
DFIR Specialist – Senior SOC Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Philippines.
• Oversee comprehensive incident response initiatives related to business email compromise, ransomware, data breaches, insider threats, and compromise assessments.
• Assist clients during investigations, containment efforts, and long-term remediation strategies.
• Perform forensic analyses across various environments including cloud, Windows, Linux, and macOS.
• Examine network traffic and log data from web application firewalls, traditional firewalls, endpoints, cloud services, and applications.
• Utilize CrowdStrike, FTK, advanced SIEM platforms, and Magnet AXIOM to detect IOCs, threat actor TTPs, root causes, and the extent of impact.
• Work collaboratively with clients and internal teams to convey findings, provide timely updates, and produce detailed reports.
• Mentor junior personnel and disseminate best practices in incident response and digital forensics.
• Stay informed about the changing threat landscape, including new developments related to AI and large language models.
• Enhance playbooks, methodologies, and tools, including artifact collectors and parsers.
• Incorporate lessons learned from live engagements into processes and automation improvements.
• Travel around 5% for on-site client interactions.
• A Bachelor’s degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related field, or equivalent professional experience.
• Experience in administering, monitoring, or investigating cloud platforms such as Microsoft Azure, AWS, Google Workspace, or Alibaba Cloud.
• At least four years of direct experience in cybersecurity operations.
• Strong skills in rapid incident response, innovative problem-solving, and report creation.
• An investigative mindset with a passion for addressing complex challenges, acquiring new techniques, and ongoing self-improvement.
• Previous experience in a client-facing incident response consulting position.
• Hands-on experience in incident response and/or digital forensics, with practical knowledge of forensic and incident response tools.
• Prior involvement in developing and facilitating tabletop exercises.
• Strong executive presence, capable of presenting intricate technical findings to C-level stakeholders.
• Demonstrated ability to foster collaborative relationships with internal teams, external partners, and clients.
• Work authorization requirements may differ based on location and will be addressed during the hiring process.
• Travel as necessary, approximately 5%, to meet client and business requirements through on-site engagements.
UltraViolet Cyber
Get handpicked remote jobs straight to your inbox weekly.