Tier 3 Digital Forensics and Incident Response Analyst

Tyto Athene

$155K — $165K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s Degree or equivalent experience
  • 8+ years of overall experience, 3+ years in digital forensics
  • Proficiency with forensic tools like Encase and Wireshark
  • Strong background in computer forensics and networking
  • Experience in security operations and incident response
  • Familiarity with Python and regular expressions
  • Knowledge of Windows and Linux command lines

Responsibilities

  • Lead teams to analyze high-priority cybersecurity incidents
  • Utilize security tools for analyzing and triaging alerts
  • Monitor customer environments for adversarial activity
  • Use advanced tools for identifying incidents’ root causes
  • Collaborate with cyber threat hunting and intelligence teams
  • Act as primary contact with law enforcement and external parties
  • Conduct post-incident analysis to identify improvement opportunities
  • Develop detection rules to enhance security monitoring
  • Document findings and maintain intake reports in IMS
  • Research emerging threats for prevention and mitigation
  • Assist in developing operational improvements for the SOC
  • Provide mentorship to lower-tier SOC Analysts

Benefits

  • Health/Dental/Vision coverage
  • 401(k) match
  • Paid Time Off
  • Short/Long Term Disability and Life Insurance
  • Referral bonuses
  • Professional development reimbursement
  • Parental leave
Full Job Description
Description

Tyto Athene is searching for a Tier 3 Digital Forensics and Incident Response Analyst. You will play a critical role in conducting in-depth analyses and responding to incidents from cyber threats facing our clients. In addition to being our initial point of contact for end users, you will serve as the escalation point for other analysts, helping guide them through more complex and high-priority incidents.

 

Responsibilities:

  • Lead cross-functional teams to perform in-depth analysis and investigation of high-priority cybersecurity incidents
  • Utilize security tools to analyze, investigate, and triage security alerts
  • Coordinate the monitoring of our customers environments, including cloud and SaaS solutions for evidence of adversarial activity
  • Utilize advanced tools, such as digital forensics or malware analysis capabilities, to identify incidents’ root causes, scope, and impact
  • Collaborate with cyber threat hunting and cyber threat intelligence teams
  • Serve as the primary incident point of contact with law enforcement, third-party vendors, and other external parties
  • Conduct post-incident analysis and lessons learned to identify improvement opportunities
  • Develop or tune detection rules or signatures to improve the effectiveness of security monitoring and collaborate with engineering teams to implement them
  • Accurately document triage findings, and intake reports of external cybersecurity events from SOC customers via phone or email in the SOCs Incident Management System(IMS)
  • Learn new open and closed-source investigative techniques
  • Perform research on emerging threats and vulnerabilities to aid their prevention and mitigation
  • Assist in developing and implementing initiatives that will enhance the SOC’s performance (e.g., SOPs, playbooks, capability deployments)
  • Escalate SOC performance issues or risks to management
  • Provide guidance and mentorship to Tier 1 and Tier 2 SOC Analysts to enhance their skills and capabilities
Qualifications Required:
  • Bachelor’s Degree or an equivalent combination of formal education and experience
  • Minimum of eight years of experience and six (6) years of general experience and three (3) years of relevant functional experience performing digital forensics
  • Demonstrated competency in forensic tools, such Encase and Wireshark
  • Core Competencies in computer forensics, computer networking and operating systems.
  • Experience with operational security, including security operations center (SOC), incident response, malware analysis, or IDS and IPS analyses
  • Understanding of scripting languages such as Python and regular expressions
  • Knowledge of Windows and Linux, and command lines

Desired:

  • One of the following certifications: CISSP - Certified Information Systems Security Professional, GCFA - GIAC Certified Forensic Analyst, GCFE - GIAC Certified Forensic Examiner, GREM - GIAC Reverse Engineering Malware

Location:

  • This is a remote position with occassional travel to the client site as needed

Clearance: 

  • TS/SCI Clearance required

Compensation:

  • Compensation is unique to each candidate and relative to the skills and experience they bring to the position. The salary range for this position is typically between $155,000-$165,000. This does not guarantee a specific salary as compensation is based upon multiple factors such as education, experience, certifications, and other requirements, and may fall outside of the above-stated range.

Benefits:

  •  Highlights of our benefits include Health/Dental/Vision, 401(k) match, Paid Time Off, STD/LTD/Life Insurance, Referral Bonuses, professional development reimbursement, and parental leave.

 

Similar Jobs

More Jobs at Tyto Athene

More Information Technology Jobs

Find similar Tier 3 Digital Forensics and Incident Response Analyst jobs: