Senior Associate, Information Security - Forensics
Listed on 2025-12-20
-
IT/Tech
Cybersecurity, Information Security
Senior Associate, Information Security - Forensics
2 days ago Be among the first 25 applicants
Company DescriptionPublicis Re:
Sources is the backbone of Publicis Groupe, the world’s most valuable agency group. We are the only full-service, end-to-end shared service organization in the industry, enabling Groupe agencies to do what they do best: innovate and transform for their clients. Formed in 1998 as a small team to service a few Publicis Groupe firms, Publicis Re:
Sources has grown to 6,200+ employees globally. We provide technology solutions and business services including finance, accounting, legal, benefits, procurement, tax, real estate, treasury and risk management. We continually transform to keep pace with our ever-changing communications industry and thrive on a spirit of innovation felt around the globe. Learn more about Publicis Re:
Sources and the Publicis Groupe agencies we support at The Publicis Re:
Sources Guiding Principles define who we are and what we stand for.
The Senior Associate, Information Security - Forensics is part of a global team and is responsible for incident response of cyber security incidents that are associated with our businesses, clients, and vendors. This role is technically skilled and ensures incident containment, remediation, and closure. The individual will work closely with the legal, data privacy, business, and client teams and must be comfortable interacting with senior executives, including C-level staff.
Salary Range: $100-125K/yr
Responsibilities- Incident Commander to lead investigation and response of cyber security incidents.
- Analyze compromised or potentially compromised systems utilizing forensics tools.
- Coordinate evidence/data gathering and document security incident reports.
- Manage, review, and present written and oral reports in a pertinent, concise, and accurate manner for distribution to management.
- Maintain current knowledge of tools and best practices in advanced persistent threats, attacker techniques, forensics, and incident response.
- Perform complex forensic investigations into system breaches, data leaks, and system weaknesses.
- Provide technical expertise to staff on security incident monitoring, triage, response, threat & vulnerability management, and security analysis.
- Provide strategic direction on Incident Management activities that will drive efficiencies across the company, including automation with AI tools.
- EDR Experience – Crowd Strike and/or Sentinel One with experience investigating and analyzing malware and other malicious activity.
- Experience with forensics tools such as FTK, EnCase, Autopsy to collect and analyze file system artifacts, process history, application artifacts, memory collection and analysis for physical and cloud systems (Windows, Mac, Linux).
- 4 or more years of experience in an analytical role as a forensics analyst (Linux, Windows, or MacOS), threat analyst, incident response, SOC analyst, or security engineer/consultant.
- Experience with cloud environments such as Azure, AWS, GCP – knowledge of collecting and analyzing logs from Guard Duty/Defender and Cloud Trail.
- Familiarity with the MITRE ATT&CK or related frameworks.
- Experience developing and managing incident response programs with a focus on efficiency through AI development.
- Strong communication skills with confidence leading Incident Response calls with different stakeholders; followed by producing detailed incident reports.
- Proficient in social engineering, phishing, and related fraud schemes.
- Strong general knowledge of security concepts and expertise in network and web application security issues.
- Experience with a scripting language such as Python, Bash, Power Shell, or another scripting language in an incident handling environment.
All your information will be kept confidential according to EEO guidelines. This job description in no way states or implies that these are the only duties to be performed by the employee(s) currently in this position. Employee(s) will be required to follow any other job related instructions and to perform any other job-related duties requested by any person authorized to give…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).