Cybersecurity Forensics and Incident Response Analyst
Core
Lead digital forensics and incident response activities, investigating cyber attacks, analyzing malicious activity, and coordinating response across technical and business teams.
Role type
Senior IC Cybersecurity Forensics and Incident Response Analyst
Builds
Forensic evidence artifacts, incident response reports, and improved detection workflows
Domain
Cybersecurity, Digital Forensics, Incident Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Windows forensics, malware analysis (static/dynamic), scripting (Python/Bash/PowerShell), SIEM/SOAR/EDR usage, network traffic analysis, memory/disk forensics, threat hunting, MITRE ATT&CK framework knowledge
Preferred skills
GIAC/ISC2/EC-Council certifications, internal security tool development, security analytics with ML/AI, virtualized environment security, Spanish or Portuguese language skills
Technologies
EnCase, FTK, SIFT, X-Ways, Volatility, Sleuth Kit, Autopsy, Splunk, Velociraptor, Active Directory, IDS/IPS, firewalls, DNS, web proxies
Responsibilities
Perform live-system, offline, and remote compromise investigations; analyze malicious activity and attack techniques; coordinate response activities during critical incidents; prepare executive summaries and investigation reports; collaborate with SOC and threat intelligence teams to improve detection and response capabilities
Seniority
Senior, hands-on IC