Haystack
← Back to Jobs
Other
SR

Unix/Linux Infrastructure Forensics & Incident Engineer

Strategic Resources InternationalSan Jose, CA🇺🇸United StatesPosted Sep 16, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
San Jose, CA, United States
Posted
Yesterday
DockerShellAWSOAuthSSOTCP/IPActive DirectoryAzureBashDNSGoogle CloudHTTPHTTPSKubernetesLDAPPerlPowerShellPythonRisk AssessmentTriage

Job Description

Level: Senior/Staff Digital Forensics and IR Engineer Function: Cybersecurity / Digital Forensics
About the Role
Key Responsibilities
Digital Forensics & Incident Response
  • Lead complex digital forensic investigations involving Unix/Linux servers, infrastructure, endpoints, cloud workloads, and enterprise applications.
  • Perform forensic acquisition, preservation, analysis, and documentation of compromised systems.
  • Investigate security incidents including:
    • Account compromise and credential theft
    • Malware and rootkits
    • Privilege escalation
    • Lateral movement
    • Persistence mechanisms
    • Data exfiltration
    • Insider threats
    • Supply-chain compromises
    • Web/application server compromises
    • Cloud infrastructure attacks
  • Analyze system artifacts including filesystem metadata, logs, processes, memory, network connections, authentication records, scheduled tasks, services, SSH activity, shell history, and persistence mechanisms.
  • Conduct timeline analysis and attack reconstruction to determine initial access, attacker activity, persistence, lateral movement, and impact.
  • Develop and maintain forensic playbooks, investigation procedures, and incident response methodologies.
Unix/Linux Infrastructure Forensics
  • Perform deep forensic analysis of Linux/Unix operating systems, including RHEL, CentOS, Ubuntu, Debian, SUSE, and other enterprise distributions.
  • Investigate compromised infrastructure including:
    • Web servers
    • Application servers
    • Database servers
    • DNS/DHCP infrastructure
    • Authentication services
    • Kubernetes/container hosts
    • CI/CD infrastructure
    • Build systems
    • Source-code repositories
    • Network infrastructure
  • Analyze Linux artifacts such as /var/log, /etc, /proc, /sys, systemd, cron, SSH configuration, authentication logs, bash history, package databases, filesystem metadata, and kernel/process information.
  • Investigate rootkits, kernel-level persistence, malicious binaries, unauthorized users, SSH keys, modified system services, and privilege escalation.
  • Perform live-response investigations while minimizing evidence contamination.
Incident Response & Threat Hunting
  • Participate in and lead high-severity incident response investigations across global enterprise infrastructure.
  • Develop hypotheses and conduct proactive threat hunting across Linux, cloud, identity, network, and application environments.
  • Correlate forensic evidence with SIEM, EDR, network telemetry, cloud logs, authentication data, and threat intelligence.
  • Identify attacker TTPs and map activity to frameworks such as MITRE ATT&CK.
  • Develop indicators of compromise (IOCs), behavioral detections, and threat-hunting queries.
  • Work with SOC and detection engineering teams to convert forensic findings into scalable detection capabilities.
Cloud, Containers & Modern Infrastructure
  • Investigate incidents involving AWS, Azure, Google Cloud Platform, and hybrid environments.
  • Perform forensic analysis of cloud workloads, virtual machines, containers, Kubernetes clusters, and cloud control-plane activity.
  • Investigate compromised containers, images, orchestration infrastructure, CI/CD pipelines, and software supply chains.
  • Understand cloud-native logging, identity, networking, storage, and workload telemetry.
Malware & Artifact Analysis
  • Analyze suspicious files, scripts, binaries, and system artifacts.
  • Perform basic static and dynamic analysis of malware and attacker tooling.
  • Identify malicious scripts involving Bash, Python, Perl, PowerShell, and other scripting languages.
  • Collaborate with malware reverse engineers when deeper binary analysis is required.
Investigation Automation & Tooling
  • Develop Python, Bash, or other automation tools to accelerate forensic collection, triage, evidence analysis, and incident response.
  • Build scalable forensic collection and investigation capabilities across thousands of enterprise systems.
  • Automate IOC searches, log analysis, timeline generation, artifact collection, and evidence correlation.
  • Evaluate and integrate modern DFIR and AI-assisted investigation technologies.
Incident Management & Executive Communication
  • Serve as a technical lead during critical security incidents.
  • Coordinate with Security Operations, Infrastructure, Cloud, Networking, IAM, Engineering, Legal, Privacy, and other stakeholders.
  • Produce high-quality forensic investigation reports, root-cause analyses, and remediation recommendations.
  • Clearly communicate technical findings, business impact, risk, and recommended actions to senior leadership.
Required Qualifications
  • 6+ years of professional experience in cybersecurity, digital forensics, incident response, infrastructure security, or a related discipline.
  • Strong hands-on experience with Unix/Linux operating systems and enterprise infrastructure.
  • Proven experience conducting complex computer forensic investigations and security incident response.
  • Strong understanding of Linux internals, filesystems, processes, memory, networking, authentication, and system services.
  • Experience investigating compromised servers and enterprise infrastructure.
  • Strong knowledge of TCP/IP, DNS, HTTP/HTTPS, SSH, TLS, VPN, firewalls, proxies, and network security.
  • Experience with SIEM, EDR/XDR, network security monitoring, vulnerability management, and security telemetry.
  • Experience with scripting/programming languages such as Python, Bash, Perl, or PowerShell.
  • Understanding of MITRE ATT&CK and modern attacker TTPs.
  • Experience working in large-scale, high-availability high-tech or cloud environments.
  • Strong analytical, problem-solving, documentation, and communication skills.
  • Ability to work effectively during high-severity incidents and under time-sensitive conditions.
Preferred Qualifications
  • Experience with AWS, Azure, or Google Cloud Platform forensics.
  • Experience with Kubernetes, Docker, containers, and cloud-native infrastructure.
  • Experience with memory forensics using tools such as Volatility.
  • Experience with forensic platforms and tools such as EnCase, FTK, Autopsy, Sleuth Kit, Velociraptor, KAPE, or equivalent technologies.
  • Experience with Linux forensic frameworks and live-response tooling.
  • Experience with malware analysis and reverse engineering.
  • Knowledge of identity attacks involving Active Directory, LDAP, Kerberos, SSO, OAuth, and cloud identity.
  • Experience investigating software supply-chain and CI/CD compromises.
  • Experience with threat intelligence and adversary tracking.
  • Experience building automated DFIR capabilities at enterprise scale.
  • Experience using AI/ML technologies to enhance threat hunting, forensic analysis, and incident response.
Certifications
Preferred certifications include:
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Examiner (GCFE)
  • GIAC Advanced Incident Response, Threat Hunting & Digital Forensics (GAIA)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Reverse Engineering Malware (GREM)
  • GCFA or equivalent advanced DFIR certification
  • CISSP
Core Competencies
Technical
  • Linux/Unix Forensics
  • Digital Forensics
  • Incident Response
  • Threat Hunting
  • Malware Analysis
  • Network Forensics
  • Cloud Forensics
  • Container/Kubernetes Security
  • Infrastructure Security
  • Identity & Authentication
  • SIEM/EDR/XDR
  • Detection Engineering
  • Security Automation
Leadership
  • Incident leadership
  • Cross-functional collaboration
  • Executive communication
  • Root-cause analysis
  • Risk assessment
  • Crisis management
  • Security investigation strategy

Similar jobs