
Digital Forensics & Incident Response Specialist
- Sydney, NSW
- $140,000 per year
- Permanent
- Full-time
- Monitor, detect, and respond to InfoSec threats
- Lead & support security incident investigations - data breaches, malware infections, insider threats, APT's etc.
- Triage, contain and remediate cybersecurity incidents and threats.
- Root cause analysis and develop IR reports with actionable recommendations.
- Collect, preserve, and analyse evidence from endpoints, networks, and cloud environments.
- Undertake memory forensics, disk forensics, and network packet analysis.
- Identify IOC's and TTP's used by threat actors.
- Work with SIEM, EDR and threat intelligence tools.
- Continuously identify improvements to Incident Management and Incident Response processes.
- Research and investigate new and emerging threats.
- Integrate information from disparate sources and create tactical intelligence to better protect organisational assets.
- Collaborate and communicate with various internal teams including SOC, IT teams, Internal Audit, Legal, and various business stakeholders.
- Work alongside a local and global teams in a 'follow-the-sun' model.
- Proven Cyber Security Incident Response experience.
- Background in digital forensics.
- Scripting experience is beneficial - e.g. Python, PowerShell, etc
- Cloud security knowledge is beneficial - including techniques to secure cloud environments & cloud Incident Response.
- Background inside enterprise environments, preferably with globally dispersed teams.
- Strong attention to detail, problem-solving & analytical skills
- Clear & confident communication & stakeholder management abilities.
- Australian Citizenship and ability to obtain NV1 clearance is essential.