JOB TITLE: DFIR Associate Manager (Digital Forensics & Incident Response)
WORK SETUP: Hybrid in Cubao
WORK SHIFT: Shifting
Salary budget: Confidential (Will be discussed during the Job Offer)
What You'll Do:
As a DFIR Associate Manager, you'll lead and support the investigation of high-impact cybersecurity incidents while helping clients improve their cyber resilience.
Your Key Responsibilities:
- Lead and support response efforts during critical cybersecurity incidents.
- Investigate ransomware attacks, malware infections, insider threats, data breaches, business email compromise (BEC), DDoS attacks, and advanced persistent threats (APTs).
- Conduct detailed forensic investigations to determine the scope, impact, root cause, and remediation requirements.
- Perform digital forensic analysis of endpoints, servers, cloud environments, and mobile devices.
- Work closely with security teams, business stakeholders, and management to coordinate response activities and communicate findings.
- Develop and enhance incident response playbooks, procedures, and documentation.
- Conduct proactive threat hunting and security investigations.
- Help optimize security tools and detection capabilities.
- Mentor team members and deliver knowledge-sharing sessions on incident response and forensic best practices.
What We're Looking For
Required Experience & Skills:
- Minimum 5 years of Digital Forensics and Incident Response (DFIR) experience
Strong understanding of:
- Incident Response Lifecycle (Investigation, Containment, Eradication, Recovery)
- Digital Forensics Methodologies
- MITRE ATT&CK Framework
- Cyber Threat Investigation and Analysis
- Windows and Linux Operating Systems
- Networking and Security Fundamentals
Hands-on experience with:
- Memory, Disk, and Network Forensics
- Malware Analysis (Static and/or Dynamic)
- SIEM, Endpoint Security, Network Security, and Email Security Technologies
Experience with forensic tools such as:
- FTK
- Autopsy
- Volatility
- EnCase
- Magnet AXIOM
- SIFT
- REMnux
- Similar DFIR platforms
Nice-to-Have Skills
- Mobile Forensics (Android/iOS)
- Threat Intelligence and Threat Hunting
- Scripting and Automation using Python or PowerShell
- Industry certifications such as: GCFA, GCFE, GNFA, Other GIAC certifications
Work Setup
- Hybrid work arrangement
- Cubao office
- Amenable to possible shifting schedules
Accelerate Your Cybersecurity Career
At Accenture, continuous learning is part of the culture. As a member of our Cyber Resilience, Response, and Recovery (CRRR) team, you'll have opportunities to pursue advanced certifications, including:
- OSCP, OSDA
- CDSA, CPTS
- GCFA, GCFE, GMON, GCIH, GREM
- CRTO, CRTL
Certification sponsorship and upskilling opportunities are available to support your growth and career advancement.
Additional Information:
- Minimum 5 years of experience is required
- Open to applicants who are currently in the Philippines and already have the right to live and work in this country are eligible for this role