Why This Role Stands Out
This hybrid role at Triskele Labs offers you the chance to hone your digital forensics skills investigating complex cyber incidents for a reputable Australian firm, contributing to critical incident response and forensic readiness. You'll thrive by leveraging your experience with forensic artifacts and incident lifecycles, working alongside a seasoned team to deliver impactful reports. Apply to join this growing practice and advance your career in a dynamic and collaborative environment.
Quick Overview
Job Description
Triskele Labs is an Australian cyber security firm delivering Managed Detection and Response, Governance Risk and Compliance, Penetration Testing, and Digital Forensics and Incident Response. We hold CREST Cyber Security Incident Response (CSIR) accreditation.
The Digital Forensics TeamWe investigate cyber incidents for clients across Australia, remotely and on site. We establish how an intrusion occurred, what the Threat Actor did, and whether data was accessed or taken. Every matter is backed by a written report that stands up to review by the client, their insurer and their legal counsel.
Work arrives from two directions. Reactive matters are referred by cyber insurers, brokers and legal panel firms, and move at pace. Proactive work is delivered to retainer clients, covering forensic readiness and response planning.
We investigate ransomware and data extortion, business email compromise, insider threat, unauthorised access, data theft, funds redirection, website and endpoint compromise, and internal investigations.
You will work alongside a highly technical and seasoned group of digital forensics practitioners. Everyone carries live matters. Digital Forensics sits alongside Incident Response within the wider DFIR practice.
Experience and Skills- Minimum one year of experience in a digital forensics role.
- Understanding of the incident lifecycle.
- Sound understanding of Windows and Linux forensic artefacts.
- Exposure to Microsoft 365 investigation is advantageous.
- Experience acquiring and handling evidence in a forensically sound manner, including chain of custody.
- Familiarity with Threat Actor tactics, techniques and procedures.
- Business-fluent written English.
- Eligibility to work in Australia.
Experience with the following tools is relevant to the role:
- Forensic suites such as Magnet Axiom, X-Ways Forensics, and Intella are advantageous.
- Experience with acquisition, triage, and analysis tools such as KAPE, EZ Tools, Hayabusa, Velociraptor, Chainsaw, and Volatility.
- Experience investigating Microsoft 365 and Entra ID environments, including the Unified Audit Log, sign-in and audit logs, mailbox rules, delegate access, and OAuth application grants, is advantageous.
- Experience with EDR and SIEM tools such as SentinelOne, CrowdStrike, Microsoft Defender, Carbon Black, Microsoft Sentinel, Elastic, and Rapid7 is advantageous.
SANS and GIAC certifications are a significant bonus, in particular GCFE, GCFA, GCFR and GCIH. Vendor training in Magnet Axiom, X-Ways or Intella is also valued.
Two courses are mandatory for every member of the team: 13Cubed Investigating Windows Endpoints and 13Cubed Investigating Linux Endpoints. If you do not hold these, Triskele Labs will fund and enrol you.
Hours, On-Call and OvertimeParticipation in the on-call rotation is voluntary.
You will work out of hours as matters require, particularly in the opening days of a ransomware or major incident matter. Out of hours work is paid as overtime.
- Join a supportive and driven team where each team member is valued.
- Collaborative and growth-oriented culture with opportunities for career development.
- Hybrid working environment, with some in-office presence expected
- Salary packaging, novated leasing available
- Access to Triskele Labs Discounts and Benefits Platform
- Ongoing training opportunities
Triskele Labs is a place where passion for cybersecurity and client success thrive. Our commitment to "Deliver Awesome" drives us to exceed expectations, making a tangible difference in our clients' security journey.
Similar jobs
- AN
Cyber Risk & Controls Analyst - Flexible Work Options
NewAnglicare
Sydney🇦🇺Hybrid40 minutes agoComplianceContinuous ImprovementRisk ManagementTechnology - VS
TSPV-Cleared Lead Cryptography Security Engineer (Canberra)
NewVertical Scope Group
Canberra, Australian Capital Territory🇦🇺Hybrid40 minutes agoPKITechnology - FT
Senior AI Security Engineer
NewFirmus Technologies
Sydney🇦🇺Hybrid40 minutes agoEncryptionOAuthOWASP+6Technology - IT
Lead Security Engineer
NewIntrepid Travel
Melbourne, Victoria🇦🇺Hybrid40 minutes agoTechnology - CS
Defence Cyber GRC Specialist
NewC4i Solutions
Canberra, Australian Capital Territory🇦🇺Hybrid40 minutes agoTechnology - IT
Lead Security Engineer: Enable Secure Global Growth
NewIntrepid Travel
Melbourne, Victoria🇦🇺Hybrid40 minutes agoTechnology