Company and Job Description
Our client is seeking an Investigator: Digital Forensics on a non-permanent basis to conduct in-depth digital forensic investigations across the organisation.
The successful candidate will be responsible for identifying, preserving, acquiring, extracting and analysing digital evidence relating to fraud, cybercrime, misconduct, insider threats and data breaches. You will work across a broad technology landscape, including endpoints, servers, mobile devices, cloud environments, Microsoft 365 and network infrastructure.
This role offers the opportunity to work on complex investigations while applying recognised forensic methodologies, maintaining evidential integrity and presenting findings to senior stakeholders and legal representatives.
Key Responsibilities
- Conduct end-to-end digital forensic investigations across endpoints, servers, mobile devices, cloud environments, Microsoft 365, network infrastructure and other digital sources.
- Gather, preserve, acquire, extract and analyse digital evidence using approved forensic methodologies and tools.
- Recover deleted, hidden, encrypted or damaged data as part of forensic investigations.
- Analyse user activity, email communications, authentication records, cloud audit logs, browser activity and application artefacts.
- Conduct endpoint, mobile, cloud, network, memory and malware forensic investigations.
- Perform forensic investigations across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform and SaaS environments.
- Utilise forensic, eDiscovery and security technologies to identify, analyse and preserve relevant digital evidence.
- Maintain accurate chain-of-custody records and ensure the secure storage, management and retention of digital evidence.
- Prepare detailed forensic reports, statistics, trends, findings, conclusions and recommendations for stakeholders.
- Conduct root cause analysis to identify control weaknesses and recommend corrective actions to reduce future risk.
- Prepare affidavits, witness statements and evidential reports for disciplinary, civil, regulatory and criminal proceedings.
- Present and testify on forensic findings at disciplinary hearings, tribunals and court proceedings when required.
- Identify and escalation emerging digital crime trends, risks and significant findings to the relevant stakeholders.
Job Experience and Skills Required
Education
- Bachelor's degree in Digital Forensics, Cyber Security, Computer Science, Information Security, Information Systems or a related field.
Experience
- Minimum 5–7 years' experience in Digital Forensics, Incident Response, Cyber Investigations or a related discipline.
- Demonstrated experience conducting complex digital forensic investigations.
- Experience working with digital evidence across endpoint, mobile, cloud, network and/or memory environments.
- Experience preparing evidential reports and presenting forensic findings to senior stakeholders, regulators and legal representatives.
- Experience maintaining chain of custody and handling digital evidence in accordance with forensic standards.
Technical Skills
- Strong knowledge of digital forensic investigation methodologies and evidence handling.
- Experience with cloud forensic investigations across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform and SaaS environments.
- Exposure to forensic and eDiscovery tools such as EnCase, FTK, Magnet AXIOM, Cellebrite, MSAB XRY, Microsoft Sentinel, Microsoft Defender and Microsoft Purview.
- Strong analytical and investigative capabilities, with the ability to identify patterns, trends, anomalies and root causes.
- Excellent report writing and evidential documentation skills.
- Strong verbal communication and presentation skills.
Advantageous Certifications
- GCFA, GCFE, GNFA or GCTI.
- EnCE, CFCE, CCE or CHFI.
- CISSP or CISM.
- Microsoft Security Certifications.
- AWS Security Specialty.
- Google Professional Cloud Security Engineer.