IBM

IBM CISO - Cybersecurity Forensic Analyst

IBM$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in Incident Response, SOC, and/or Digital Forensics in a corporate environment.
  • Strong digital forensics skills using tools like EnCase, FTK, and Autopsy.
  • Ability to maintain evidence chain of custody and audit readiness.
  • Strong investigative and analytical skills, especially with log correlation and timeline reconstruction.
  • Experience with incident response workflows and EDR/SIEM platforms.
  • Familiarity with attack TTPs and experience with malware analysis or memory forensics preferred.
  • Knowledge of Windows, Mac, and Linux operating systems.

Responsibilities

  • Conduct forensic investigations on endpoint, network, and cloud environments.
  • Collect and analyze digital evidence while adhering to established standards.
  • Support incident response activities, from triage to recovery.
  • Correlate forensic evidence with threat intelligence and detection signals.
  • Analyze logs and disk images to reconstruct attack timelines.
  • Document findings in clear reports for various stakeholders.
  • Collaborate with CSIRT, SOC, Legal, and Compliance teams as needed.

Benefits

  • Healthcare benefits including medical, dental, and mental health support.
  • Financial programs like 401(k), life insurance, and short & long-term disability coverage.
  • Generous paid time off including holidays, vacation, and parental leave options.
  • Access to training and educational resources for skill development and certification.
  • Diverse employee resource groups and opportunities for community involvement.
Full Job Description
Your role and responsibilities

IBM's Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to cybersecurity incidents across the Americas region.

In this role, you will work at the intersection of incident response, digital forensics, and threat analysis, partnering closely with responders, threat detection teams, and leadership to investigate security events, preserve forensic evidence, and drive timely containment and remediation.

This is a hands-on analytical role requiring the ability to translate complex technical findings into actionable insights, enabling both operational response and executive decision-making. The successful candidate will demonstrate strong technical depth, investigative rigor, and the ability to operate effectively in high-pressure environments.

Key Responsibilities:

-Conduct forensic investigations on endpoint, network, and cloud environments

-Collect, preserve, and analyze digital evidence in accordance with established standards

-Support incident response activities, including triage, containment, eradication, and recovery

-Correlate forensic evidence with threat intelligence and detection signals
-Ability to analyze disk images, logs, and recovered data

-Reconstruct attack timelines and identify root cause and impact

-Document findings and produce clear, defensible reports for technical and non-technical stakeholders

-Collaborate across CSIRT, SOC, Legal, and Compliance teams as needed

-Contribute to post-incident reviews and continuous improvement of response capabilities

Required education

Associate's Degree/College Diploma

Preferred education

Bachelor's Degree

Required technical and professional expertise

- 3-5 years of experience in Incident Response, SOC and/or Digital Forensics in a global corporate environment
- Key Technical Skills
  • Strong digital forensics expertise across endpoints, systems, and network artifacts; experience with industry-standard tools (e.g., EnCase, FTK, Autopsy)
  • Ability to collect, preserve, and analyze evidence while maintaining chain of custody and audit readiness
  • Strong investigative and analytical skills, including correlation of logs, endpoint, and network data to determine root cause and reconstruct timelines
  • Experience operating within incident response workflows and using EDR, SIEM, and detection platforms in active incident environments
  • Understanding of attacker TTPs, with exposure to malware analysis or memory forensics preferred
  • Analysis using EDR tooling such as Crowdstrike or Microsoft Defender for Endpoint (MDE)
  • Basic scripting/automation skills (e.g., Python, PowerShell) are a plus

- Strong understanding of Windows, Mac, and Linux operating systems
- Solid working knowledge of networking topology, technology and tools, such as firewalls, proxies, IDS/IPS, EDR
Event analysis and correlation
Excellent technical writing and presentation skills

- The ability to work independently and effectively, as well as in a group setting required.

Preferred technical and professional experience

- Demonstrated computer forensic investigations experience
- Demonstrated knowledge of commercial and open-source forensic tools, such as X-Ways, Axiom, Autopsy, ELK, SIFT, Plaso, etc
- Familiarity with enterprise cybersecurity tooling (EDR, SIEM, forensic
platforms) Scripting & Automation (Nice to Have)
- Certifications such as: GCFA, CHFI, GCIH (or equivalent experience, nice to have)

- Demonstrated knowledge of analysis with EDR tooling, such as Crowdstrike or Microsoft Defender for Endpoint (MDE)
- Knowledge of incident response and analysis in cloud environments, such as IBM Cloud, AWS, or Azure
- Ability to successfully lead and facilitate information gathering meetings
- Experience managing small and large scale cyber security incidents

OTHER RELEVANT JOB DETAILS

IBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:
  • Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
  • Financial programs such as 401(k), the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
  • Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs. IBM also offers paid family leave benefits to eligible employees where required by applicable law
  • Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
  • Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences


We consider qualified applicants with criminal histories, consistent with applicable law.

This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role.

IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship.

The compensation range and benefits for this position are based on a full-time schedule for a full calendar year. The salary will vary depending on your job-related skills, experience and location. Pay increment and frequency of pay will be in accordance with employment classification and applicable laws. For part time roles, your compensation and benefits will be adjusted to reflect your hours. Benefits may be pro-rated for those who start working during the calendar year.

About IBM

Sequent Computer Systems designs and manufactures multiprocessing computer systems based on Cache Coherent Non-Uniform Memory Access architecture, which are used primarily as application and database servers for commercial applications. Through a partnership with Oracle Corporation, Sequent became a dominant high-end UNIX platform in the late 1980s and early 1990s. Later it introduced a next-generation high-end platform for UNIX and Windows NT based on non-uniform memory access architecture, NUMA-Q. Sequent Computer Systems, Inc. was incorporated in 1983 and is based in Beaverton, Oregon. In July 1999 Sequent Computer Systems, Inc. was acquired by International Business Machines Corp.

IBM Careers

Joining IBM presents a prime opportunity to be part of our global team of professionals, leading the way in technological innovation and business solutions. At IBM, we offer more than just job opportunities; we provide a platform for growth, leadership development, and a chance to be at the forefront of industry innovation. Work You’ll Do At IBM, your work impacts global markets and helps reshape industries. As part of our team, you will contribute to projects that harness the power of cloud computing, AI, and blockchain technologies. With IBM, you are positioned to lead in the marketplace, leveraging our deep industry expertise and commitment to digital innovation. Transform Your Career IBM is not just a company; it's a culture of innovation and leadership. We are committed to diversity and providing an inclusive environment where all professionals can thrive. Joining IBM means being part of a team that values your unique skills and perspectives. IBM offers a variety of career paths, including full-time positions and internships, that allow you to explore your interests and develop new skills. Our professional development programs are designed to help you grow at every stage of your career, featuring robust training, certification support, and opportunities for advancement. Innovate with Us Engage in work that matters with a team of over 350,000 IBMers worldwide, driving progress in over 170 countries. At IBM, innovation isn’t just about technology, it’s about transforming how businesses operate and compete. Your work will deliver solutions that anticipate and fulfill the needs of our clients in an ever-evolving landscape. Be Part of a Great Team IBMers are diverse, talented, and globally connected. You’ll collaborate with thought leaders and industry experts who are shaping the future of technology. Our culture fosters creativity, teamwork, and the continuous pursuit of excellence. Networking and Professional Growth IBM is deeply invested in the professional growth of its employees. We encourage networking within the company to foster connections that can lead to greater innovation and career advancement. Our leadership is committed to providing every employee with the tools they need to succeed, from mentorship programs to diversity training. Explore Job Opportunities Whether you’re looking for an internship, a graduate role, or a leadership position, IBM offers a range of career opportunities. Our hiring process is designed to be transparent and fair, providing you with all the resources you need to succeed in your interview and resume preparation. Stay Connected Join Our Team Discover the various positions available that match your skills and interests. At IBM, we look for passionate, curious, and solution-driven team players. Explore our open positions and find where you can make a difference. Keep Up to Date Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. Job Alert Emails Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. See what exciting and rewarding opportunities await at IBM. Join IBM and be part of a legacy of leadership and innovation. Shape your future and build a career designed to last.
Learn more about IBM
Size
307,600 employees
Market Cap
$128 billion
Industry
Net Income
$5.5 billion
Founded
1911
5 Year Trend
-6.4%
Revenue
$73.6 billion
NASDAQ

Similar Jobs

More Jobs at IBM

More Information Technology Jobs

Find similar IBM CISO - Cybersecurity Forensic Analyst jobs: