Nviso logo
NvisoPosted 7 months ago
EXPIRED

Senior Incident Response & Digital Forensics Consultant

HybridAthens, Attica, Greece

Full TimeSenior LevelAssociates Degree

Job Summary

Conduct host, network, and memory forensics using tools like Magnet AXIOM Cyber, X-Ways, Volatility, and Wireshark to support cyber incident investigations. Lead single-system forensic analysis, perform timeline analysis, and execute live response artifact capture for containment and eradication strategies. Drive basic malware triage of executables and scripts, while acting as Incident Lead to set investigative questions and steer technical analysis tasks. Lead customer calls during incidents, deliver status reports, and contribute to executive-ready communications. Support improvement projects for automation in digital forensics, develop incident response processes, and perform threat hunting engagements within customer environments. Assist with tabletop exercises, readiness assessments, and threat-intelligence briefings. On-call rotation typically one week per month. Requires NATO citizenship and 3+ years of hands-on experience.

Required Qualifications

  • Citizenship in one of the 32 NATO member states
  • 3+ years of hands-on experience, including acting as an incident response case lead
  • Strong knowledge of cyber intrusion analysis, incident response, digital forensics on Windows/MacOS/Unix
  • Demonstrated expertise in memory forensics (Volatility, MemProcFS)
  • Demonstrated expertise in timeline analysis (e.g., MFTECmd, KAPE, Plaso/Timesketch)
  • Demonstrated expertise in disk forensics (Magnet AXIOM Cyber, X-Ways, Autopsy)
  • Proficiency with live response tooling (e.g., Velociraptor, GRR Rapid Response, EDR live response)
  • Ability to remain calm during crisis situations and prioritize effectively under pressure
  • Language: English (must have)

Desired Qualifications

  • German (nice to have)
  • Experience with cloud telemetry (Microsoft 365/Azure, AWS, Google Cloud/Workspace)
  • Experience with host forensics tools (Magnet AXIOM Cyber, X-Ways, Autopsy)
  • Experience with network forensics tools (Wireshark, tshark)
  • Experience with memory forensics tools (Volatility, MemProcFS)
  • Experience with log analysis
  • Experience with basic malware triage of executables and malicious scripts (static and behavioral)
  • Experience with live response artifact capture
  • Experience with volatile data collection
  • Experience with containment to support eradication and recovery efforts
  • Experience with timeline analysis of compromised hosts
  • Experience with conducting live response
  • Experience with performing threat hunting engagements
  • Experience with tabletop exercises
  • Experience with incident and forensic readiness assessments
  • Experience with threat-intelligence-related briefings
  • Experience with building & automating incident response processes
  • Experience with developing analytical capabilities
  • Experience with setting investigative questions
  • Experience with delegating technical analysis tasks
  • Experience with steering containment and eradication strategies
  • Experience with producing high-quality forensic and executive reports
  • Experience with peer-reviewing case notes, artifacts, and draft reports
  • Experience with leading customer calls during incidents
  • Experience with cyber crisis management
  • Experience with delivering status reports
  • Experience with planning for containment, eradication and recovery efforts
  • Experience with input to executive-ready communications
  • Experience with supporting improvement projects related to automation in digital forensics
  • Experience with developing NVISO tools and incident response processes
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with reporting
  • Experience with leading single-system forensic analysis
  • Experience with contributing to complex intrusions, including those with lateral movement
  • Experience with performing containment to support eradication and recovery efforts
  • Experience with recovering from incidents
  • Experience with working collaboratively with clients and cross-functional teams
  • Experience with acting as an Incident Lead
  • Experience with setting investigative questions
  • Experience with delegating technical analysis tasks
  • Experience with steering containment and eradication strategies
  • Experience with producing high-quality forensic and executive reports
  • Experience with peer-reviewing case notes, artifacts, and draft reports
  • Experience with leading customer calls during incidents
  • Experience with contributing to cyber crisis management
  • Experience with delivering status reports
  • Experience with planning for containment, eradication and recovery efforts
  • Experience with input to executive-ready communications
  • Experience with supporting improvement projects related to automation in digital forensics
  • Experience with developing NVISO tools and incident response processes
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with reporting
  • Experience with performing threat hunting engagements within customer environments
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with execution
  • Experience with reporting
  • Experience with assisting in other engagements such as tabletop exercises, incident and forensic readiness assessments, and threat-intelligence-related briefings
  • Experience with acting as an incident response case lead
  • Experience with cyber intrusion analysis
  • Experience with incident response
  • Experience with digital forensics on Windows/MacOS/Unix
  • Experience with memory forensics (Volatility, MemProcFS)
  • Experience with timeline analysis (e.g., MFTECmd, KAPE, Plaso/Timesketch)
  • Experience with disk forensics (Magnet AXIOM Cyber, X-Ways, Autopsy)
  • Experience with live response tooling (e.g., Velociraptor, GRR Rapid Response, EDR live response)
  • Experience with coordinating remediation actions
  • Up-to-date knowledge on the latest cybersecurity threats and attacker TTPs
  • Excellent analytical and problem-solving skills with an eye for detail in documentation
  • Effective communication and interpersonal skills to work collaboratively with clients and cross-functional teams
  • Ability to remain calm during crisis situations and prioritize effectively under pressure
  • Language: English (must have)
  • German (nice to have)
  • Experience with cloud telemetry (Microsoft 365/Azure, AWS, Google Cloud/Workspace)
  • Experience with host forensics (Magnet AXIOM Cyber, X-Ways, Autopsy)
  • Experience with network forensics (Wireshark, tshark)
  • Experience with memory forensics (Volatility, MemProcFS)
  • Experience with log analysis
  • Experience with basic malware triage of executables and malicious scripts (static and behavioral)
  • Experience with live response artifact capture
  • Experience with volatile data collection
  • Experience with containment to support eradication and recovery efforts
  • Experience with timeline analysis of compromised hosts
  • Experience with conducting live response
  • Experience with performing threat hunting engagements
  • Experience with tabletop exercises
  • Experience with incident and forensic readiness assessments
  • Experience with threat-intelligence-related briefings
  • Experience with building & automating incident response processes
  • Experience with developing analytical capabilities
  • Experience with setting investigative questions
  • Experience with delegating technical analysis tasks
  • Experience with steering containment and eradication strategies
  • Experience with producing high-quality forensic and executive reports
  • Experience with peer-reviewing case notes, artifacts, and draft reports
  • Experience with leading customer calls during incidents
  • Experience with cyber crisis management
  • Experience with delivering status reports
  • Experience with planning for containment, eradication and recovery efforts
  • Experience with input to executive-ready communications
  • Experience with supporting improvement projects related to automation in digital forensics
  • Experience with developing NVISO tools and incident response processes
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with reporting
  • Experience with leading single-system forensic analysis
  • Experience with contributing to complex intrusions, including those with lateral movement
  • Experience with performing timeline analysis of compromised hosts
  • Experience with conducting live response artifact capture
  • Experience with volatile data collection
  • Experience with containment to support eradication and recovery efforts
  • Experience with recovering from incidents
  • Experience with acting as an Incident Lead
  • Experience with setting investigative questions
  • Experience with delegating technical analysis tasks
  • Experience with steering containment and eradication strategies
  • Experience with producing high-quality forensic and executive reports
  • Experience with peer-reviewing case notes, artifacts, and draft reports
  • Experience with leading customer calls during incidents
  • Experience with cyber crisis management
  • Experience with delivering status reports
  • Experience with planning for containment, eradication and recovery efforts
  • Experience with input to executive-ready communications
  • Experience with supporting improvement projects related to automation in digital forensics
  • Experience with developing NVISO tools and incident response processes
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with reporting
  • Experience with performing threat hunting engagements within customer environments
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with execution
  • Experience with reporting
  • Experience with assisting in other engagements such as tabletop exercises, incident and forensic readiness assessments, and threat-intelligence-related briefings
  • Experience with acting as an incident response case lead
  • Experience with cyber intrusion analysis
  • Experience with incident response
  • Experience with digital forensics on Windows/MacOS/Unix
  • Experience with memory forensics (Volatility, MemProcFS)
  • Experience with timeline analysis (e.g., MFTECmd, KAPE, Plaso/Timesketch)
  • Experience with disk forensics (Magnet AXIOM Cyber, X-Ways, Autopsy)
  • Experience with live response tooling (e.g., Velociraptor, GRR Rapid Response, EDR live response)
  • Experience with coordinating remediation actions
  • Up-to-date knowledge on the latest cybersecurity threats and attacker TTPs
  • Excellent analytical and problem-solving skills with an eye for detail in documentation
  • Effective communication and interpersonal skills to work collaboratively with clients and cross-functional teams
  • Ability to remain calm during crisis situations and prioritize effectively under pressure
  • Language: English (must have)
  • German (nice to have)
  • Experience with cloud telemetry (Microsoft 365/Azure, AWS, Google Cloud/Workspace)
  • Experience with host forensics (Magnet AXIOM Cyber, X-Ways, Autopsy)
  • Experience with network forensics (Wireshark, tshark)
  • Experience with memory forensics (Volatility, MemProcFS)
  • Experience with log analysis
  • Experience with basic malware triage of executables and malicious scripts (static and behavioral)
  • Experience with live response artifact capture
  • Experience with volatile data collection
  • Experience with containment to support eradication and recovery efforts
  • Experience with timeline analysis of compromised hosts
  • Experience with conducting live response
  • Experience with performing threat hunting engagements
  • Experience with tabletop exercises
  • Experience with incident and forensic readiness assessments
  • Experience with threat-intelligence-related briefings
  • Experience with building & automating incident response processes
  • Experience with developing analytical capabilities
  • Experience with setting investigative questions
  • Experience with delegating technical analysis tasks
  • Experience with steering containment and eradication strategies
  • Experience with producing high-quality forensic and executive reports
  • Experience with peer-reviewing case notes, artifacts, and draft reports
  • Experience with leading customer calls during incidents
  • Experience with cyber crisis management
  • Experience with delivering status reports
  • Experience with planning for containment, eradication and recovery efforts
  • Experience with input to executive-ready communications
  • Experience with supporting improvement projects related to automation in digital forensics
  • Experience with developing NVISO tools and incident response processes
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with reporting
  • Experience with leading single-system forensic analysis
  • Experience with contributing to complex intrusions, including those with lateral movement
  • Experience with performing timeline analysis of compromised hosts
  • Experience with conducting live response artifact capture
  • Experience with volatile data collection
  • Experience with containment to support eradication and recovery efforts
  • Experience with recovering from incidents
  • Experience with acting as an Incident Lead
  • Experience with setting investigative questions
  • Experience with delegating technical analysis tasks
  • Experience with steering containment and eradication strategies
  • Experience with producing high-quality forensic and executive reports
  • Experience with peer-reviewing case notes, artifacts, and draft reports
  • Experience with leading customer calls during incidents
  • Experience with cyber crisis management
  • Experience with delivering status reports
  • Experience with planning for containment, eradication and recovery efforts
  • Experience with input to executive-ready communications
  • Experience with supporting improvement projects related to automation in digital forensics
  • Experience with developing NVISO tools and incident response processes
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with reporting
  • Experience with performing threat hunting engagements within customer environments
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with execution
  • Experience with reporting
  • Experience with assisting in other engagements such as tabletop exercises, incident and forensic readiness assessments, and threat-intelligence-related briefings
  • Experience with acting as an incident response case lead
  • Experience with cyber intrusion analysis
  • Experience with incident response
  • Experience with digital forensics on Windows/MacOS/Unix
  • Experience with memory forensics (Volatility, MemProcFS)
  • Experience with timeline analysis (e.g., MFTECmd, KAPE, Plaso/Timesketch)
  • Experience with disk forensics (Magnet AXIOM Cyber, X-Ways, Autopsy)
  • Experience with live response tooling (e.g., Velociraptor, GRR Rapid Response, EDR live response)
  • Experience with coordinating remediation actions
  • Up-to-date knowledge on the latest cybersecurity threats and attacker TTPs
  • Excellent analytical and problem-solving skills with an eye for detail in documentation
  • Effective communication and interpersonal skills to work collaboratively with clients and cross-functional teams
  • Ability to remain calm during crisis situations and prioritize effectively under pressure
  • Language: English (must have)
  • German (nice to have)
  • Experience with cloud telemetry (Microsoft 365/Azure, AWS, Google Cloud/Workspace)
  • Experience with host forensics (Magnet AXIOM Cyber, X-Ways, Autopsy)
  • Experience with network forensics (Wireshark, tshark)
  • Experience with memory forensics (Volatility, MemProcFS)
  • Experience with log analysis
  • Experience with basic malware triage of executables and malicious scripts (static and behavioral)
  • Experience with live response artifact capture
  • Experience with volatile data collection
  • Experience with containment to support eradication and recovery efforts
  • Experience with timeline analysis of compromised hosts
  • Experience with conducting live response
  • Experience with performing threat hunting engagements
  • Experience with tabletop exercises
  • Experience with incident and forensic readiness assessments
  • Experience with threat-intelligence-related briefings
  • Experience with building & automating incident response processes
  • Experience with developing analytical capabilities
  • Experience with setting investigative questions
  • Experience with delegating technical analysis tasks
  • Experience with steering containment and eradication strategies
  • Experience with producing high-quality forensic and executive reports
  • Experience with peer-reviewing case notes, artifacts, and draft reports
  • Experience with leading customer calls during incidents
  • Experience with cyber crisis management
  • Experience with delivering status reports
  • Experience with planning for containment, eradication and recovery efforts
  • Experience with input to executive-ready communications
  • Experience with supporting improvement projects related to automation in digital forensics
  • Experience with developing NVISO tools and incident response processes
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with reporting
  • Experience with leading single-system forensic analysis
  • Experience with contributing to complex intrusions, including those with lateral movement
  • Experience with performing timeline analysis of compromised hosts
  • Experience with conducting live response artifact capture
  • Experience with volatile data collection
  • Experience with containment to support eradication and recovery efforts
  • Experience with recovering from incidents
  • Experience with acting as an Incident Lead
  • Experience with setting investigative questions
  • Experience with delegating technical analysis tasks
  • Experience with steering containment and eradication strategies
  • Experience with producing high-quality forensic and executive reports
  • Experience with peer-reviewing case notes, artifacts, and draft reports
  • Experience with leading customer calls during incidents
  • Experience with cyber crisis management
  • Experience with delivering status reports
  • Experience with planning for containment, eradication and recovery efforts
  • Experience with input to executive-ready communications
  • Experience with supporting improvement projects related to automation in digital forensics
  • Experience with developing NVISO tools and incident response processes
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with reporting
  • Experience with performing threat hunting engagements within customer environments
  • Experience with technical planning
  • Experience with requirements definition
  • Experience with execution
  • Experience with reporting
  • Experience with assisting in other engagements such as tabletop exercises, incident and forensic readiness assessments, and threat-intelligence-related briefings
  • Experience with acting as an incident response case lead
  • Experience with cyber intrusion analysis
  • Experience with incident response
  • Experience with digital forensics on Windows/MacOS/Unix
  • Experience with memory forensics (Volatility, MemProcFS)
  • Experience with timeline analysis (e.g., MFTECmd, KAPE, Plaso/Timesketch)
  • Experience with disk forensics (Magnet AXIOM Cyber, X-Ways, Autopsy)
  • Experience with live response tooling (e.g., Velociraptor, GRR Rapid Response, EDR live response)
  • Experience with coordinating remediation actions
  • Up-to-date knowledge on the latest cybersecurity threats and attacker TTPs
  • Excellent analytical and problem-solving skills with an eye for detail in documentation
  • Effective communication and interpersonal skills to work collaboratively with clients and cross-functional teams
  • Ability to remain calm during crisis situations and prioritize effectively under pressure
  • Language: English (must have)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles