Digital Forensics Analyst

Rolls-Royce plc

Indianapolis (IN)

Hybrid

USD 99,000 - 160,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) retirement plan with company匹配
Paid Time Off
Tuition reimbursement
Flexible spending account

Job summary

Rolls-Royce plc in Indianapolis, IN is seeking a highly motivated Digital Forensics Analyst to join our Purple Team. This role bridges incident response, threat hunting, digital forensics, adversary emulation, and detection engineering.

The ideal candidate enjoys investigating real‑world attacks, improving detection capabilities, and collaborating with red and blue teams to strengthen security posture. Pay ranges and requirements reflect the role and location, with hybrid work and US citizenship

Qualifications

  • Associate's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2+ years of relevant experience.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2+ years of relevant experience.
  • Master's degree in Cybersecurity, Computer Science, Information Technology, Mathematics.
  • PhD in Cybersecurity, Computer Science, Information Technology, Mathematics.
  • In lieu of a degree must have 6+ years' experience in Cyber Security or Information Technology
  • Must be a US Citizen

Responsibilities

  • Incident Response Lead or support investigations involving malware, ransomware, insider threats, and advanced persistent threats.
  • Perform endpoint, memory, disk, and cloud forensics.
  • Conduct triage activities during security incidents.
  • Coordinate containment, eradication, and recovery efforts.
  • Develop incident response playbooks and procedures.
  • Produce executive and technical incident reports.
  • Threat Hunting Conduct proactive hunts across endpoints, identity, cloud, and network telemetry.
  • Develop hypotheses based on emerging adversary techniques.
  • Analyze attack patterns using MITRE ATT&CK.
  • Identify gaps in visibility and logging.
  • Purple Team Operations Collaborate with red team operators to emulate adversary tactics.
  • Validate detections against simulated attacks.
  • Assist in planning and executing purple team exercises.
  • Measure and improve detection coverage.
  • Map detections and hunting content to ATT&CK techniques.
  • Detection Engineering Develop and tune detections within SIEM and EDR platforms.
  • Reduce false positives while improving fidelity.
  • Create custom analytics, dashboards, and monitoring content.
  • Automate repetitive investigation tasks through scripting.
  • Forensics Acquire and analyze forensic artifacts from: Windows systems; Linux systems; Cloud environments; Containers; Identity providers; Perform timeline reconstruction; Analyze persistence mechanisms.

Skills

Incident Response
Threat Hunting
DFIR
Digital Forensics
Adversary Emulation
MITRE ATT&CK
PowerShell
Python
KQL

Education

Associate's degree in Cybersecurity, Computer Science, Information Technology, Mathematics
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Mathematics
Master's degree in Cybersecurity, Computer Science, Information Technology, Mathematics
PhD in Cybersecurity, Computer Science, Information Technology, Mathematics
6+ years' experience in Cyber Security or Information Technology in lieu of a degree

Tools

FTK Imager
Volatility 3
Velociraptor
Microsoft Sentinel
Splunk Enterprise Security
Elastic Security
Microsoft Defender XDR
CrowdStrike Falcon
SentinelOne
Singularity
Caldera
Prelude Operator
Velociraptor
TheHive
Azure
AWS
Google Cloud

Job description

Job Title: Digital Forensics Analyst

Working Pattern: Fulltime - hybrid

Working location: Indianapolis, IN

Relocation assistance will be provided if applicable

Why Rolls-Royce?

At Rolls-Royce we are proud to be a business that has truly helped to shape the modern world and are committed to always being a force for progress; powering, protecting and connecting people everywhere. By joining Rolls-Royce, you’ll have the opportunity to create world‑class power and propulsion solutions, pushing your problem‑solving and ingenuity, to deliver real impact that puts safety first. You’ll be given responsibility and the opportunity to grow in our high‑performance culture. This is Infinite Potential. And it’s your chance to really shine and contribute to one of the world’s most recognized brands and a beacon for engineering excellence.

Position Summary

We are seeking a highly motivated DFIR Specialist to join our Purple Team. This role bridges offensive and defensive security operations by combining incident response, threat hunting, digital forensics, adversary emulation, and detection engineering. The ideal candidate enjoys investigating real‑world attacks, understanding adversary behavior, improving detection capabilities, and working collaboratively with red and blue teams to strengthen security posture.

What you will be doing
  • Incident Response Lead or support investigations involving malware, ransomware, insider threats, and advanced persistent threats.
  • Perform endpoint, memory, disk, and cloud forensics.
  • Conduct triage activities during security incidents.
  • Coordinate containment, eradication, and recovery efforts.
  • Develop incident response playbooks and procedures.
  • Produce executive and technical incident reports.
  • Threat Hunting Conduct proactive hunts across endpoints, identity, cloud, and network telemetry.
  • Develop hypotheses based on emerging adversary techniques.
  • Analyze attack patterns using frameworks such as MITRE ATT&CK.
  • Identify gaps in visibility and logging.
  • Purple Team Operations Collaborate with red team operators to emulate adversary tactics.
  • Validate detections against simulated attacks.
  • Assist in planning and executing purple team exercises.
  • Measure and improve detection coverage.
  • Map detections and hunting content to ATT&CK techniques.
  • Detection Engineering Develop and tune detections within SIEM and EDR platforms.
  • Reduce false positives while improving fidelity.
  • Create custom analytics, dashboards, and monitoring content.
  • Automate repetitive investigation tasks through scripting.
  • Forensics Acquire and analyze forensic artifacts from: Windows systems; Linux systems; Cloud environments; Containers; Identity providers; Perform timeline reconstruction; Analyze persistence mechanisms.
Basic Qualifications
  • Associate's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience
  • Master's degree in Cybersecurity, Computer Science, Information Technology, Mathematics
  • PhD in Cybersecurity, Computer Science, Information Technology, Mathematics
  • In lieu of a degree must have 6+ years' experience in Cyber Security or Information Technology
  • Must be a US Citizen
Preferred Qualifications
  • 3+ years focused on incident response, threat hunting, or DFIR.
  • 6+ years' experience in Cyber Security or Information Technology
  • Experience with various memory acquisition techniques/tools: FTK Imager; Volatility 3; Velociraptor for remote memory dumps
  • Experience with enterprise SIEM platforms such as: Microsoft Sentinel; Splunk Enterprise Security; Elastic Security
  • Experience with EDR technologies including: Microsoft Defender XDR; CrowdStrike Falcon; SentinelOne; Singularity
  • Familiarity with: Windows Event Logs; Sysmon; KQL; Sigma rules; YARA; PowerShell; Python
  • Memory analysis
  • Malware triage
  • Understanding of: Attack chains; Identity-based attacks; Cloud attack techniques; Detection engineering principles
  • Experience with adversary emulation frameworks.
  • Familiarity with: Caldera; Prelude Operator; Velociraptor
  • TheHive
  • Cloud security investigation experience in: Microsoft Azure; Amazon AWS; Google Cloud
Certifications
  • GIAC certifications such as GCFA, GCIH, GCFE, etc.
  • Microsoft certifications such as SC-200, SC-400, AZ-500
  • CISSP, CCSP

Rolls-Royce is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any protected characteristics. We are committed to providing a respectful and non-discriminatory workplace where individuality is valued and everyone can thrive.

Infinite Potential #CLOLI #CLOPROF

Job Category Information Technology

Pay Range Pay ranges for remote employees are based on the state where the employee resides and may vary from the posted range. $98,566-$160,169-Annually

Location: Indianapolis, IN

Benefits
  • health, dental, vision, disability, life and accidental death & dismemberment insurance
  • a flexible spending account
  • a health savings account
  • a 401(k) retirement savings plan with a company match
  • Employee Assistance Program
  • Paid Time Off
  • certain paid holidays
  • paid parental and family care leave
  • tuition reimbursement
  • a long-term incentive plan

Rolls-Royce pioneers cutting-edge technologies that deliver the cleanest, safest and most competitive solutions to our planet’s vital power needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Digital Forensics Analyst
Digital Forensics Analyst

Rolls-Royce • Indianapolis (IN)

Hybrid
USD 99,000 - 160,000
Health insurance
401(k) match
Paid time off
+1
Digital Forensics Analyst
Digital Forensics Analyst

rollsroyce • United States

Hybrid
USD 90,000 - 130,000
Relocation assistance
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Rolls-Royce plc • Indianapolis (IN)

Hybrid
USD 90,000 - 130,000
Discretionary bonus
Health insurance
401(k) with company match
+5
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Rolls-Royce plc • United States

Hybrid
USD 110,000 - 160,000
Health insurance
Discretionary bonus plan
401(k) with company match
+2
Cyber Security Engineering Manager
Cyber Security Engineering Manager

Rolls-Royce plc • United States

Hybrid
USD 123,000 - 199,000
Health insurance
Dental insurance
Vision insurance
+4
Senior Cyber Security Engineer
Senior Cyber Security Engineer

rollsroyce • United States

Hybrid
USD 110,000 - 160,000
Discretionary bonus
Health insurance
401(k) with company match
Cyber Security Engineering Manager
Cyber Security Engineering Manager

Rolls-Royce plc • Indianapolis (IN)

Hybrid
USD 123,000 - 199,000
Health insurance
401(k) match
Flexible work
+3
Cyber Security Engineer
Cyber Security Engineer

Rolls-Royce plc • Indianapolis (IN)

Hybrid
USD 90,000 - 140,000
Health
Dental
Vision
+6
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Visa Hunt • United States

Hybrid
USD 110,000 - 170,000
Discretionary bonus plan
Digital Governance Solutions Specialist
Digital Governance Solutions Specialist

Rolls-Royce plc • Indianapolis (IN)

Hybrid
USD 123,000 - 199,000
Health insurance
Dental insurance
Vision insurance
+4