IBM CISO - Cybersecurity Forensic Analyst

IBM

Chicago (IL)

On-site

USD 110,000 - 140,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

IBM’s Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to cybersecurity incidents across the Americas region.

The role sits at the intersection of incident response, digital forensics, and threat analysis, partnering with responders, threat detection teams, and leadership to investigate security events, preserve forensic evidence, and drive timely containment and remediation.

Qualifications

  • 3-5 years of experience in Incident Response, SOC and/or Digital Forensics in a global corporate environment.
  • Strong digital forensics expertise across endpoints, systems, and network artifacts; experience with industry-standard tools (e.g., EnCase, FTK, Autopsy).
  • Ability to collect, preserve, and analyze evidence while maintaining chain of custody and audit readiness.
  • Strong investigative and analytical skills, including correlation of logs, endpoint, and network data to determine root cause and reconstruct timelines.
  • Experience operating within incident response workflows and using EDR, SIEM, and detection platforms in active incident environments.
  • Understanding of attacker TTPs, with exposure to malware analysis or memory forensics preferred.
  • Analysis using EDR tooling such as Crowdstrike or Microsoft Defender for Endpoint (MDE).
  • Basic scripting/automation skills (e.g., Python, PowerShell) are a plus.
  • Strong understanding of Windows, Mac, and Linux operating systems.
  • Solid working knowledge of networking topology, technology and tools, such as firewalls, proxies, IDS/IPS, EDR.

Responsibilities

  • Conduct forensic investigations on endpoint, network, and cloud environments
  • Collect, preserve, and analyze digital evidence in accordance with established standards
  • Support incident response activities, including triage, containment, eradication, and recovery
  • Correlate forensic evidence with threat intelligence and detection signals
  • Ability to analyze disk images, logs, and recovered data
  • Reconstruct attack timelines and identify root cause and impact
  • Document findings and produce clear, defensible reports for technical and non-technical stakeholders
  • Collaborate across CSIRT, SOC, Legal, and Compliance teams as needed
  • Contribute to post-incident reviews and continuous improvement of response capabilities

Skills

Incident Response
Digital Forensics
Log Correlation
Threat Analysis
Technical Writing

Education

Bachelor's Degree

Tools

EnCase
FTK
Autopsy
X-Ways
ELK
SIFT
CrowdStrike
Microsoft Defender for Endpoint

Job description

The Office of the CISO has the responsibility to safeguard not only IBM systems but those of clients we support around the globe. The IBM CISO office is comprised of teams that cover all aspects of security - from Vulnerabilty Management, Threat Detection, Security Operations, Product Security, Mail Security, System Inventory, Endpoint Detection, as well as Computer Security Incidence Response. CSIRT is responsible for maintaining and managing the IBM internal global incident response process for cybersecurity and data privacy cases across IBM.

The Office of the CISO has the responsibility to safeguard not only IBM systems but those of clients we support around the globe. The IBM CISO office is comprised of teams that cover all aspects of security - from Vulnerabilty Management, Threat Detection, Security Operations, Product Security, Mail Security, System Inventory, Endpoint Detection, as well as Computer Security Incidence Response. CSIRT is responsible for maintaining and managing the IBM internal global incident response process for cybersecurity and data privacy cases across IBM.

Your Role And Responsibilities

IBM’s Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to cybersecurity incidents across the Americas region.

In this role, you will work at the intersection of incident response, digital forensics, and threat analysis, partnering closely with responders, threat detection teams, and leadership to investigate security events, preserve forensic evidence, and drive timely containment and remediation.

This is a hands‑on analytical role requiring the ability to translate complex technical findings into actionable insights, enabling both operational response and executive decision-making. The successful candidate will demonstrate strong technical depth, investigative rigor, and the ability to operate effectively in high‑pressure environments.

Key Responsibilities
  • Conduct forensic investigations on endpoint, network, and cloud environments
  • Collect, preserve, and analyze digital evidence in accordance with established standards
  • Support incident response activities, including triage, containment, eradication, and recovery
  • Correlate forensic evidence with threat intelligence and detection signals
  • Ability to analyze disk images, logs, and recovered data
  • Reconstruct attack timelines and identify root cause and impact
  • Document findings and produce clear, defensible reports for technical and non-technical stakeholders
  • Collaborate across CSIRT, SOC, Legal, and Compliance teams as needed
  • Contribute to post-incident reviews and continuous improvement of response capabilities
Preferred Education

Bachelor's Degree

Required Technical And Professional Expertise
  • 3-5 years of experience in Incident Response, SOC and/or Digital Forensics in a global corporate environment
  • Key Technical Skills
  • Strong digital forensics expertise across endpoints, systems, and network artifacts; experience with industry-standard tools (e.g., EnCase, FTK, Autopsy)
  • Ability to collect, preserve, and analyze evidence while maintaining chain of custody and audit readiness
  • Strong investigative and analytical skills, including correlation of logs, endpoint, and network data to determine root cause and reconstruct timelines
  • Experience operating within incident response workflows and using EDR, SIEM, and detection platforms in active incident environments
  • Understanding of attacker TTPs, with exposure to malware analysis or memory forensics preferred
  • Analysis using EDR tooling such as Crowdstrike or Microsoft Defender for Endpoint (MDE)
  • Basic scripting/automation skills (e.g., Python, PowerShell) are a plus
  • Strong understanding of Windows, Mac, and Linux operating systems
  • Solid working knowledge of networking topology, technology and tools, such as firewalls, proxies, IDS/IPS, EDR
Event analysis and correlation
Excellent technical writing and presentation skills
  • The ability to work independently and effectively, as well as in a group setting required.
Preferred Technical And Professional Experience
  • Demonstrated computer forensic investigations experience
  • Demonstrated knowledge of commercial and open-source forensic tools, such as X-Ways, Axiom, Autopsy, ELK, SIFT, Plaso, etc
  • Familiarity with enterprise cybersecurity tooling (EDR, SIEM, forensic
platforms) Scripting & Automation (Nice to Have)
  • Certifications such as: GCFA, CHFI, GCIH (or equivalent experience, nice to have)
  • Demonstrated knowledge of analysis with EDR tooling, such as Crowdstrike or Microsoft Defender for Endpoint (MDE)
  • Knowledge of incident response and analysis in cloud environments, such as IBM Cloud, AWS, or Azure
  • Ability to successfully lead and facilitate information gathering meetings
  • Experience managing small and large scale cyber security incidents
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IBM CISO - Cybersecurity Forensic Analyst
IBM CISO - Cybersecurity Forensic Analyst

IBM • Austin (TX)

On-site
USD 110,000 - 160,000
Global Incident Response Forensic Analyst
Global Incident Response Forensic Analyst

IBM • Chicago (IL)

On-site
USD 110,000 - 140,000
Expert Cyber Defender TS/SCI
Expert Cyber Defender TS/SCI

IBM • Bethesda (MD)

On-site
USD 120,000 - 150,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Senior Incident Response Lead & Forensics Expert
Senior Incident Response Lead & Forensics Expert

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Incident Response & Digital Forensics Analyst
Incident Response & Digital Forensics Analyst

IBM • Austin (TX)

On-site
USD 110,000 - 160,000
Cybersecurity Analyst (Digital Forensics/Incident Response)
Cybersecurity Analyst (Digital Forensics/Incident Response)

Columbia University Information Technology • New York (NY)

On-site
USD 80,000 - 110,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Cybersecurity Remediation Engineer
Cybersecurity Remediation Engineer

IBM • Austin (TX)

On-site
USD 100,000 - 130,000
Cybersecurity Remediation Engineer
Cybersecurity Remediation Engineer

IBM • Atlanta (GA)

On-site
USD 80,000 - 120,000