
Cybersecurity Forensics Analyst - Expert
- Cincinnati, OH
- Permanent
- Full-time
- Serves as a leader for Forensics Investigations, managing the CIRT and forensic workload. Serves as a liaison for Legal, Corporate Security, Human Resources, and/or other areas requiring forensics support. Advises lawyers and investigators on the relevance of data to a case or investigation.
- May testify in court, if required.
- Investigates reports of suspicious activity, analyzing evidence to determine the “who, what, when, and how” aspects of the incident.
- Maintains the chain of custody for evidence used in crimes and/or incidents, including computers, mobile devices, and/or digital storage media.
- Tracks and reports on metrics pertinent to the forensics workload.
- Reviews technical and procedural documentation for systems and solutions to ensure completeness and accuracy.
- Maintains and updates Runbooks and other support documents as appropriate
- Provides input to architecture and technology teams on tools, processes, and requirements for forensics investigations
- Maintains current knowledge of hardware, software and network technology and recommends modifications as required
- Comply with the organization's cybersecurity policies, procedures among colleagues, contractors, alliances, etc.
- Assist with automation efforts to streamline incident response procedures and capabilities.
- Works with vendors to understand product roadmaps and plan for upgrades
- Provide after hours on-call forensic support on a recurring basis
- 5 years in a Forensics and Incident Response roles
- 2 Years Experience documenting and maintaining procedures/runbooks
- Bachelor's degree in Information Systems, Computer Science or related field preferred
- Experience working with Enterprise Forensics tools
- Experience with OpenText Enterprise EnCase solution, Exterro Forensics Took Kit, or similar solutions in an enterprise-wide deployment a plus
- Experience with mobile forensics tools such as Cellebrite, Oxygen, or XRY.
- Experience with Python, PowerShell, or Kusto Query Language
- Strong organizational skills
- Excellent communication and customer service skills
- SIEM/SOAR, EDR/XDR experience a plus
- Ability to develop strong partnerships
- Ability to work flexible hours
- Strong troubleshooting and problem-solving skills
- Forensics and Cybersecurity Certifications (GCFA, GCFE, GASF, GCFR, CFCE) or equivalent