Rolls-Royce plc

Digital Forensics Analyst

Rolls-Royce plc$98K — $160K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Associate's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2+ years relevant experience OR;
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2+ years relevant experience OR;
  • Master's degree in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • PhD in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • In lieu of a degree, must have 6+ years experience in Cyber Security or Information Technology.
  • Must be a US Citizen.

Responsibilities

  • Lead or support investigations involving malware and ransomware incidents.
  • Perform various forensic analyses across endpoints and cloud environments.
  • Conduct triage during security incidents and coordinate containment efforts.
  • Develop incident response playbooks and detailed reports.
  • Proactively hunt threats across multiple telemetry sources.
  • Collaborate with red team operators for adversary emulation activities.
  • Develop and tune detections in SIEM and EDR platforms.

Benefits

  • Comprehensive benefits package including health, dental, and vision insurance.
  • 401(k) retirement plan with company match.
  • Tuition reimbursement for further education.
  • Flexible spending account options available.
  • Paid Time Off and holidays included.
  • Employee Assistance Program support.
Full Job Description
Job Description

Job Title: Digital Forensics Analyst

Working Pattern: Fulltime - hybrid

Working location: Indianapolis, IN

Relocation assistance will be provided if applicable

Position Summary:

We are seeking a highly motivated DFIR Specialist to join our Purple Team. This role bridges offensive and defensive security operations by combining incident response, threat hunting, digital forensics, adversary emulation, and detection engineering.
The ideal candidate enjoys investigating real-world attacks, understanding adversary behavior, improving detection capabilities, and working collaboratively with red and blue teams to strengthen security posture.

What you will be doing:

Incident Response
  • Lead or support investigations involving malware, ransomware, insider threats, and advanced persistent threats.
  • Perform endpoint, memory, disk, and cloud forensics.
  • Conduct triage activities during security incidents.
  • Coordinate containment, eradication, and recovery efforts.
  • Develop incident response playbooks and procedures.
  • Produce executive and technical incident reports.
Threat Hunting
  • Conduct proactive hunts across endpoints, identity, cloud, and network telemetry.
  • Develop hypotheses based on emerging adversary techniques.
  • Analyze attack patterns using frameworks such as MITRE ATT&CK.
  • Identify gaps in visibility and logging.
Purple Team Operations
  • Collaborate with red team operators to emulate adversary tactics.
  • Validate detections against simulated attacks.
  • Assist in planning and executing purple team exercises.
  • Measure and improve detection coverage.
  • Map detections and hunting content to ATT&CK techniques.
Detection Engineering
  • Develop and tune detections within SIEM and EDR platforms.
  • Reduce false positives while improving fidelity.
  • Create custom analytics, dashboards, and monitoring content.
  • Automate repetitive investigation tasks through scripting.
Forensics
  • Acquire and analyze forensic artifacts from:
    • Windows systems
    • Linux systems
    • Cloud environments
    • Containers
    • Identity providers
  • Perform timeline reconstruction.
  • Analyze persistence mechanisms.


Basic Qualifications:
  • Associate's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;
  • Master's degree in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • PhD in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • In lieu of a degree must have 6+ years' experience in Cyber Security or Information Technology
  • Must be a US Citizen


Preferred Qualifications:
  • 3+ years focused on incident response, threat hunting, or DFIR.
  • 6+ years' experience in Cyber Security or Information Technology
  • Experience with various memory acquisition techniques/tools:
    • FTK Imager
    • Volatility 3
    • Velociraptor for remote memory dumps
  • Experience with enterprise SIEM platforms such as:
    • Microsoft Sentinel
    • Splunk Enterprise Security
    • Elastic Security
  • Experience with EDR technologies including:
    • Microsoft Defender XDR
    • CrowdStrike Falcon
    • SentinelOne Singularity
  • Familiarity with:
    • Windows Event Logs
    • Sysmon
    • KQL
    • Sigma rules
    • YARA
    • PowerShell
    • Python
    • Memory analysis
    • Malware triage
  • Understanding of:
    • Attack chains
    • Identity-based attacks
    • Cloud attack techniques
    • Detection engineering principles
  • Experience with adversary emulation frameworks.
  • Familiarity with:
    • Caldera
    • Prelude Operator
    • Velociraptor
    • TheHive
  • Cloud security investigation experience in:
    • Microsoft Azure
    • Amazon AWS
    • Google Cloud

Certifications:
  • GIAC certifications such as GCFA, GCIH, GCFE, etc.
  • Microsoft certifications such as SC-200, SC-400, AZ-500
  • CISSP, CCSP


Job Category

Information Technology

Job Posting Date

04 Sept 2026; 00:09
Pay Range

Pay ranges for remote employees are based on the state where the employee resides and may vary from the posted range.

$98,566-$160,169-Annually

Location:

Indianapolis, IN

Benefits

Rolls-Royce provides a comprehensive and competitive Total Rewards package that includes base pay and a discretionary bonus plan. Eligible employees may have the opportunity to enroll in other benefits, including health, dental, vision, disability, life and accidental death & dismemberment insurance; a flexible spending account; a health savings account; a 401(k) retirement savings plan with a company match; Employee Assistance Program; Paid Time Off; certain paid holidays; paid parental and family care leave; tuition reimbursement; and a long-term incentive plan. The options available to an employee may vary depending on eligibility factors such as date of hire, employment type, and the applicability of collective bargaining agreements.

About Rolls-Royce plc

Rolls-Royce plc is a British multinational engineering company that designs, manufactures, and distributes power systems for aviation, marine, and energy markets. The company was founded in 1904 and is headquartered in London, England. Rolls-Royce is a leading provider of power systems for civil and military aircraft, and is also a major supplier of power systems for marine vessels. The company's energy division provides power systems for the oil and gas industry, as well as for power generation and other industrial applications. Rolls-Royce has operations in over 50 countries and employs over 50,000 people worldwide.
Learn more about Rolls-Royce plc
Size
44,000 employees
Industry
NASDAQ

Similar Jobs

More Jobs at Rolls-Royce plc

More Information Technology Jobs

Find similar Digital Forensics Analyst jobs: