The Lead Analyst, Information Security (Forensics) serves as the organization's subject matter expert for digital forensics investigations and evidence preservation. This role leads complex forensic examinations supporting cybersecurity incidents, legal matters, compliance investigations, and employee misconduct inquiries. The position ensures evidence is collected, analyzed, documented, and maintained in accordance with industry best practices and chain-of-custody requirements while partnering closely with Information Security, Legal, Human Resources, Compliance, and external stakeholders. The Lead Analyst translates forensic findings into clear, defensible reports and provides guidance to analysts and incident responders to strengthen the organization's investigative capabilities.
Essential Duties and Responsibilities- Lead digital forensic investigations involving security incidents, suspected policy violations, litigation support, and regulatory inquiries.
- Collect, preserve, analyze, and document digital evidence from endpoints, servers, cloud platforms, mobile devices, email systems, and other enterprise technologies.
- Maintain strict chain-of-custody controls and evidence handling procedures to ensure admissibility and defensibility of findings.
- Conduct forensic triage, scoping, root-cause analysis, timeline reconstruction, and artifact analysis during cybersecurity incidents.
- Partner with Legal, Human Resources, Compliance, Internal Audit, and business leaders to support investigations and fact-finding efforts.
- Prepare comprehensive investigative reports, executive summaries, and technical findings for various audiences.
- Support incident response activities, including containment, eradication, recovery, and lessons learned.
- Maintain forensic methodologies, playbooks, procedures, and tooling to support operational excellence.
- Evaluate emerging forensic technologies, threat trends, and investigative techniques.
- Provide expert testimony, affidavits, or forensic support documentation when required.
- Mentor and provide guidance to less experienced analysts and incident responders.
- Ensure investigative processes align with regulatory, legal, and organizational requirements.
People Manager ResponsibilitiesThis position does not have direct people management responsibilities. However, incumbents may mentor, coach, train, and provide technical leadership to junior analysts and cross-functional team members.
Required Education- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Digital Forensics, Criminal Justice, or a related field; or equivalent work experience.
Required Experience- 6+ years of experience in digital forensics, incident response, cybersecurity investigations, or related information security disciplines.
- Experience conducting enterprise forensic investigations involving Windows, Linux, cloud platforms, email systems, and mobile devices.
- Experience supporting legal, HR, compliance, or regulatory investigations.
Preferred Experience- Experience with eDiscovery and litigation support.
- Experience in highly regulated environments.
- Prior experience leading major incident investigations
Our Benefits - Comprehensive medical, dental, and vision plans
- 401(k) retirement plan with up to 5% company match
- Pre-tax accounts to help streamline eligible expenses
- Company-paid disability and life insurance
- Employee Assistance Program (EAP)
- Career and Leadership Development Programs
- Paid time off, company holidays, and volunteer days
The Next StepReady to join our team? We'd love to hear from you. Fill out an application now and join our talent community to learn about future opportunities.