Cybersecurity Engineer- Forensics/Risk

Gravity IT Resources

Salt Lake City (UT)

Hybrid

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gravity IT Resources is seeking a Cyber Analyst-Forensics/Insider Threat to join a hybrid team in Salt Lake City. The role focuses on insider risk, DLP, and digital forensics within a security operations environment, blending hands-on investigations with detection engineering and cross-team collaboration.

2+ years of cybersecurity experience, strong SIEM/EDR background, and ability to mentor others are required. Direct hire with compensation of $120,000–$150,000 and hybrid work options.

Qualifications

  • 2+ years of hands-on cybersecurity experience with forensics or investigations.
  • Experience with forensic evidence collection and investigation workflows.
  • Experience supporting insider risk cases and handling sensitive data.
  • Proficient with DLP incident triage.
  • Hands-on SIEM and EDR experience; able to refine alert logic.
  • Strong written and verbal communication; create technical docs.

Responsibilities

  • Serve as a technical SME across security operations tooling and processes, including SIEM, EDR, and digital forensics platforms.
  • Build and improve detections/monitoring use cases, insider risk procedures, playbooks, and technical documentation.
  • Partner with security engineering/architecture to enhance monitoring, alerting, and workflows.
  • Mentor teammates on incident response practices and tool usage.
  • Respond to insider risk and DLP-related incidents as escalation point.
  • Conduct digital forensic collections, preservation, and analysis for internal investigations.
  • Tune alerting and provide continuous improvement to reduce false positives.
  • Support other security operations initiatives as needed.

Skills

Digital forensics
Insider risk
DLP investigations
SIEM
EDR
Incident response
Investigations workflow
Technical documentation

Job description

Job Description

Cyber Analyst- Forensics/Insider Threat


Position Type: Direct Hire


Compensation: $120,000-150,000


Location: Hybrid- Salt Lake City


Experience Level: 5+ years experience



Overview

A large, multi-site organization is seeking a Cybersecurity Engineer to support and matureinsider risk,data loss prevention (DLP), anddigital forensicscapabilities within a security operations environment. This role blends hands-on investigation work with detection engineering, documentation, and cross-team collaboration.



What you’ll do


  • Serve as a technical SME across security operations tooling and processes, including SIEM, EDR, and digital forensics platforms.

  • Build and improve detections/monitoring use cases, insider risk procedures, playbooks, and technical documentation.

  • Partner with security engineering/architecture stakeholders to enhance monitoring, alerting, and operational workflows.

  • Mentor teammates on incident response practices, investigation methods, and tool usage.

  • Respond to insider risk and DLP-related incidents, acting as an escalation point for complex or high-priority cases.

  • Conduct digital forensic collections, preservation, and analysis to support internal investigations.

  • Tune alerting and provide continuous improvement feedback to reduce false positives and improve fidelity.

  • Support other security operations initiatives as needed.



What you bring (required)


  • 2+ years of progressive hands-on experience in cybersecurity, with meaningful exposure to digital forensics and/or investigations (or an equivalent combination of education and experience).

  • Experience with forensic evidence collection and investigation workflows.

  • Experience supporting insider risk cases and handling sensitive investigation data with discretion.

  • Experience triaging and resolving DLP incidents.

  • Hands-on experience with one or more digital forensics tools/platforms (commercial or widely adopted industry tools).

  • Hands-on SIEM experience, including building or refining alert logic/use cases (not only monitoring dashboards).

  • Solid understanding of common attack techniques and phases of intrusion (recon? access? escalation? persistence? lateral movement? cleanup/anti-forensics).

  • Strong written and verbal communication skills; able to produce clear technical documentation.



Nice to have


  • Networking fundamentals and traffic analysis familiarity (proxies, firewalls, routing/switching concepts).

  • Windows and Linux/UNIX administration fundamentals.

  • Scripting/automation (Python, PowerShell, Bash, JavaScript, etc.).

  • Threat hunting experience or methodology exposure.

  • Forensics or incident response certifications/training (or equivalent practical experience).



Equal Employment Opportunity Statement
Gravity IT Resources is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees and applicants. We do not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, veteran status, or any other legally protected characteristic. All employment decisions are based on qualifications, merit, and business needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Analyst - Forensics/Risk
Cybersecurity Analyst - Forensics/Risk

Gravity IT Resources • Salt Lake City (UT)

Hybrid
USD 120,000 - 150,000
Hybrid Cyber Forensics & Insider Risk Engineer
Hybrid Cyber Forensics & Insider Risk Engineer

Gravity IT Resources • Salt Lake City (UT)

Hybrid
USD 120,000 - 150,000
Cyber Forensics & Insider Risk Analyst - Hybrid
Cyber Forensics & Insider Risk Analyst - Hybrid

Gravity IT Resources • Salt Lake City (UT)

Hybrid
USD 120,000 - 150,000
Sr. Cyber Defense Analyst
Sr. Cyber Defense Analyst

Patriot Talent Solutions • United States

On-site
USD 120,000 - 190,000
Senior Cybersecurity Analyst #3344
Senior Cybersecurity Analyst #3344

Genius Road, LLC • Austin (TX)

Hybrid
USD 150,000 - 190,000
Certified Women’s Business Enterprise
Equal Opportunity Employer
Digital Forensics Senior Analyst at Gulfstream Savannah, GA
Digital Forensics Senior Analyst at Gulfstream Savannah, GA

Gulfstream • Savannah (GA)

On-site
USD 90,000 - 120,000
Digital Forensics Lead
Digital Forensics Lead

Agile Defense • Reston (VA)

On-site
USD 110,000 - 150,000
Security Automation Engineer
Security Automation Engineer

Uvcyber • Portland (OR)

On-site
USD 120,000 - 150,000
401(k) with employer match
Medical, Dental, and Vision insurance
Discretionary Time Off program
+2
Incident Response Manager
Incident Response Manager

Crowe LLP • United States

On-site
USD 120,000 - 150,000
Director, DFIR (Remote)
Director, DFIR (Remote)

Surefire Cyber Inc. • Northern (KY)

Hybrid
USD 150,000 - 190,000
Competitive pay
PTO
Medical & dental coverage
+2