Senior Cybersecurity Incident Responder
Core
Lead digital forensics & incident response (DFIR) engagements and proactive advisory services for major cybersecurity incidents across Australia and New Zealand.
Role type
Senior IC cybersecurity incident responder (DFIR)
Builds
DFIR reports, containment/eradication/recovery strategies, threat intelligence briefings, and threat models
Domain
Cybersecurity / Digital Forensics / Incident Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Digital forensics investigation, incident response leadership, root cause analysis, adversary activity timeline construction, intrusion vector identification, evidence collection and preservation, stakeholder communication, security framework knowledge (NIST CSF, MITRE ATT&CK, D3FEND)
Preferred skills
Basic scripting/automation (PowerShell, Bash, Python, Ruby), DFIR certifications (SANS GCFA/GCFE/GCIH)
Technologies
EnCase, X-Ways, Magnet Axiom, Velociraptor, KAPE, THOR, CrowdStrike, Microsoft Defender, Splunk, Sentinel, EDR, SIEM, XDR
Responsibilities
Conduct thorough investigations into major security incidents to determine root causes and impact; analyze affected systems using forensic techniques; utilize security tooling to investigate confirmed or suspected compromises; collect digital forensics evidence in accordance with industry standards; produce comprehensive DFIR reports; support coordination of containment, eradication, and recovery efforts; deliver proactive services including tabletop exercises, threat hunting, and breach readiness assessments; participate in on-call roster for major incidents; travel to customer sites as required
Seniority
Senior, hands-on IC