- Engage on behalf of CYPFER in incident response tasks, interacting with various insurance partners, legal counsel, incident response units, client executives, and technical teams.
- Utilize standard tools and methodologies to collect forensic artifacts and images from affected systems.
- Assist with Windows forensics and triage to assess compromise and investigations.
- Apply mitigation strategies and concepts to remediate identified threats.
- Analyze triage collections/artifacts for indicators of compromise (IOCs) and potentially malicious activity.
- Review logs from host systems and appliances to identify suspicious activities.
- Collect forensic disk and memory images from physical and virtual endpoints and servers.
- Correlate events and build timelines of events.
Requirements
- 8+ years of experience in digital forensics, incident response, or a similar role
- Knowledge of Windows and Unix/Linux operating systems
- Understanding of the functionality of EDR / EPP technologies
- Familiarity with forensic acquisition and analysis of physical and virtual systems
- Working knowledge of storage technologies such as RAID, NAS, SAN, Fiber Channel, iSCSI, and NFS
- Ability to analyze and interpret logs from various sources
- Ability to perform threat research and analyze current threats
- Understanding of business email compromise (BEC) cases and investigation techniques
Senior Digital Forensics and Incident Response Consultant in plano at Unknown Company
This position is listed as full time and onsite.