Analyste Forensique Cyber Expérimenté(e) – Réponse à Incident (Digital Forensics and Incident Response) - Toulouse
Core
Conduct advanced digital forensics investigations on critical security incidents including ransomware, APTs, and data exfiltration to strengthen client security posture.
Role type
Senior Digital Forensics and Incident Response (DFIR) Analyst
Builds
Technical reports, executive summaries, DFIR playbooks, and automated tools
Domain
Cybersecurity / Digital Forensics / Incident Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Windows, Linux, macOS, cloud environments (Azure, AWS), FTK, Splunk, Volatility, MITRE ATT&CK, NIST IR, SIEM logs, memory artifacts, network protocols, Wireshark, Python, PowerShell
Preferred skills
GCFA, GCFE, GCIH, CHFI certifications
Technologies
FTK, Splunk, Volatility, Wireshark, Python, PowerShell, Azure, AWS
Responsibilities
Respond rapidly to major compromises (ransomware, APT, data exfiltration); collect, preserve, and analyze digital evidence (disks, memory, logs, network artifacts); produce detailed technical reports and executive summaries; develop DFIR playbooks, tools, and procedures; monitor emerging threats and contribute to threat intelligence; collaborate with SOC, network, cloud, and client teams
Seniority
Senior, hands-on IC