Digital Forensics Analyst
Core
Investigate cyber incidents (ransomware, data theft, insider threat, etc.) to determine intrusion methods, actor actions, and data impact, producing legally defensible reports for clients, insurers, and legal counsel.
Role type
Digital Forensics Analyst (IC)
Builds
Forensic reports and incident analysis for clients across Australia
Domain
Cybersecurity / Digital Forensics
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Windows forensic artefacts analysis, Linux forensic artefacts analysis, evidence acquisition and chain of custody, incident lifecycle understanding, Threat Actor TTPs analysis, Microsoft 365 investigation, EDR/SIEM log analysis
Preferred skills
Magnet Axiom, X-Ways Forensics, Intella, KAPE, EZ Tools, Hayabusa, Velociraptor, Chainsaw, Volatility, Microsoft Entra ID investigation, SANS/GIAC certifications (GCFE, GCFA, GCFR, GCIH)
Technologies
Magnet Axiom, X-Ways Forensics, Intella, KAPE, EZ Tools, Hayabusa, Velociraptor, Chainsaw, Volatility, SentinelOne, CrowdStrike, Microsoft Defender, Carbon Black, Microsoft Sentinel, Elastic, Rapid7, Microsoft 365, Entra ID
Responsibilities
Investigate reactive cyber incidents referred by insurers and legal firms; deliver proactive forensic readiness and response planning for retainer clients; analyze forensic data from Windows, Linux, and cloud environments; produce written reports for legal and insurance review; participate in on-call rotation for major incidents
Seniority
Junior to Mid-level, hands-on IC