Digital Forensics:
Job Description:
- 6+ years of experience in Digital Forensics and Incident Response.
- The successful applicant must possess one or more current, applicable professional/technical certifications, such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Security Compliance Specialist (CSCS), Certified Information Privacy Professional (CIPP), Certified Information Systems Security Professional (CISSP), Certified Internal Auditor (CIA), GPEN, GWAPT, SANS GCFA/GCFE/GSEC/GCIA/GCIH/GREM/GNFA, EnCE, CHFI, CEH, ECIH.
- Knowledge of Cyber Security management practices, network, and application vulnerability assessments, change control, business continuity planning, data privacy, and risk assessment practices.
- Proficiency with EnCase or any other forensic tool such as FTK, X-Ways, etc.
- Experience with network packets/traffic analysis using tools like Wireshark, tcpdump, Zeek, tshark, SiLK, etc.
- Experience hunting threats using SIEM and other detection platforms.
- Proficiency with Windows and -nix OS platforms.
- Experience in Incident Investigation and reporting relevant facts.
- Experience in memory analysis using tools like Volatility, Rekall, etc.
- Experience using platforms/distributions like SIFT, Remnux, FLARE, etc.
- Experience with basic static and dynamic/behavioral malware analysis. Advanced static and dynamic analysis experience would be a plus.
- Scripting skills are a plus.
- Knowledge of TCP/IP communications and how common protocols (SMTP, HTTP, POP3, IMAP, etc.) and applications work at the network.
- Ability to demonstrate analytical expertise, close attention to detail, excellent critical thinking, logic, and solution orientation and to learn and adapt quickly.
- Bachelor's Degree in Information Systems, Computer Science, or related field or equivalent or an equivalent number of years of experience.
(ref:hirist.tech)