Forensic Lead

areteir

United States

On-site

USD 110,000 - 170,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

areteir seeks a senior digital forensics investigator to lead Tiger Team engagements across ransomware, cloud, insider threat, and advisory/Enterprise Incident Response (EIR). You will guide investigations from data collection to narrative delivery, ensuring timely, well-documented findings.

With 8+ years in IR/DF, you will interact with SOC threat intel and legal teams, mentor analysts, and manage budgets and SLAs while delivering high-quality forensic analyses for diverse clients.

Qualifications

  • Thorough knowledge of host-based forensics, network forensics, malware analysis and data breach response.
  • Experience with a common scripting or programming language, including Perl, Python, Bash, or PowerShell.
  • Experience in a security professional services consulting firm, preferred.
  • One or more Digital Forensic and Incident Response Certifications such as GCFE, GCFA, GNFA, GCTI, GREM, CHFI, CCE, CFC, EnCE, and CFCE, preferred.

Responsibilities

  • Oversees forensics analysis and supports Tiger Teams and engagements beyond ransomware/BEC matters.
  • Leads investigations across Cloud, insider threat, and advisory/Enterprise Incident Response matters.
  • Ensures digital forensic analysis across Windows, Mac, and Windows OS and networking appliances.
  • Provides forensic data and artifact collection requests for timely analysis with minimal impact.
  • Delivers findings for Tiger Teams and maintains oversight across multiple teams.
  • Reviews scoping notes and case background for situational awareness at start of engagements.
  • Drives investigations forward to reveal how threat actors compromised client networks.
  • Collaborates with threat intel, SOC, and Negotiations teams for incident response.
  • Supports the Forensic Director as SME and maintains case load and SLAs.
  • Manages forensic data collection process and ensures on-time reporting and updates.
  • Communicates findings clearly to clients and counsel; supports update calls and client correspondence.
  • Conducts performance reviews of assigned analysts and ensures balanced caseload.
  • Performs final report review from the investigator’s perspective.

Skills

Host-based forensics
Network forensics
Malware analysis
Data breach response
Scripting (Perl/Python/Bash/PowerShell
Security consulting experience
IR/DF certifications (GCFE/GCFA/ GNFA/

Education

Bachelor's degree + 8+ yrs IR/DF
Master's degree + 6+ yrs IR/DF
J.D. + 4+ yrs IR/DF

Tools

EnCase
Axiom
X-Ways
FTK
SIFT
ELK
Redline
Volatility
Open-source tools

Job description

ROLES & RESPONSIBILITIES
  • Oversees Forensics analysis and supports multiple Tiger Teams and engagements for matters beyond Ransomware/BEC matters.
  • Leads investigations for projects beyond Ransomware and BEC including Cloud, insider threat, and advisory/Enterprise Incident Response (EIR) matters.
  • Works with the Forensic members of the Tiger Team to ensure digital forensic analysis of Windows, Apple Mac, and Windows based operating systems, in addition to the analysis of networking appliances including but not limited to, VPN and firewall appliances is performed in an efficient and timely manner.
  • Provides forensic data and artifact collection requests based on the investigative approach to ensure the data is collected and made available for forensic analysis with limited impact.
  • Leads delivery of findings for a Tiger Team working in conjunction with the Senior Analyst to provide oversight across multiple additional Tiger Teams, while taking on leadership responsibilities related to the delivery across the additional multiple Tiger Teams.
  • Reviews scoping call notes and case background for situational awareness from the start of every engagement.
  • Drives the forensic investigation forward ensuring the right data is collected and analysis questions are answered to tell the narrative story of how the threat actor compromised the client's network and environment.
  • Works with the Tiger Team to understand the nature of issues, potential risk to Counsel, Carrier, and Client relationships.
  • Collaborate and leverage threat intel Tactics, Techniques, and Procedures (TTPs)/Indicators of Compromise (IOCs), information from our Security Operations Center (SOC)/Threat Hunting team, and updates from our Negotiations teams as part of the incident.
  • Supports the Director, as a Forensic Subject Matter Expert (SME) for all active forensic analysis for projects on the assigned Tiger Team.
  • Maintains target utilization for members of the Tiger Team that comes from client billable work including forensic analysis, participating in client update or forensic scoping and update findings calls, client correspondence related to forensic analysis, data collection, or investigative questions verbally or in writing.
  • Initiates and manages the forensic data collection process in support of the forensic investigation for the assigned engagement.
  • Ensures the forensic project timeline is on track, daily updates are provided from the assigned analysts to the IR Director, and Analyst SLAs are met (i.e. report is delivered on time, interim and final updates are provided on-time when asked).
  • Delivers Forensics findings and updates to support the Tiger Teams and Senior Analysts as needed due to conflicts or time-off in a clear, concise manner while adjusting communication content and style to meet the needs of diverse stakeholders.
  • Ensures assigned analysts have the data, context, and clarity they need to conduct accurate and timely analysis.
  • Works with Senior Analyst to deliver on the Forensic Investigations plan & manages the delivery timeline delivery across the projects.
  • Monitors and tracks the Forensic budget and budget burn rate across multiple engagements.
  • Allocates Forensic Tiger Team and Tiger Team Pool resources to the Tiger Team projects to maximize delivery based on the availability and utilization of the team members.
  • Works client facing on forensic update calls to ensure accurate updates are conveyed as they relate to the investigation.
  • Communicates both verbally and in writing to answer client and counsel questions related to the forensic investigation.
  • Supports the Tiger Team IR Director with delegating and managing the Senior Analysts and Analysts who report to Forensic Lead on their respective Tiger Team.
  • Conducts the performance reviews of all assigned forensic analysts Maintains a case load of at least two cases and conducts forensic analysis, in addition to other responsibilities.
  • Conducts final review of the report from the perspective of the forensic investigator ensuring all possible investigative questions were addressed in the analysis and requesting additional context or analysis when the report requires more work.
  • May perform other duties as assigned by management.
SKILLS AND KNOWLEDGE
  • Thorough knowledge of host-based forensics, network forensics, malware analysis and data breach response.
  • Experience with EnCase, Axiom, X-Ways, FTK, SIFT, ELK, Redline, Volatility, and open source forensic tools.
  • Experience with a common scripting or programming language, including Perl, Python, Bash, or PowerShell.
  • Experience in a security professional services consulting firm, preferred.
  • One or more Digital Forensic and Incident Response Certifications such as GCFE, GCFA, GNFA, GCTI, GREM, CHFI, CCE, CFC, EnCE, and CFCE, preferred.
JOB REQUIREMENTS
  • Bachelor's Degree and 8+ years of incident response or digital forensics experience or Master's Degree and 6+ years related experience or J.D. and 4+ years related experience
  • Consulting experience, preferred
  • DI
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Forensic Analyst
Forensic Analyst

areteir • United States

On-site
USD 90,000 - 140,000
Senior Forensics Lead - Incident Response & Tiger Teams
Senior Forensics Lead - Incident Response & Tiger Teams

areteir • United States

On-site
USD 110,000 - 170,000
Investigation & Forensic Analyst
Investigation & Forensic Analyst

Jobtailor • San Diego (CA)

On-site
USD 70,000 - 100,000
Senior Digital Forensics and Incident Response Consultant
Senior Digital Forensics and Incident Response Consultant

Jobtailor • Plano (TX)

On-site
USD 120,000 - 180,000
Digital Forensic Specialist
Digital Forensic Specialist

ALLTECH CONSULTING SVC INC • Troy (MI)

On-site
USD 60,000 - 110,000
Engagement Lead, Incident Response
Engagement Lead, Incident Response

areteir • United States

On-site
USD 140,000 - 230,000
Digital Forensics and Incident Analyst
Digital Forensics and Incident Analyst

Jobtailor • Washington

On-site
USD 120,000 - 180,000
IBM CISO - Cybersecurity Forensic Analyst
IBM CISO - Cybersecurity Forensic Analyst

IBM • Austin (TX)

On-site
USD 110,000 - 160,000
Host Based Systems Analyst IV
Host Based Systems Analyst IV

Solutions³ LLC • Virginia (MN)

On-site
USD 110,000 - 170,000
Senior Incident Response Lead & Forensics Expert
Senior Incident Response Lead & Forensics Expert

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000