Contract Incident Response Analyst (DFIR)
Support a partner company’s incident response team on contract assignments involving digital forensics and active cyber threats. Work is flexible and requires availability for at least a few hours per week.
Обязанности
- Conduct incident response and digital forensic investigations into active threats and security breaches.
- Analyze live response data and forensic artifacts to identify malicious activity and attack methods.
- Investigate Windows, macOS, and Linux systems using appropriate forensic techniques and tools.
- Investigate business email compromise, account takeover, and other identity-related incidents.
- Analyze network activity and identify suspicious behavior and indicators of compromise.
- Support investigations across cloud environments and SaaS applications.
- Apply threat intelligence and knowledge of adversary techniques to investigations.
- Contribute analysis to cases involving ransomware and sophisticated threats, including nation-state activity.
- Share investigative expertise and feedback to help improve incident response practices.
Требования
- Professional experience responding to cyber threats as an incident response consultant, SOC analyst, or in a related role.
- Strong knowledge of Windows, macOS, and Linux fundamentals and forensic artifacts.
- Experience with digital forensics, business email compromise investigations, and network analysis.
- Ability to distinguish legitimate user activity from threat actor behavior using technical evidence and context.
- Ability to work independently and contribute to an experienced team.
- Availability for at least a few hours of incident response work per week.
- Ability to balance contract work with existing professional commitments, where permitted by the current employer.
Будет плюсом
- Experience investigating cloud-native environments across AWS, GCP, and Azure, or the ability and willingness to develop that expertise.
- Interest in threat intelligence, emerging attack techniques, and evolving cyber threats.
Условия и преимущества
- Flexible contract engagement designed to accommodate existing commitments.
- Work on live investigations without a traditional full-time on-call schedule.
- Exposure to complex cyber incidents and cloud environments.
- Collaborate with experienced incident response and digital forensics specialists.
- Flexible assignments based on availability and active case needs.