ISA Cybersecurity logo
ISA CybersecurityPosted 1 month ago

Incident Response Analyst, Digital Forensics & Incident Response

$75,000–$105,000 year

HybridToronto, Ontario, Canada

Full TimeMid LevelMedium

Job Summary

Conduct digital forensic acquisition and analysis across endpoint, server, network, mobile, and cloud sources to identify indicators of compromise and reconstruct attack timelines. Support the Incident Commander in executing IR Retainer engagements and Emergency IRs, maintaining chain-of-custody discipline suitable for legal proceedings throughout evidence handling. Gather evidence from logs and artifacts to correlate threat intelligence and TTPs, while drafting technical findings for client, legal, or law enforcement delivery. Apply and refine DFIR playbooks during live engagements and contribute to post-incident reviews to improve detection capabilities. Act as a client-facing technical resource and assist with technical scoping for proposals and RFP responses. Participate in 24x7 on-call rotation for IR Retainers and Emergency IRs, with a requirement to obtain Government of Canada security clearance.

Required Qualifications

  • 3+ years of progressive experience in cybersecurity, including direct experience in incident response and/or digital forensics
  • Working knowledge of the incident response lifecycle, containment and eradication strategies, and digital forensic methodologies
  • Hands-on experience with host, network, or cloud forensics, including exposure to chain-of-custody requirements
  • Proficient working with Windows, Linux, and MacOS environments
  • Exposure to cloud forensics or investigations (AWS, Azure, GCP, Microsoft 365, Google Workspace)
  • Working knowledge of security control families such as EDR, SIEM, SOAR, NDR, identity, email security, or DLP
  • Familiarity with MITRE ATT&CK and current ransomware/APT TTPs
  • Clear written and verbal communication skills; ability to document technical findings for both technical and non-technical audiences
  • Bachelor's degree in computer science, Information Security, or related field, or equivalent professional experience
  • Willingness to participate in 24x7 on-call rotation for IR Retainers and Emergency IRs
  • Ability to obtain Government of Canada security clearance
  • Strong English language skills, written and verbal

Desired Qualifications

  • Familiarity with frameworks such as NIST SP 800-61, ISO 27035, or NIST CSF is an asset
  • Experience supporting MSSP service delivery, including contractual SLAs and 24x7 operations
  • Exposure to OSINT gathering and correlation in support of threat actor attribution or exposure analysis
  • Experience supporting law enforcement engagements or regulatory investigations
  • Exposure to dark web or social-media threat monitoring
  • Multilingual capability is an asset
  • Preferred: GCIH, GCFA, GCFE
  • Nice to have: OSCP, CySA+, CHFI, ECIH, CompTIA Security+, CISSP (or actively pursuing)
  • Cloud (any of): AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce