Cybersecurity Analyst - Forensics/Risk

Gravity IT Resources

Salt Lake City (UT)

Hybrid

USD 120,000 - 150,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gravity IT Resources is seeking a Cyber Analyst- Forensics/Insider Threat to support insider risk, DLP, and digital forensics within a security operations environment. The role blends hands-on investigation with detection engineering and cross-team collaboration.

The position requires 2+ years of hands-on cybersecurity experience, including digital forensics and SIEM/EDR skills, and offers a hybrid work arrangement in Salt Lake City.

Qualifications

  • 2+ years of progressive hands-on cybersecurity experience with forensics/investigations.
  • Experience with forensic evidence collection and investigation workflows.
  • Experience supporting insider risk cases and handling sensitive data with discretion.
  • Experience triaging and resolving DLP incidents.

Responsibilities

  • Serve as a technical SME across SIEM, EDR, and digital forensics platforms.
  • Build and improve detections/monitoring use cases, insider risk procedures, playbooks, and documentation.
  • Partner with security engineering/architecture to enhance monitoring and workflows.
  • Mentor teammates on incident response practices and tool usage.
  • Respond to insider risk and DLP incidents as escalation point for high-priority cases.
  • Conduct digital forensic collections, preservation, and analysis for internal investigations.
  • Tune alerting to reduce false positives and improve fidelity.
  • Support other security operations initiatives as needed.

Skills

Cybersecurity experience
Digital forensics
Insider risk
DLP incidents
Forensics tools
SIEM alert logic
Attack techniques knowledge
Technical communication

Tools

SIEM platforms
EDR platforms
Digital forensics tools

Job description

Job Description: Cyber Analyst- Forensics/Insider Threat

Position Type: Direct Hire

Compensation: $120,000-150,000

Location: Hybrid- Salt Lake City

Experience Level: 5+ years experience

Overview

A large, multi-site organization is seeking a Cybersecurity Engineer to support and mature insider risk, data loss prevention (DLP), and digital forensics capabilities within a security operations environment. This role blends hands-on investigation work with detection engineering, documentation, and cross-team collaboration.

What you’ll do
  • Serve as a technical SME across security operations tooling and processes, including SIEM, EDR, and digital forensics platforms.
  • Build and improve detections/monitoring use cases, insider risk procedures, playbooks, and technical documentation.
  • Partner with security engineering/architecture stakeholders to enhance monitoring, alerting, and operational workflows.
  • Mentor teammates on incident response practices, investigation methods, and tool usage.
  • Respond to insider risk and DLP-related incidents, acting as an escalation point for complex or high-priority cases.
  • Conduct digital forensic collections, preservation, and analysis to support internal investigations.
  • Tune alerting and provide continuous improvement feedback to reduce false positives and improve fidelity.
  • Support other security operations initiatives as needed.
What you bring (required)
  • 2+ years of progressive hands-on experience in cybersecurity, with meaningful exposure to digital forensics and/or investigations (or an equivalent combination of education and experience).
  • Experience with forensic evidence collection and investigation workflows.
  • Experience supporting insider risk cases and handling sensitive investigation data with discretion.
  • Experience triaging and resolving DLP incidents.
  • Hands-on experience with one or more digital forensics tools/platforms (commercial or widely adopted industry tools).
  • Hands-on SIEM experience, including building or refining alert logic/use cases (not only monitoring dashboards).
  • Solid understanding of common attack techniques and phases of intrusion (recon ? access ? escalation ? persistence ? lateral movement ? cleanup/anti-forensics).
  • Strong written and verbal communication skills; able to produce clear technical documentation.
Nice to have
  • Networking fundamentals and traffic analysis familiarity (proxies, firewalls, routing/switching concepts).
  • Windows and Linux/UNIX administration fundamentals.
  • Threat hunting experience or methodology exposure.
  • Forensics or incident response certifications/training (or equivalent practical experience).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Forensics & Insider Risk Analyst - Hybrid
Cyber Forensics & Insider Risk Analyst - Hybrid

Gravity IT Resources • Salt Lake City (UT)

Hybrid
USD 120,000 - 150,000
Senior Cyber Security Specialist I - Insider Threat Analysis
Senior Cyber Security Specialist I - Insider Threat Analysis

Walgreens • United States

Hybrid
USD 98,000 - 158,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Re:Sources • Chicago (IL)

On-site
USD 100,000 - 120,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Re:Sources • Atlanta (GA)

On-site
USD 100,000 - 120,000
Senior Associate, Information Security - Forensics
Senior Associate, Information Security - Forensics

Publicis Re:Sources • New York (NY)

On-site
USD 100,000 - 120,000
Cyber Defense Forensics Lead
Cyber Defense Forensics Lead

Tyto Athene, LLC • Ashburn (VA)

On-site
USD 120,000 - 150,000
Cyber Security Analyst 5457
Cyber Security Analyst 5457

Tier4 Group • Wixom (MI)

On-site
USD 120,000 - 160,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
External Job Posting Title Digital Forensic Analyst
External Job Posting Title Digital Forensic Analyst

Peraton • Chantilly (VA)

On-site
USD 176,000 - 282,000
Heavily subsidized employee benefits
25 days of PTO
Bonus plan eligibility
Cybersecurity Analyst
Cybersecurity Analyst

Quantum Integrators Group • West Windsor (NJ)

Hybrid
USD 80,000 - 100,000
Competitive salary
Performance-based bonuses
Learning and professional development opportunities
+2