Volexity logo
Volexity
Posted 70 days agoVerified live 1d ago

Incident Response and Forensic Analyst

Brief overview

Remote
3+ yrsMinimum
Digital ForensicsIncident ResponseEvidence AcquisitionEvidence PreservationHost Artifact AnalysisNetwork Artifact AnalysisMemory ForensicsDisk Image AnalysisNetwork Traffic AnalysisCommand-line ToolsScripting - PythonScripting - BashOperating Systems Internals - WindowsOperating Systems Internals - LinuxOperating Systems Internals - macOSMicrosoft 365Google Workspace

About the company

Volexity logo
Volexityvolexity.com

Volexity is a security firm that assists organizations with incident response, digital forensics, trusted advisory, and threat intelligence.

Job description

Summary

Volexity is a company that specializes in incident response and forensic analysis, and they are seeking an Incident Response and Forensic Analyst. The role involves leading investigations into cyber-attacks, analyzing digital evidence, and collaborating with various teams to enhance security measures.

Responsibilities

  • Incident Response: Lead and support investigations into security incidents, including APT intrusions, malware infections, ransomware, unauthorized access to cloud environments, and data breaches
  • Digital Forensics: Collect, preserve, and analyze digital evidence across endpoints, servers, cloud environments, and network systems, placing strong emphasis on memory forensics and volatile data analysis
  • Tool & Process Development: Develop and refine forensic workflows, scripts, and methodologies to improve investigation effectiveness
  • Reporting & Documentation: Produce detailed forensic reports, executive summaries, and technical briefs that clearly communicate findings
  • Cross-Team Collaboration: Partner with our Network Security Monitoring, Threat Intelligence, and Engineering teams to share insights and strengthen detection and response capabilities within our solutions
  • Proactive Assessments: Support threat-hunting activities, compromise assessments, and M&A cybersecurity assessments to identify weaknesses before incidents occur
  • Trusted Advisory: Serve as a trusted advisor to clients by addressing cybersecurity questions, providing expert guidance, and supporting their overall security posture

Skills

  • At least 3-5 years of hands-on experience performing digital forensics during security incidents, including evidence acquisition, preservation, and analysis
  • Proficiency in analyzing host and network-based artifacts (logs, memory, disk images, network traffic) using command-line tools and scripts
  • Strong knowledge of operating systems internals (Windows, Linux, macOS) and common attack techniques
  • Well versed in investigating activity in Microsoft 365, Google Workspace, GCP, Azure, AWS, and OCI environments
  • Experience responding to complex breaches related to web applications, operating systems, embedded devices, and cloud services
  • Ability to understand different attack techniques and how they relate to specific forensic artifacts
  • Familiar scripting with Python and Bash to automate forensic analysis, parse logs, and support incident response workflows
  • Excellent written and verbal communication skills, with the ability to document and communicate findings to customers
  • Knowledge of the current threat landscape and the TTPs of various threat actors
  • Resourceful self-starter who can work both with a team and independently, when required
  • Strong understanding of computer memory structure and how it relates to memory forensics
  • Prior use of memory analysis frameworks such as Volatility
  • Familiarity with other commercial forensic platforms related to Windows, macOS, Linux, and iOS
  • Experience with EDR/XDR platforms such as SentinelOne, Microsoft Defender for Endpoint, and CrowdStrike Falcon
  • Experience responding to incidents in cloud environments, such as AWS or Azure

Qualifications

Must Haves

  • At least 3-5 years of hands-on experience performing digital forensics during security incidents, including evidence acquisition, preservation, and analysis
  • Proficiency in analyzing host and network-based artifacts (logs, memory, disk images, network traffic) using command-line tools and scripts
  • Strong knowledge of operating systems internals (Windows, Linux, macOS) and common attack techniques
  • Well versed in investigating activity in Microsoft 365, Google Workspace, GCP, Azure, AWS, and OCI environments
  • Experience responding to complex breaches related to web applications, operating systems, embedded devices, and cloud services
  • Ability to understand different attack techniques and how they relate to specific forensic artifacts
  • Familiar scripting with Python and Bash to automate forensic analysis, parse logs, and support incident response workflows
  • Excellent written and verbal communication skills, with the ability to document and communicate findings to customers
  • Knowledge of the current threat landscape and the TTPs of various threat actors
  • Resourceful self-starter who can work both with a team and independently, when required

Nice to Haves

  • Strong understanding of computer memory structure and how it relates to memory forensics
  • Prior use of memory analysis frameworks such as Volatility
  • Familiarity with other commercial forensic platforms related to Windows, macOS, Linux, and iOS
  • Experience with EDR/XDR platforms such as SentinelOne, Microsoft Defender for Endpoint, and CrowdStrike Falcon
  • Experience responding to incidents in cloud environments, such as AWS or Azure

More jobs like this