
DFIR Specialist, Senior SOC Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Malaysia, +3 more countries.
• Oversee comprehensive incident response engagements involving investigation, containment, and long-term remediation.
• Assist clients in navigating cases of business email compromise, ransomware, data breaches, insider threats, and compromise assessments.
• Perform forensic analysis across cloud platforms, Windows, Linux, and macOS environments.
• Evaluate network traffic and log data from web application firewalls, traditional firewalls, endpoints, cloud services, and applications.
• Utilize CrowdStrike, FTK, next-generation SIEM platforms, and Magnet AXIOM to pinpoint IOCs, TTPs, root causes, and the scope of impact.
• Work collaboratively with clients and internal teams to convey findings, provide timely updates, and produce detailed reports.
• Mentor junior team members and disseminate best practices in incident response and digital forensics.
• Stay informed about the changing threat landscape, including threats related to AI and large language models.
• Enhance playbooks, methodologies, tools, artifact collectors, and parsers.
• Integrate lessons learned from real engagements into operational processes and automation.
• Travel approximately 5% for client and business requirements through on-site engagements.
• Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related field, or equivalent professional experience.
• Experience in administering, monitoring, or investigating cloud platforms such as Microsoft Azure, AWS, Google Workspace, or Alibaba Cloud.
• At least four years of hands-on experience in cybersecurity operations.
• Strong capabilities in rapid incident response, creative problem-solving, and report writing.
• Investigative mindset with a passion for tackling complex problems, learning new techniques, and continuous improvement.
• Previous experience in a client-facing incident response consulting role.
• Direct experience in incident response and/or digital forensics, including practical use of forensic and incident response tools.
• Previous history of developing and facilitating tabletop exercises.
• Strong executive presence with the ability to present complex technical findings to C-level stakeholders.
• Proven track record of building collaborative relationships with internal teams, external partners, and clients.
• Work authorization requirements may vary by location and will be discussed during the application process.
• Approximately 5% travel to support client and business needs through on-site engagements.
• Opportunity to engage with a diverse range of customers and senior stakeholders across Asia and beyond.
• Mentorship and opportunities for knowledge sharing.
• Professional growth through exposure to the evolving threat landscape, including AI- and large language model-related threats.
UltraViolet Cyber
Get handpicked remote jobs straight to your inbox weekly.