5+ years of experience
Concerned about your lack of experience? Learn More...
Employment Type:
Full time
Job Category:
Information Services
Digital Forensics Incident Response Team Lead
(This job is no longer available)
Grad Date

Not sure what types of jobs you are interested in?

Explore Jobs
Based on Your Education

Follow This Company

Job Description

Looking for a Digital Forensics Incident Response Team Lead over: Threat Intelligence, Threat Hunting, Incident Monitoring, 1st year computer forensics malware investigations forensic software XWays, Encase FTX.

You will perform intelligence-driven network defense supporting the Security Operations Center capabilities (Threat Intelligence, Threat Hunting, and Incident Monitoring/Response/Handling, et al.) The role involves forensic analysis of online and offline ( dead-box ) hosts and network logs associated with information security incidents discovered by the Threat Hunting and Monitoring capabilities.


Bachelor of Science degree
5+ years of direct computer forensics experience.
Operational understanding of modern threats and tactics used currently.
Experience with malware investigations and techniques used to investigate these incident.
Experience with PII and PCI investigations, as well identifying the resources needed to successfully investigate them.
Experience in supporting an Enterprise or Security Operation Center (SOC) investigation.
Familiar with industry accepted Open Source Solutions to help with varied components of an investigation.
Familiar with industry standard forensic software such as XWays, EnCase, FTK, and other software's that may come to market.
Experience with identification, preservation, and analysis of electronic data pertaining to laptops, desktops, Servers, backup tapes, mobile devices, webmail providers, cloud services, and other emerging technologies.
Strong background with Microsoft Windows, Apple OS X, and Linux operating systems.
Familiar with network environments and computer and network administration protocols.


Applicants must be eligible to work in the specified location