Cyber Triage and Forensic Senior Analyst
Listed on 2025-12-02
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
Cyber Triage and Forensic Senior Analyst
Join to apply for the Cyber Triage and Forensic Senior Analyst role at EY
.
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Today’s world is fueled by vast amounts of information. Data is more valuable than ever before, and protecting data and information systems is central to doing business.
Everyone in EY Information Security has a critical role to play.
Within Security we blend risk strategy, digital identity, cyber defense, application security, and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security‑focused individuals dedicated to supporting, protecting, and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunityCyber Triage and Forensics (CTF) Incident Analyst will work as a senior member of the technical team responsible for security incident response for EY. The candidate will serve as an escalation point for suspected or confirmed security incidents. Responsibilities include performing digital forensic analysis, following security incident response standard methodologies, malware analysis, identifying indicators of compromise, supporting remediation or coordinating remediation efforts of a security incident, and developing documentation to support the security incident response process.
YourKey Responsibilities
- Investigate, coordinate, bring to resolution, and report on security incidents as they are brought up or identified.
- Forensically analyze end‑user systems and servers found to have possible indicators of compromise.
- Perform analysis of artifacts collected during a security incident/forensic analysis.
- Identify security incidents through hunting operations within a SIEM, EDR, and other relevant tools.
- Interface and connect with server owners, system custodians, and IT contacts to pursue security incident response activities, including obtaining access to systems, collecting digital artifacts, and executing containment or remediation actions.
- Provide consultation and assessment on perceived security threats.
- Maintain, manage, improve, and update security incident process and protocol documentation.
- Regularly provide reporting and metrics on case work.
- Resolve security incidents by identifying root cause and solutions.
- Analyze findings in investigative matters and develop fact‑based reports.
- Be on‑call to deliver global incident response.
- Proven integrity and judgment within a professional environment.
- Ability to appropriately balance work/personal priorities.
- Bachelor’s or Master’s Degree in Computer Science, Information Systems, Engineering, or a related field.
- 7+ years experience in incident response, computer forensics analysis, and/or malware reverse engineering.
- Understanding of security threats, vulnerabilities, and incident response.
- Understanding of electronic investigation, forensic tools, and methodologies, including log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processes, malware identification and analysis.
- Be familiar with legalities surrounding electronic discovery and analysis.
- Experience with EDR and SIEM technologies (i.e. Splunk).
- Deep understanding of both Windows and Unix/Linux based operating systems.
- Hold or be willing to pursue related professional certifications such as GCFE, GCFA, or GREM.
- Background in security incident response in cloud‑based environments, such as Azure.
- Programming skills in Power Shell, Python, and/or C/C++.
- Understanding of the best security practices for network architecture and server configuration.
- Demonstrated integrity in a professional environment.
- Ability to work independently.
- Have a global mindset for working with different cultures and backgrounds.
- Knowledgeable in business industry standard security incident response process, procedures, and lifecycle.
- Positive…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).