DFIR
On-siteHerzliya, Tel Aviv, Israel
Job Summary
DFIR team member at CYE responsible for incident response lifecycle and real-time activities, including detection, containment, eradication, and recovery in cloud environments (Azure, AWS). Conduct digital forensics investigations, research and analyze TTPs used by malicious actors, and perform hunt-evil activities. Collaborate with in-house red team, CTI, and cyber architect teams and engage with worldwide companies, CISOs, and technology experts. Requires 2-3 years of DFIR experience, cloud-forensics experience, Windows/Linux forensics, network forensics, threat hunting and cyber threat intelligence, experience with Splunk/Elasticsearch/SQL/VQL, understanding of targeted attacks, and strong English communication skills.
Required Qualifications
- 2-3 years of experience as a DFIR team member
- Experience with performing digital forensics in a cloud environment
- Experience with performing digital forensics of Windows-based and/or Linux-based platforms, network forensics, and analysis
- Thorough understanding of threat hunting models, as well as cyber threat intelligence, including TTP and IoCs extraction and mapping
- Experience with research and data analysis of large DBs via Splunk, Elasticsearch, SQL, or VQL
- Strong understanding of targeted attacks; able to create customized tactical remediation plans
- Good written and verbal English communication skills
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.