At-Bay logo
At-Bay
Posted 120 days agoVerified live 2d ago

Cyber Analyst, Digital Forensics Incident Response

Brief overview

United StatesHybrid
UndergradOr in progress
$80k–$115k/yrStated range
2+ yrsMinimum
6 H-1B approvalsDept. of Labor
2 green cardsCertified filings
Digital forensicsIncident responseDigital evidence collection and analysisCyber threat intelligence development and analysisIntrusion detectionCyber threat huntingMalware analysisIncident recoveryData restoration from backupsOperation of decryptor toolsBusiness Email Compromise investigationRansomware incident handlingStrong oral communicationStrong written communicationCloud environments knowledge

About the company

At-Bay is the InsurSec (Insurance and Cybersecurity) provider for the digital age.

Visa sponsorship history

4 years sponsoring, last filed FY2026

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
6H-1B approved
100%approval rate
1new H-1B hires
2PERM certified
$135,000median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20241
20254
20261
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20232
20251
20261
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20252
Top sponsored roles
GAAP Accounting ManagerRisk System DeveloperActuarial Analyst, PricingCommunications Manager

Job description

Summary

At-Bay is a fast-growth InsurSec company on a mission to protect small businesses from digital risks. The Cyber Analyst role focuses on delivering incident investigation and response services, involving the collection and analysis of digital evidence, development of incident reports, and training for insureds.

Responsibilities

  • Forensically sound collection, transmission, and storage of digital evidence
  • Analysis of digital evidence to identify indicators of compromise and adversary activity
  • Development of incident timelines and theories of compromise
  • Identification of incident root causes
  • Participation in threat actor negotiations as necessary (e.g., ransom negotiations, etc.)
  • Participation in incident recovery (e.g., restoration of data from backups, reimaging workstations and servers, rebuilding network infrastructure, etc.) activities as necessary
  • Development and delivery of incident reports to document key incident details for engagement stakeholders including executive leaders for insureds, breach coach attorneys, and At-Bay claims management staff as necessary
  • Development and delivery of recommendations to mitigate the risk of future incidents for impacted insureds
  • Development and delivery of incident response training and simulations for targeted insureds

Skills

  • Previous digital forensics and incident response experience
  • Strong oral and written communication skills
  • Previous hands-on experience performing digital forensics and incident response, including several of the following: Business Email Compromise, Ransomware, Digital evidence collection and analysis, Development and analysis of cyber threat intelligence, Leadership of or participation in investigations involving digital evidence, Intrusion detection / cyber threat hunting, Malware analysis, Incident recovery activities such as restoration of data from backups, operation of decryptor tools, etc
  • Previous hands-on experience working in information technology operations (e.g., Network Operations Center, Security Operations Center, Incident Response Team, etc.)
  • Bachelor's degree or equivalent
  • Minimum of 2 years of experience in cybersecurity operations, incident response, incident recovery, or another security discipline
  • Willingness to travel as needed to perform job functions
  • Significant undergraduate or graduate coursework in computer science, computer engineering, information systems, or cybersecurity
  • Previous background in law enforcement or government/military with experience leading complex technical investigations
  • Knowledge of cloud environments, including knowledge of cloud security products and services offered by major cloud service providers (e.g., AWS, Azure, Google)
  • Experience in a top-10 cyber consulting firm or leading DFIR provider preferred
  • One or more industry cybersecurity certifications (e.g., GCIH, Security+, CISSP, etc.)

Qualifications

Must Haves

  • Previous digital forensics and incident response experience
  • Strong oral and written communication skills
  • Previous hands-on experience performing digital forensics and incident response, including several of the following: Business Email Compromise, Ransomware, Digital evidence collection and analysis, Development and analysis of cyber threat intelligence, Leadership of or participation in investigations involving digital evidence, Intrusion detection / cyber threat hunting, Malware analysis, Incident recovery activities such as restoration of data from backups, operation of decryptor tools, etc
  • Previous hands-on experience working in information technology operations (e.g., Network Operations Center, Security Operations Center, Incident Response Team, etc.)
  • Bachelor's degree or equivalent
  • Minimum of 2 years of experience in cybersecurity operations, incident response, incident recovery, or another security discipline
  • Willingness to travel as needed to perform job functions

Nice to Haves

  • Significant undergraduate or graduate coursework in computer science, computer engineering, information systems, or cybersecurity
  • Previous background in law enforcement or government/military with experience leading complex technical investigations
  • Knowledge of cloud environments, including knowledge of cloud security products and services offered by major cloud service providers (e.g., AWS, Azure, Google)
  • Experience in a top-10 cyber consulting firm or leading DFIR provider preferred
  • One or more industry cybersecurity certifications (e.g., GCIH, Security+, CISSP, etc.)

More jobs like this