Investigator: Digital Forensics
Our client is seeking an Investigator: Digital Forensics on a non‑permanent basis to conduct in‑depth digital forensic investigations across the organisation. The successful candidate will be responsible for identifying, preserving, acquiring, extracting and analysing digital evidence relating to fraud, cybercrime, misconduct, insider threats and data breaches.
Location: Johannesburg, Gauteng
Employment Type: Contract
Salary: R180,000 - R250,000 per year
- Conduct end‑to‑end digital forensic investigations across endpoints, servers, mobile devices, cloud environments, Microsoft 365, network infrastructure and other digital sources.
- Gather, preserve, acquire, extract and analyse digital evidence using approved forensic methodologies and tools.
- Recover deleted, hidden, encrypted or damaged data as part of forensic investigations.
- Analyse user activity, email communications, authentication records, cloud audit logs, browser activity and application artefacts.
- Conduct endpoint, mobile, cloud, network, memory and malware forensic investigations.
- Perform forensic investigations across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform and SaaS environments.
- Utilise forensic, eDiscovery and security technologies to identify, analyse and preserve relevant digital evidence.
- Maintain accurate chain‑of‑custody records and ensure the secure storage, management and retention of digital evidence.
- Prepare detailed forensic reports, statistics, trends, findings, conclusions and recommendations for stakeholders.
- Conduct root cause analysis to identify control weaknesses and recommend corrective actions to reduce future risk.
- Prepare affidavits, witness statements and evidential reports for disciplinary, civil, regulatory and criminal proceedings.
- Present and testify on forensic findings at disciplinary hearings, tribunals and court proceedings when required.
- Identify and elevate emerging digital crime trends, risks and significant findings to the relevant stakeholders.
Minimum Requirements
- Bachelor's degree in Digital Forensics, Cyber Security, Computer Science, Information Security, Information Systems or a related field.
- 5–7 years’ experience in Digital Forensics, Incident Response, Cyber Investigations or a related field.
- Experience preparing evidential reports and presenting findings to senior stakeholders, regulators and legal representatives.
- Strong understanding of digital evidence preservation and chain‑of‑custody principles.
Technical Skills
- Experience with EnCase, FTK, Magnet AXIOM, Cellebrite, MSAB XRY, Microsoft Sentinel, Microsoft Defender, Microsoft Purview, Azure, Microsoft 365, AWS, GCP.
- Knowledge of cloud forensic investigations across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform and SaaS environments.
- Strong analytical and investigative capabilities, with the ability to identify patterns, trends, anomalies and root causes.
- Excellent report writing and evidential documentation skills.
- Strong verbal communication and presentation skills.
Preferred Certifications
- GCFA, GCFE, GNFA, GCTI, EnCE, CFCE, CCE, CHFI, CISSP, CISM
- Microsoft Security Certifications, AWS Security Specialty, Google Professional Cloud Security Engineer
Equal Opportunity
EEO Minorities/Females/Protected Veterans/Disabled