
Cybersecurity Forensic Examiner I
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in Alabama, +35 more states.
• Investigate and address escalated security incidents.
• Coordinate efforts among teams and departments during security events.
• Lead technical discussions and analyses.
• Create documentation and communications regarding incidents.
• Provide guidance on countermeasures and enhance security analytics and alerts.
• Define the scope and objectives of incident responses based on business requirements and regulatory standards.
• Conduct cybersecurity analysis and design.
• Execute investigations and manage legal preservation workflows.
• Troubleshoot issues related to access control, provisioning requests, network security, and endpoint security systems.
• Evaluate escalated security events and spearhead response actions to mitigate business impact.
• Serve as the Incident Coordinator and Scribe for significant cyber breaches and advanced attacks.
• Support communication efforts during cybersecurity incidents, recoveries, breaches, intrusions, and system abuses.
• Engage in security reviews, assessments, tabletop exercises, risk evaluations, and post-incident activities.
• Formulate recommendations to enhance security posture.
• Document activities related to incident response, metrics, reporting, and lessons learned.
• Assist with alerts and detection capabilities for Indicators of Compromise.
• Evaluate and develop security policies, procedures, and Incident Response documentation.
• Provide technical expertise and operational assistance for security software.
• Manage and perform eDiscovery operations, including legal preservation, litigation holds, forensic collections, and native file productions.
• Manage evidence documentation and maintain the chain of custody.
• Offer guidance and oversight to ensure compliance with cybersecurity laws, regulations, and guidelines.
• Conduct cybersecurity examinations, digital forensics, and eDiscovery operations across multiple departments.
• Bachelor's degree or a suitable combination of relevant education, technical, business, and healthcare experience.
• Certification required within one year of entering the position: EnCase Certified Examiner (EnCE), EnCase Certified eDiscovery Practitioner (EnCEP), Certified Computer Examiner (CCE), or another certification designated by the Cybersecurity Leader.
• Minimum of two years of experience in Information Technology or Cybersecurity within a corporate or similar environment, with forensic knowledge or training.
• Strong understanding of business, information security, and/or computer science.
• Ability to communicate and collaborate across various departments and facilities at different levels.
• Capacity to balance project workloads with customer support and on-call responsibilities.
• Willingness to work variable shifts and hours.
• Ability to respond to pages may be required.
• Additional related certifications are preferred.
• Experience with cybersecurity controls, policies, and procedures is preferred.
• Familiarity with analyzing network activities, responding to anomalies, and reporting events is preferred.
• Experience with level 1 incident response handling and addressing reported or detected incidents is preferred.
• Background in digital forensics and incident response is preferred.
• Additional related education and/or experience is preferred.
• Health and financial security options.
• A variety of benefit plans available for employees and their families.
• Comprehensive Total Rewards package.
Zscaler
Viatris
ActBlue
AlphaSense
Get handpicked remote jobs straight to your inbox weekly.