Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
San Jose, CA, United States
Posted
Yesterday
DockerShellAWSOAuthSSOTCP/IPActive DirectoryAzureBashDNSGoogle CloudHTTPHTTPSKubernetesLDAPPerlPowerShellPythonRisk AssessmentTriage
Job Description
Level: Senior/Staff Digital Forensics and IR Engineer Function: Cybersecurity / Digital Forensics
About the Role
Key Responsibilities
Digital Forensics & Incident Response
Preferred certifications include:
Technical
About the Role
Key Responsibilities
Digital Forensics & Incident Response
- Lead complex digital forensic investigations involving Unix/Linux servers, infrastructure, endpoints, cloud workloads, and enterprise applications.
- Perform forensic acquisition, preservation, analysis, and documentation of compromised systems.
- Investigate security incidents including:
- Account compromise and credential theft
- Malware and rootkits
- Privilege escalation
- Lateral movement
- Persistence mechanisms
- Data exfiltration
- Insider threats
- Supply-chain compromises
- Web/application server compromises
- Cloud infrastructure attacks
- Analyze system artifacts including filesystem metadata, logs, processes, memory, network connections, authentication records, scheduled tasks, services, SSH activity, shell history, and persistence mechanisms.
- Conduct timeline analysis and attack reconstruction to determine initial access, attacker activity, persistence, lateral movement, and impact.
- Develop and maintain forensic playbooks, investigation procedures, and incident response methodologies.
- Perform deep forensic analysis of Linux/Unix operating systems, including RHEL, CentOS, Ubuntu, Debian, SUSE, and other enterprise distributions.
- Investigate compromised infrastructure including:
- Web servers
- Application servers
- Database servers
- DNS/DHCP infrastructure
- Authentication services
- Kubernetes/container hosts
- CI/CD infrastructure
- Build systems
- Source-code repositories
- Network infrastructure
- Analyze Linux artifacts such as /var/log, /etc, /proc, /sys, systemd, cron, SSH configuration, authentication logs, bash history, package databases, filesystem metadata, and kernel/process information.
- Investigate rootkits, kernel-level persistence, malicious binaries, unauthorized users, SSH keys, modified system services, and privilege escalation.
- Perform live-response investigations while minimizing evidence contamination.
- Participate in and lead high-severity incident response investigations across global enterprise infrastructure.
- Develop hypotheses and conduct proactive threat hunting across Linux, cloud, identity, network, and application environments.
- Correlate forensic evidence with SIEM, EDR, network telemetry, cloud logs, authentication data, and threat intelligence.
- Identify attacker TTPs and map activity to frameworks such as MITRE ATT&CK.
- Develop indicators of compromise (IOCs), behavioral detections, and threat-hunting queries.
- Work with SOC and detection engineering teams to convert forensic findings into scalable detection capabilities.
- Investigate incidents involving AWS, Azure, Google Cloud Platform, and hybrid environments.
- Perform forensic analysis of cloud workloads, virtual machines, containers, Kubernetes clusters, and cloud control-plane activity.
- Investigate compromised containers, images, orchestration infrastructure, CI/CD pipelines, and software supply chains.
- Understand cloud-native logging, identity, networking, storage, and workload telemetry.
- Analyze suspicious files, scripts, binaries, and system artifacts.
- Perform basic static and dynamic analysis of malware and attacker tooling.
- Identify malicious scripts involving Bash, Python, Perl, PowerShell, and other scripting languages.
- Collaborate with malware reverse engineers when deeper binary analysis is required.
- Develop Python, Bash, or other automation tools to accelerate forensic collection, triage, evidence analysis, and incident response.
- Build scalable forensic collection and investigation capabilities across thousands of enterprise systems.
- Automate IOC searches, log analysis, timeline generation, artifact collection, and evidence correlation.
- Evaluate and integrate modern DFIR and AI-assisted investigation technologies.
- Serve as a technical lead during critical security incidents.
- Coordinate with Security Operations, Infrastructure, Cloud, Networking, IAM, Engineering, Legal, Privacy, and other stakeholders.
- Produce high-quality forensic investigation reports, root-cause analyses, and remediation recommendations.
- Clearly communicate technical findings, business impact, risk, and recommended actions to senior leadership.
- 6+ years of professional experience in cybersecurity, digital forensics, incident response, infrastructure security, or a related discipline.
- Strong hands-on experience with Unix/Linux operating systems and enterprise infrastructure.
- Proven experience conducting complex computer forensic investigations and security incident response.
- Strong understanding of Linux internals, filesystems, processes, memory, networking, authentication, and system services.
- Experience investigating compromised servers and enterprise infrastructure.
- Strong knowledge of TCP/IP, DNS, HTTP/HTTPS, SSH, TLS, VPN, firewalls, proxies, and network security.
- Experience with SIEM, EDR/XDR, network security monitoring, vulnerability management, and security telemetry.
- Experience with scripting/programming languages such as Python, Bash, Perl, or PowerShell.
- Understanding of MITRE ATT&CK and modern attacker TTPs.
- Experience working in large-scale, high-availability high-tech or cloud environments.
- Strong analytical, problem-solving, documentation, and communication skills.
- Ability to work effectively during high-severity incidents and under time-sensitive conditions.
- Experience with AWS, Azure, or Google Cloud Platform forensics.
- Experience with Kubernetes, Docker, containers, and cloud-native infrastructure.
- Experience with memory forensics using tools such as Volatility.
- Experience with forensic platforms and tools such as EnCase, FTK, Autopsy, Sleuth Kit, Velociraptor, KAPE, or equivalent technologies.
- Experience with Linux forensic frameworks and live-response tooling.
- Experience with malware analysis and reverse engineering.
- Knowledge of identity attacks involving Active Directory, LDAP, Kerberos, SSO, OAuth, and cloud identity.
- Experience investigating software supply-chain and CI/CD compromises.
- Experience with threat intelligence and adversary tracking.
- Experience building automated DFIR capabilities at enterprise scale.
- Experience using AI/ML technologies to enhance threat hunting, forensic analysis, and incident response.
Preferred certifications include:
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Examiner (GCFE)
- GIAC Advanced Incident Response, Threat Hunting & Digital Forensics (GAIA)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Reverse Engineering Malware (GREM)
- GCFA or equivalent advanced DFIR certification
- CISSP
Technical
- Linux/Unix Forensics
- Digital Forensics
- Incident Response
- Threat Hunting
- Malware Analysis
- Network Forensics
- Cloud Forensics
- Container/Kubernetes Security
- Infrastructure Security
- Identity & Authentication
- SIEM/EDR/XDR
- Detection Engineering
- Security Automation
- Incident leadership
- Cross-functional collaboration
- Executive communication
- Root-cause analysis
- Risk assessment
- Crisis management
- Security investigation strategy
Similar jobs
- CI
Office Intern
NewCharles IT
Stamford, Connecticut🇺🇸On-siteYesterdayComplianceScheduling - CD
Treatment Coordinator
NewCommonwealth Dentistry
Suffolk, Virginia🇺🇸On-siteYesterdayAccounts ReceivableMicrosoft OfficeScheduling - EE
Safety Coordinator - Houston, TX
NewEnterprise Electrical
Houston, Texas🇺🇸On-siteYesterdayComplianceConstruction ManagementContinuous Improvement+4 - IP
Part Time Clubhouse Monitor Manufactured Housing Community
NewInvestment Property Group
Huntington Beach, California🇺🇸On-siteYesterdaySOAPEmployee Engagement - GA
Geotechnical Field Professional
NewGeo-Technology Associates Inc.
Alliance, Ohio🇺🇸On-siteYesterdayCompliance - CW
Second Shift Compliance Manager
NewCity Wide Facility Solutions
Ontario, California🇺🇸On-siteYesterdayCRMCompliance