- Manage and service NCC Group clients within the Digital Forensics and Incident Response space
- Participate in the analysis and response to security incidents and events
- Support clients through deep technical, detail-oriented analysis
- Manage and mentor team members
- Coordinate cohesive teams during technical engagements
- Respond to emergency incidents, including mitigation and remediation activities
- Maintain composure and effectiveness in client incident-management scenarios
- Provide clients with high-quality technical investigations
- Collaborate on the identification, resolution, and documentation of security incidents
- Conduct intelligence-driven investigative analysis
- Discuss broader technology and security posture with clients to perform Cyber Threat assessments
- Support internal cross-service collaboration, reviews, and efficiency improvements
Requirements
- Ample experience in incident response, security operations or strategic security consulting
- Strong technical knowledge supporting cyber incident response activities
- Understanding of network analysis, host investigation and forensics, and malware analysis
- Significant experience in a Digital Forensics environment
- Experience using a case management system
- Advanced host, network, and cloud system forensics
- Log analysis and malware triage
- Experience evaluating client security controls, architecture, and operations
- Experience crafting scripts and tools using Perl, Python, PowerShell, and Bash
- Experience triaging Windows and Linux hosts
- Experience with network traffic analysis
- Experience with log data analysis
- Ability to explain technical output to non-technical audiences, including executive and C-Suite levels
- Experience working in 24x7 environments and turns
- Ability to lead large-sized projects and take responsibility for analysis and reporting
- Strong interpersonal and communication skills, including report-writing and presentation skills
- Ability to identify attacker tactics, techniques and procedures (TTPs) and develop indicators of compromise
- Relevant professional certification such as CREST CPIA/CRIA/CCNIA/CCHIA or SANS GCFA/GNFA/GCIH preferred
- Strong understanding of common enterprise technologies and configurations, including Azure, M365, AWS, and GCP
Core Competencies
Demonstrates expertise in Digital Forensics and Incident Response, with a strong focus on technical analysis, incident management, and client communication. Capable of leading teams and projects while providing high-quality investigations and security assessments.
Highest-signal resume keywords
- Incident Response
- Digital Forensics
- Malware Analysis
- Python Scripting
- Cloud System Forensics
ATS Optimization Keywords
Hard Skills
- Incident Response
- Digital Forensics
- Network Analysis
- Malware Analysis
- Log Analysis
- Windows Host Triage
- Linux Host Triage
- Cloud Forensics
- Technical Investigations
- Cyber Threat Assessment
Soft Skills
- Interpersonal Skills
- Communication Skills
- Report Writing
- Presentation Skills
- Team Leadership
Certifications & Qualifications
- CREST CPIA
- CREST CRIA
- CREST CCNIA
- CREST CCHIA
- SANS GCFA
- SANS GNFA
- SANS GCIH
Industry Keywords
- Cybersecurity
- Security Operations
- Incident Management
- Technical Engagements
- Emergency Incident Response
Tools & Technologies
- Perl
- Python
- PowerShell
- Bash
- Case Management System
- Azure
- M365
- AWS
- GCP