Digital Forensics Analyst

Triskele Labs

City of Melbourne

On-site

AUD 80,000 - 120,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Hybrid working environment
Salary packaging/novated leasing
Discounts & Benefits Platform access
Ongoing training opportunities
Work‑life balance support

Job summary

Triskele Labs is a cyber security firm providing DFIR services across Australia, with on‑site and remote work. The Digital Forensics Team investigates incidents, establishes intrusion methods, and documents data access or loss with formal reports for clients and insurers.

The role requires 1+ year in digital forensics, knowledge of Windows/Linux artefacts, and exposure to M365 investigations. A hybrid work pattern and ongoing training are available.

Qualifications

  • Minimum one year of experience in a digital forensics role.
  • Understanding of the incident lifecycle.
  • Sound understanding of Windows and Linux forensic artefacts.
  • Exposure to Microsoft 365 investigation is advantageous.
  • Experience acquiring and handling evidence in a forensically sound manner, including chain of custody.
  • Familiarity with Threat Actor tactics, techniques and procedures.
  • Business-fluent written English.
  • Eligibility to work in Australia.

Responsibilities

  • Investigate cyber incidents for clients across Australia, remotely and on site, and establish how an intrusion occurred.
  • Determine what the Threat Actor did and whether data was accessed or taken.
  • Prepare written reports that stand up to review by clients, insurers and legal counsel.
  • Work on reactive matters and proactive retainer work for forensic readiness and response planning.
  • Collaborate with a highly technical DFIR team and handle matters with others in the group.
  • Contribute to ongoing investigations of ransomware, data extortion and insider threats.

Skills

Digital forensics
Incident response
Windows forensics
Linux forensics
Microsoft 365 investigation
Evidence handling & chain of custody
Threat actor TTPs
English communication
Eligibility to work in Australia

Tools

Magnet Axiom
X-Ways Forensics
Intella
KAPE
EZ Tools
Hayabusa
Velociraptor
Chainsaw
Volatility
SentinelOne
CrowdStrike
Microsoft Defender
Carbon Black
Microsoft Sentinel
Elastic
Rapid7

Job description

Triskele Labs is an Australian cyber security firm delivering Managed Detection and Response, Governance Risk and Compliance, Penetration Testing, and Digital Forensics and Incident Response. We hold CREST Cyber Security Incident Response (CSIR) accreditation.

The Digital Forensics Team

We investigate cyber incidents for clients across Australia, remotely and on site. We establish how an intrusion occurred, what the Threat Actor did, and whether data was accessed or taken. Every matter is backed by a written report that stands up to review by the client, their insurer and their legal counsel.

Work arrives from two directions. Reactive matters are referred by cyber insurers, brokers and legal panel firms, and move at pace. Proactive work is delivered to retainer clients, covering forensic readiness and response planning.

We investigate ransomware and data extortion, business email compromise, insider threat, unauthorised access, data theft, funds redirection, website and endpoint compromise, and internal investigations.

You will work alongside a highly technical and seasoned group of digital forensics practitioners. Everyone carries live matters. Digital Forensics sits alongside Incident Response within the wider DFIR practice.

Experience and Skills
  • Minimum one year of experience in a digital forensics role.
  • Understanding of the incident lifecycle.
  • Sound understanding of Windows and Linux forensic artefacts.
  • Exposure to Microsoft 365 investigation is advantageous.
  • Experience acquiring and handling evidence in a forensically sound manner, including chain of custody.
  • Familiarity with Threat Actor tactics, techniques and procedures.
  • Business-fluent written English.
  • Eligibility to work in Australia.
Tools

Experience with the following tools is relevant to the role:

  • Forensic suites such as Magnet Axiom, X-Ways Forensics, and Intella are advantageous.
  • Experience with acquisition, triage, and analysis tools such as KAPE, EZ Tools, Hayabusa, Velociraptor, Chainsaw, and Volatility.
  • Experience investigating Microsoft 365 and Entra ID environments, including the Unified Audit Log, sign-in and audit logs, mailbox rules, delegate access, and OAuth application grants, is advantageous.
  • Experience with EDR and SIEM tools such as SentinelOne, CrowdStrike, Microsoft Defender, Carbon Black, Microsoft Sentinel, Elastic, and Rapid7 is advantageous.
Training and Certifications

SANS and GIAC certifications are a significant bonus, in particular GCFE, GCFA, GCFR and GCIH. Vendor training in Magnet Axiom, X-Ways or Intella is also valued.

Two courses are mandatory for every member of the team: 13Cubed Investigating Windows Endpoints and 13Cubed Investigating Linux Endpoints. If you do not hold these, Triskele Labs will fund and enrol you.

Hours, On-Call and Overtime

Participation in the on-call rotation is voluntary.

You will work out of hours as matters require, particularly in the opening days of a ransomware or major incident matter. Out of hours work is paid as overtime.

  • Join a supportive and driven team where each team member is valued.
  • Collaborative and growth-oriented culture with opportunities for career development.
  • Hybrid working environment, with some in-office presence expected
  • Salary packaging, novated leasing available
  • Access to Triskele Labs Discounts and Benefits Platform
  • Ongoing training opportunities
Why Triskele Labs?

Triskele Labs is a place where passion for cybersecurity and client success thrive. Our commitment to "Deliver Awesome" drives us to exceed expectations, making a tangible difference in our clients’ security journey.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Digital Forensics Analyst – DFIR & Incident Response
Hybrid Digital Forensics Analyst – DFIR & Incident Response

Triskele Labs • City of Melbourne

Hybrid
AUD 80,000 - 120,000
Hybrid working environment
Salary packaging/novated leasing
Discounts & Benefits Platform access
+2
Hybrid Digital Forensics Analyst - Dfir & Incident Response
Hybrid Digital Forensics Analyst - Dfir & Incident Response

Triskele Labs • Australia

Hybrid
AUD 70,000 - 110,000
Hybrid work pattern
Ongoing training
Security Engineer at Triskele Labs Australia
Security Engineer at Triskele Labs Australia

Triskele Labs • Australia

On-site
AUD 90,000 - 120,000
Collaborate with C-Suite executives
Career advancement opportunities
Modern office in Melbourne CBD
+1
Offensive Security Consultant
Offensive Security Consultant

Triskele Labs • City of Melbourne

On-site
AUD 120,000 - 160,000
Training and development
Employee Assistance Program (EAP)
Team social functions
+2
Level 1 Security Analyst
Level 1 Security Analyst

Triskele Labs • City of Melbourne

On-site
AUD 60,000 - 78,000
Senior Cybersecurity Incident Responder
Senior Cybersecurity Incident Responder

Datacom • Australia

Hybrid
AUD 100,000 - 130,000
Social events
Chill-out spaces
Remote working
+2
Digital Forensics & Incident Response Specialist (DFIR)
Digital Forensics & Incident Response Specialist (DFIR)

Talenza • Sydney

Hybrid
AUD 140,000 - 190,000
Hybrid working environment
Ongoing professional development
Career progression opportunities
Principal Analyst
Principal Analyst

Infotrust • Sydney

Hybrid
AUD 180,000 - 240,000
Senior Technical Customer Success Manager
Senior Technical Customer Success Manager

Triskele Labs • City of Melbourne

On-site
AUD 120,000 - 160,000
Senior DFIR Lead & Investigations Strategist
Senior DFIR Lead & Investigations Strategist

Infotrust • Sydney

Hybrid
AUD 180,000 - 240,000