
DFIR Specialist – Senior SOC Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Hong Kong, +3 more countries.
• Oversee comprehensive incident response initiatives related to business email compromise, ransomware, data breaches, insider threats, and compromise assessments.
• Perform forensic examinations across cloud, Windows, Linux, and macOS platforms.
• Examine network traffic and log information from web application firewalls, firewalls, endpoints, cloud services, and applications.
• Utilize tools such as CrowdStrike, FTK, next-generation SIEM platforms, and Magnet AXIOM to detect indicators of compromise, threat actor TTPs, root causes, and the extent of impact.
• Work collaboratively with clients and internal teams to relay findings, provide timely updates, and produce detailed reports.
• Provide mentorship to junior team members, sharing expertise in incident response and digital forensics.
• Stay informed about emerging threats, including those related to AI and large language models.
• Enhance playbooks, methodologies, and tools, including artifact collectors and parsers.
• Integrate lessons learned from active engagements into operational processes and automation.
• Travel as necessary for on-site client interactions.
• A Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related field, or equivalent professional experience.
• Experience in administering, monitoring, or investigating cloud environments such as Microsoft Azure, AWS, Google Workspace, or Alibaba Cloud.
• A minimum of four years of direct experience in cybersecurity operations.
• Strong skills in rapid incident response, innovative problem-solving, and report preparation.
• An investigative mindset with a passion for tackling complex issues, acquiring new techniques, and enhancing skills.
• Previous experience in a client-facing role within incident response consulting.
• Hands-on experience in incident response and/or digital forensics, with practical knowledge of forensic and incident response tools.
• Experience in developing and facilitating tabletop exercises.
• Strong executive presence, capable of articulating intricate technical findings to C-level stakeholders.
• Proven track record of fostering collaborative relationships with internal teams, external partners, and clients.
• Work authorization requirements may differ by location and will be discussed during the hiring process.
• Approximately 5% travel to support client and business requirements through on-site engagements.
UltraViolet Cyber
Get handpicked remote jobs straight to your inbox weekly.