Incident Response and Forensic Analyst
Core
Investigating security incidents, conducting digital forensic examinations, and leading response efforts to protect critical enterprise IT assets.
Role type
Senior IC incident response and digital forensic analyst
Builds
Incident response playbooks, forensic investigation workflows, and threat intelligence reports
Domain
Cybersecurity / Digital Forensics / Incident Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Digital forensics on Windows/Linux/macOS, memory forensics, network forensics, malware analysis, incident response frameworks, evidence preservation, chain of custody procedures
Preferred skills
Cloud forensics (AWS/Azure/GCP), reverse engineering, scripting (Python/PowerShell/Bash), SIEM log analysis, threat intelligence platforms, EDR tools, mobile device forensics, MITRE ATT&CK
Technologies
EnCase, FTK, X-Ways, Autopsy, Wireshark, tcpdump, NetworkMiner, CrowdStrike, Carbon Black, SentinelOne
Responsibilities
Leading incident response activities from detection through recovery, conducting forensic investigations on compromised systems, analyzing malware samples and attacker techniques, developing incident response playbooks, coordinating with SOC and legal stakeholders, documenting incident timelines and findings, providing expert testimony on forensic findings, mentoring junior analysts
Seniority
Senior, hands-on IC