeholders.
  • Participate in an on-call roster for major incident response.
  • Occasional planned or last-minute/urgent travel to customer sites will be required for certain customer facing engagements. This may include a customer site in your home city, or travel to other customer sites within Australia and New Zealand.

What you'll bring

  • Confidence in communicating with a variety of senior stakeholders, including Senior Leadership teams in difficult / tense situations.
  • Proven experience in responding to high-profile cybersecurity incidents that have had significant operational or privacy impacts to the affected organisation such as ransomware & data breaches.
  • Experience in digital forensics & incident response (DFIR) with an understanding of key system & digital forensic artifacts and how they are useful in a cybersecurity investigation.
  • Experience using DFIR tools such as EnCase, X-Ways, Magnet Axiom, Velociraptor, KAPE, & THOR.
  • Proven knowledge and experience of efficiently searching large datasets across multiple log sources and underlying platforms including XDR/EDR and SIEM products such as CrowdStrike, Microsoft Defender, Splunk, or Sentinel.
  • A strong understanding of current and emerging attacker behaviours, tools, tactics, and techniques.
  • An understanding of various security frameworks and methodologies such as NIST CSF, MITRE ATT&CK and D3FEND, Unified Kill Chain and OWASP Top 10.
  • Basic scripting or automation skills are desirable (for example PowerShell, Bash, Python, or Ruby).
  • SANS GCFA, GCFE, GCIH, or relevant DFIR certifications are desirable.

Why join us here at Datacom?

Datacom is one of Australia and New Zealand's largest suppliers of Information Technology professional services. We've managed to maintain a dynamic, agile, small business feel that often gets lost in larger organizations. Our people are the heartbeat of Datacom, creating a unique culture and energy you'll feel from the moment you meet us.

We genuinely care about our team and offer perks like social events, chill-out spaces, remote working, flexi-hours, and professional development courses. You'll have the chance to learn, grow your career, connect authentically, and bring your true self to work. We recognize and value your contributions in a collegial, flat-structured environment.

We operate at the cutting edge of technology, helping Australia and New Zealand's largest enterprise organizations explore possibilities and solve their most complex challenges. Translation: you'll never run out of interesting problems to tackle.

We're committed to creating an inclusive and welcoming workplace for everyone. We take pride in the steps we've taken and continue to take to make our environment fun, friendly, and supportive for all.

Required Skills
Digital ForensicsIncident ResponseSIEM AnalysisThreat HuntingCrowdStrikeSplunkMITRE ATT&CKScripting (PowerShell/Python)Log CorrelationCybersecurity Frameworks
Looking for a remote dev community?

200+ professionals, 37 countries, one network

Working remotely doesn't mean working alone. Iglu connects you with developers, designers, and digital experts worldwide. Collaborate, learn, and grow together.

Global professional network
Knowledge sharing & collaboration
Regular community events
Cross-project opportunities
Join the community
37 countries represented
About company
Datacom

Datacom is one of Australia and New Zealand’s largest suppliers of Information Technology professional services. They work with organisations and communities across Australia and New Zealand to make a difference in people’s lives and help organisations use the power of tech to innovate and grow.

Visit website
Job Details
Category security
Posted 8 months ago