Digital Forensics Analyst

rollsroyce

United States

Hybrid

USD 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Relocation assistance

Job summary

Rolls-Royce is seeking a highly motivated DFIR Specialist to join our Purple Team, bridging offensive and defensive security through incident response, threat hunting, digital forensics, adversary emulation, and detection engineering.

The ideal candidate enjoys investigating real-world attacks, understanding adversary behavior, improving detections, and collaborating with red and blue teams to strengthen security posture in a hybrid Indianapolis environment.

Qualifications

  • Associate's/Bachelor's/Master's/PhD in cybersecurity, CS, IT or math with related experience.
  • Alternatives: 6+ years' experience in cyber security/IT in lieu of a degree.

Responsibilities

  • Lead or support incident response investigations (malware, ransomware, insider threats, APTs).
  • Perform forensic analysis of Windows, Linux, cloud, and container environments.
  • Conduct threat hunting across endpoints, identity, cloud, and network telemetry.
  • Collaborate with red/blue teams to emulate adversary tactics and validate detections.
  • Develop and tune detections in SIEM/EDR platforms and create analytics dashboards.

Skills

Incident response
Threat hunting
Digital forensics
Memory analysis
Python
PowerShell

Education

Associate's degree in Cybersecurity/CS/IT/Math
Bachelor's degree in Cybersecurity/CS/IT/Math
Master's degree in Cybersecurity/CS/IT/Math
PhD in Cybersecurity/CS/IT/Math
6+ years' experience in lieu of a degree

Tools

FTK Imager
Volatility 3
Velociraptor
Microsoft Sentinel
Splunk Enterprise Security
Elastic Security
Microsoft Defender XDR
CrowdStrike Falcon
SentinelOne Singularity

Job description

Job Description

Job Title: Digital Forensics Analyst

Working Pattern: Fulltime - hybrid

Working location: Indianapolis, IN

Relocation assistance will be provided if applicable

Why Rolls-Royce?

At Rolls-Royce we are proud to be a business that has truly helped to shape the modern world and are committed to always being a force for progress; powering, protecting and connecting people everywhere.

By joining Rolls-Royce, you'll have the opportunity to create world-class power and propulsion solutions, pushing your problem-solving and ingenuity, to deliver real impact that puts safety first.

You'll be given responsibility and the opportunity to grow in our high-performance culture. This is Infinite Potential . And it's your chance to really shine and contribute to one of the world's most recognized brands and a beacon for engineering excellence.

Position Summary:

We are seeking a highly motivated DFIR Specialist to join our Purple Team. This role bridges offensive and defensive security operations by combining incident response, threat hunting, digital forensics, adversary emulation, and detection engineering.

The ideal candidate enjoys investigating real-world attacks, understanding adversary behavior, improving detection capabilities, and working collaboratively with red and blue teams to strengthen security posture.

What you will be doing :
  • Incident Response
    • Lead or support investigations involving malware, ransomware, insider threats, and advanced persistent threats.
    • Perform endpoint, memory, disk, and cloud forensics.
    • Conduct triage activities during security incidents.
    • Coordinate containment, eradication, and recovery efforts.
    • Develop incident response playbooks and procedures.
    • Produce executive and technical incident reports.
  • Threat Hunting
    • Conduct proactive hunts across endpoints, identity, cloud, and network telemetry.
    • Develop hypotheses based on emerging adversary techniques.
    • Analyze attack patterns using frameworks such as MITRE ATT&CK.
    • Identify gaps in visibility and logging.
  • Purple Team Operations
    • Collaborate with red team operators to emulate adversary tactics.
    • Validate detections against simulated attacks.
    • Assist in planning and executing purple team exercises.
    • Measure and improve detection coverage.
    • Map detections and hunting content to ATT&CK techniques.
  • Detection Engineering
    • Develop and tune detections within SIEM and EDR platforms.
    • Reduce false positives while improving fidelity.
    • Create custom analytics, dashboards, and monitoring content.
    • Automate repetitive investigation tasks through scripting.
  • Forensics
    • Acquire and analyze forensic artifacts from: Windows systems
    • Linux systems
    • Cloud environments
    • Containers
    • Identity providers
    • Perform timeline reconstruction.
    • Analyze persistence mechanisms.
Basic Qualifications:
  • Associate's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;
  • Master's degree in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • PhD in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • In lieu of a degree must have 6+ years' experience in Cyber Security or Information Technology
  • Must be a US Citizen
Preferred Qualifications:
  • 3+ years focused on incident response, threat hunting, or DFIR.
  • 6+ years' experience in Cyber Security or Information Technology
  • Experience with various memory acquisition techniques/tools: FTK Imager
  • Volatility 3
  • Velociraptor for remote memory dumps
  • Experience with enterprise SIEM platforms such as: Microsoft Sentinel
  • Splunk Enterprise Security
  • Elastic Security
  • Experience with EDR technologies including: Microsoft Defender XDR
  • CrowdStrike Falcon
  • SentinelOne Singularity
  • Familiarity with: Windows Event Logs
  • Sysmon
  • KQL
  • Sigma rules
  • YARA
  • PowerShell
  • Python
  • Memory analysis
  • Malware triage
  • Understanding of: Attack chains
  • Identity-based attacks
  • Cloud attack techniques
  • Detection engineering principles
  • Experience with adversary emulation frameworks.
  • Familiarity with: Caldera
  • Prelude Operator
  • Velociraptor
  • TheHive
  • Cloud security investigation experience in: Microsoft Azure
  • Amazon AWS
  • Google Cloud
Certifications:
  • GIAC certifications such as GCFA, GCIH, GCFE, etc.
  • Microsoft certifications such as SC-200, SC-400, AZ-500
  • CISSP, CCSP

Our vision is to ensure that the quality and dynamism that shaped our history continues into our future. It's a bold pursuit, and we never stop striving to go further, faster, and better. We lead progress, creating the technologies that move us forward. If you're driven to grow, to learn, and to make a lasting difference, this is where you belong.

Rolls-Royce is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any protected characteristics. We are committed to providing a respectful and non-discriminatory workplace where ind

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Digital Forensics Analyst
Digital Forensics Analyst

Rolls-Royce plc • Indianapolis (IN)

Hybrid
USD 99,000 - 160,000
Health insurance
401(k) retirement plan with company匹配
Paid Time Off
+2
Digital Forensics Analyst
Digital Forensics Analyst

Rolls-Royce • Indianapolis (IN)

Hybrid
USD 99,000 - 160,000
Health insurance
401(k) match
Paid time off
+1
Cyber Security Engineer
Cyber Security Engineer

Rolls-Royce plc • Indianapolis (IN)

Hybrid
USD 90,000 - 140,000
Health
Dental
Vision
+6
Hybrid Digital Forensics & Purple Team Analyst
Hybrid Digital Forensics & Purple Team Analyst

rollsroyce • United States

Hybrid
USD 90,000 - 130,000
Relocation assistance
DFIR & Incident Response Specialist - Hybrid
DFIR & Incident Response Specialist - Hybrid

Rolls-Royce plc • Indianapolis (IN)

Hybrid
USD 99,000 - 160,000
Health insurance
401(k) retirement plan with company匹配
Paid Time Off
+2
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Rolls-Royce plc • Indianapolis (IN)

Hybrid
USD 90,000 - 130,000
Discretionary bonus
Health insurance
401(k) with company match
+5
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Rolls-Royce plc • United States

Hybrid
USD 110,000 - 160,000
Health insurance
Discretionary bonus plan
401(k) with company match
+2
Hybrid Purple Team DFIR Specialist
Hybrid Purple Team DFIR Specialist

Rolls-Royce • Indianapolis (IN)

Hybrid
USD 99,000 - 160,000
Health insurance
401(k) match
Paid time off
+1
Senior Cyber Security Engineer
Senior Cyber Security Engineer

rollsroyce • United States

Hybrid
USD 110,000 - 160,000
Discretionary bonus
Health insurance
401(k) with company match
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Visa Hunt • United States

Hybrid
USD 110,000 - 170,000
Discretionary bonus plan