HamburgerMenu
hirist

Job Description

Description :

Role Overview :

We are seeking a highly skilled Forensic Lead BEC (Business Email Compromise) to lead complex digital forensic investigations and cyber incident response engagements.

This role requires deep expertise in email compromise investigations, digital forensics, malware analysis, and breach response, along with the ability to deliver clear, actionable insights to both technical and business stakeholders.

The ideal candidate will have hands-on experience across host, network, and memory forensics, and will play a critical role in identifying attack vectors, analyzing compromised environments, and supporting remediation efforts.

Key Responsibilities :

- Lead and execute Business Email Compromise (BEC) investigations and cyber incident response engagements.

- Perform host-based, network, and memory forensics analysis across Windows, Linux, and Mac environments.

- Investigate data breaches, phishing incidents, and malware attacks, identifying root causes and impact.

- Analyze forensic artifacts, system logs, and network traffic to detect and respond to security incidents.

- Review and correlate logs including Windows Event Logs, Unified Audit Logs, firewall logs, VPN logs, and endpoint telemetry.

- Conduct network traffic analysis and Network Security Monitoring (NSM) to identify suspicious activity.

- Support cyber insurance investigations and provide detailed forensic evidence and reporting.

- Prepare and present comprehensive forensic reports for both technical and non-technical audiences.

- Ensure secure handling of sensitive data including PII, PHI, and confidential datasets.

- Collaborate with internal teams, clients, and stakeholders to drive timely incident resolution.

Core Skills & Expertise :

Digital Forensics & Security :

- Strong experience in Business Email Compromise (BEC) investigations.

- Expertise in digital forensics, incident response, and cyber investigations.

- Deep knowledge of Windows, Linux, and Mac disk and memory forensics.

- Strong understanding of forensic artifacts and deleted data recovery techniques.

- Experience in malware analysis and data breach response.

Network & Log Analysis :

- Proficiency in analyzing network traffic, system logs, and security events.

- Strong understanding of Network Security Monitoring (NSM) and threat detection.

- Experience working with log sources such as firewall, VPN, endpoint, and audit logs.

Tools & Technologies :

Hands-on experience with tools such as :

1. EnCase, Axiom, FTK, X-Ways

2. SIFT, ELK Stack, Splunk

3. Redline, Volatility

4. Wireshark, TCPDump

5. Other open-source forensic tools

Qualifications & Experience :

- Bachelors degree in Information Security, Computer Science, Cybersecurity, or Digital Forensics (or equivalent experience)

- Minimum 7+ years of experience in digital forensics, incident response, or cybersecurity investigations

- Experience in handling enterprise-level cyber incidents and investigations

Certifications (Preferred) :

Candidates should hold two or more of the following :

1. Security+

2. Network+

3. CEH (Certified Ethical Hacker)

4. CHFI (Computer Hacking Forensic Investigator)

5. SANS certifications (GCED, GCIH, GCFE, GCFA)

Key Competencies :

- Strong analytical and investigative mindset

- Ability to present complex findings clearly to non-technical stakeholders

- High attention to detail and accuracy

- Strong problem-solving and decision-making skills

- Ability to work in high-pressure incident environments

Why Join :

- Opportunity to work on high-impact cybersecurity and forensic investigations

- Exposure to complex global incident response scenarios

- Work with advanced tools and a highly skilled security team


info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...