Global Incident Response Forensic Analyst

IBM

Chicago (IL)

On-site

USD 110,000 - 140,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

IBM’s Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to cybersecurity incidents across the Americas region.

The role sits at the intersection of incident response, digital forensics, and threat analysis, partnering with responders, threat detection teams, and leadership to investigate security events, preserve forensic evidence, and drive timely containment and remediation.

Qualifications

  • 3-5 years of experience in Incident Response, SOC and/or Digital Forensics in a global corporate environment.
  • Strong digital forensics expertise across endpoints, systems, and network artifacts; experience with industry-standard tools (e.g., EnCase, FTK, Autopsy).
  • Ability to collect, preserve, and analyze evidence while maintaining chain of custody and audit readiness.
  • Strong investigative and analytical skills, including correlation of logs, endpoint, and network data to determine root cause and reconstruct timelines.
  • Experience operating within incident response workflows and using EDR, SIEM, and detection platforms in active incident environments.
  • Understanding of attacker TTPs, with exposure to malware analysis or memory forensics preferred.
  • Analysis using EDR tooling such as Crowdstrike or Microsoft Defender for Endpoint (MDE).
  • Basic scripting/automation skills (e.g., Python, PowerShell) are a plus.
  • Strong understanding of Windows, Mac, and Linux operating systems.
  • Solid working knowledge of networking topology, technology and tools, such as firewalls, proxies, IDS/IPS, EDR.

Responsibilities

  • Conduct forensic investigations on endpoint, network, and cloud environments
  • Collect, preserve, and analyze digital evidence in accordance with established standards
  • Support incident response activities, including triage, containment, eradication, and recovery
  • Correlate forensic evidence with threat intelligence and detection signals
  • Ability to analyze disk images, logs, and recovered data
  • Reconstruct attack timelines and identify root cause and impact
  • Document findings and produce clear, defensible reports for technical and non-technical stakeholders
  • Collaborate across CSIRT, SOC, Legal, and Compliance teams as needed
  • Contribute to post-incident reviews and continuous improvement of response capabilities

Skills

Incident Response
Digital Forensics
Log Correlation
Threat Analysis
Technical Writing

Education

Bachelor's Degree

Tools

EnCase
FTK
Autopsy
X-Ways
ELK
SIFT
CrowdStrike
Microsoft Defender for Endpoint

Job description

IBM’s Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to cybersecurity incidents across the Americas region.

The role sits at the intersection of incident response, digital forensics, and threat analysis, partnering with responders, threat detection teams, and leadership to investigate security events, preserve forensic evidence, and drive timely containment and remediation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response & Digital Forensics Analyst
Incident Response & Digital Forensics Analyst

IBM • Austin (TX)

On-site
USD 110,000 - 160,000
IBM CISO - Cybersecurity Forensic Analyst
IBM CISO - Cybersecurity Forensic Analyst

IBM • Chicago (IL)

On-site
USD 110,000 - 140,000
IBM CISO - Cybersecurity Forensic Analyst
IBM CISO - Cybersecurity Forensic Analyst

IBM • Austin (TX)

On-site
USD 110,000 - 160,000
Global Cyber Incident Response Associate
Global Cyber Incident Response Associate

IBM • Herndon (VA)

On-site
USD 76,000 - 116,000
Healthcare benefits
401(k) and IBM Stock Purchase Plan
Paid time off and holidays
Senior Incident Response Lead: Forensics, Automation & AI
Senior Incident Response Lead: Forensics, Automation & AI

Jobgether • United States

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) retirement plan with company匹配
Life insurance
+1
TS/SCI Cyber Defense & IR Analyst
TS/SCI Cyber Defense & IR Analyst

IBM • Jasper (AL)

On-site
USD 85,000 - 125,000
Healthcare benefits
401(k) plan
Paid time off
+2
Cybersecurity Forensics Consultant - Incident Response
Cybersecurity Forensics Consultant - Incident Response

Forensic Focus Limited • Washington, Northern (KY)

Hybrid
USD 40,000 - 52,000
Digital Forensics & Incident Response Specialist
Digital Forensics & Incident Response Specialist

ALLTECH CONSULTING SVC INC • Troy (MI)

On-site
USD 60,000 - 110,000
Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

Forensic Focus Limited • Indianapolis (IN)

Hybrid
USD 90,000 - 130,000
Cyber Forensic Analyst: Incident Response
Cyber Forensic Analyst: Incident Response

Govserviceshub • New York (NY)

On-site
USD 80,000 - 100,000