Incident response researcher/ DFIR
Posted 27 days ago · 0 applicants
Saving, applying or scoring takes a few seconds to set up your free account.
The role in plain words
- At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry)
- Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework)
- Familiarity with cloud infrastructure investigation, specifically Microsoft 365 / Azure AD environments and AWS CloudTrail
- Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis
- Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix), including host-based forensics and experience with analyzing OS artifacts (MFT, Registry, Event Logs, Volatile Memory)
Extracted from the job description · kept up to date automatically
Who this suits
Full job description
Original listing · kept for referenceWe are a leading, innovative and fast-growing cybersecurity consulting company.
With extensive experience supporting organizations (in Israel and globally) during attacks, we are dedicated to being ready when challenges strike.
We are looking for DFIR professional to join our team.
Job Description
* Participate in forensic and incident response investigations, including large-scale sophisticated attacks, conduct log analysis, host and network-based forensics.
* Participate in threat hunting: proactively hunt for targeted attacks and new emerging threats in client’s networks; as well as security assessments and simulations.
* Identify indicators of compromise (IOCs) and tools, tactics, and procedures (TTPs) to help ascertain whether and how breaches have occurred.
* Utilize and develop tools and methodologies to improve the existing investigative and hunting technological stack.
* Collaborate with IT and Security teams during investigations.
* Generate and present a comprehensive and professional report of findings from investigations.
Main Requirements
* At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry).
* Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework).
* Familiarity with cloud infrastructure investigation, specifically **Microsoft 365 / Azure AD** environments and AWS CloudTrail.
* Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis.
* Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix), including host-based forensics and experience with analyzing OS artifacts (MFT, Registry, Event Logs, Volatile Memory).
* Fluency with one or more scripting languages (i.e., Python, PowerShell) for data parsing and automation.
* Problem solver, in-depth thinker with a growth mindset, capable of maintaining composure under pressure during high-stakes crises.
Questions about this role
- This listing did not state a salary. We only show pay when the employer publishes it.
- At least 3 years of relevant experience in DFIR or advanced cyber threat investigation (from military service and/or industry), Demonstrated in-depth understanding of the life cycle of advanced security threats, attack vectors, and variant methods of exploration (MITRE ATT&CK framework), Familiarity with cloud infrastructure investigation, specifically Microsoft 365 / Azure AD environments and AWS CloudTrail, Deep technical understanding of network fundamentals, common Internet protocols, and advanced firewall (FW)/proxy log analysis, Solid understanding of system and security controls on at least two OSs (Windows, Linux / Unix), including host-based forensics and experience with analyzing OS artifacts (MFT, Registry, Event Logs, Volatile Memory)