Summary
Volexity is a company that specializes in incident response and forensic analysis, and they are seeking an Incident Response and Forensic Analyst. The role involves leading investigations into cyber-attacks, analyzing digital evidence, and collaborating with various teams to enhance security measures.
Responsibilities
- Incident Response: Lead and support investigations into security incidents, including APT intrusions, malware infections, ransomware, unauthorized access to cloud environments, and data breaches
- Digital Forensics: Collect, preserve, and analyze digital evidence across endpoints, servers, cloud environments, and network systems, placing strong emphasis on memory forensics and volatile data analysis
- Tool & Process Development: Develop and refine forensic workflows, scripts, and methodologies to improve investigation effectiveness
- Reporting & Documentation: Produce detailed forensic reports, executive summaries, and technical briefs that clearly communicate findings
- Cross-Team Collaboration: Partner with our Network Security Monitoring, Threat Intelligence, and Engineering teams to share insights and strengthen detection and response capabilities within our solutions
- Proactive Assessments: Support threat-hunting activities, compromise assessments, and M&A cybersecurity assessments to identify weaknesses before incidents occur
- Trusted Advisory: Serve as a trusted advisor to clients by addressing cybersecurity questions, providing expert guidance, and supporting their overall security posture
Skills
- At least 3-5 years of hands-on experience performing digital forensics during security incidents, including evidence acquisition, preservation, and analysis
- Proficiency in analyzing host and network-based artifacts (logs, memory, disk images, network traffic) using command-line tools and scripts
- Strong knowledge of operating systems internals (Windows, Linux, macOS) and common attack techniques
- Well versed in investigating activity in Microsoft 365, Google Workspace, GCP, Azure, AWS, and OCI environments
- Experience responding to complex breaches related to web applications, operating systems, embedded devices, and cloud services
- Ability to understand different attack techniques and how they relate to specific forensic artifacts
- Familiar scripting with Python and Bash to automate forensic analysis, parse logs, and support incident response workflows
- Excellent written and verbal communication skills, with the ability to document and communicate findings to customers
- Knowledge of the current threat landscape and the TTPs of various threat actors
- Resourceful self-starter who can work both with a team and independently, when required
- Strong understanding of computer memory structure and how it relates to memory forensics
- Prior use of memory analysis frameworks such as Volatility
- Familiarity with other commercial forensic platforms related to Windows, macOS, Linux, and iOS
- Experience with EDR/XDR platforms such as SentinelOne, Microsoft Defender for Endpoint, and CrowdStrike Falcon
- Experience responding to incidents in cloud environments, such as AWS or Azure
Qualifications
Must Haves
- At least 3-5 years of hands-on experience performing digital forensics during security incidents, including evidence acquisition, preservation, and analysis
- Proficiency in analyzing host and network-based artifacts (logs, memory, disk images, network traffic) using command-line tools and scripts
- Strong knowledge of operating systems internals (Windows, Linux, macOS) and common attack techniques
- Well versed in investigating activity in Microsoft 365, Google Workspace, GCP, Azure, AWS, and OCI environments
- Experience responding to complex breaches related to web applications, operating systems, embedded devices, and cloud services
- Ability to understand different attack techniques and how they relate to specific forensic artifacts
- Familiar scripting with Python and Bash to automate forensic analysis, parse logs, and support incident response workflows
- Excellent written and verbal communication skills, with the ability to document and communicate findings to customers
- Knowledge of the current threat landscape and the TTPs of various threat actors
- Resourceful self-starter who can work both with a team and independently, when required
Nice to Haves
- Strong understanding of computer memory structure and how it relates to memory forensics
- Prior use of memory analysis frameworks such as Volatility
- Familiarity with other commercial forensic platforms related to Windows, macOS, Linux, and iOS
- Experience with EDR/XDR platforms such as SentinelOne, Microsoft Defender for Endpoint, and CrowdStrike Falcon
- Experience responding to incidents in cloud environments, such as AWS or Azure