Senior Associate, Information Security - Forensics
Listed on 2025-12-20
-
IT/Tech
Cybersecurity, Information Security, Data Security
Senior Associate, Information Security – Forensics
Join to apply for the Senior Associate, Information Security – Forensics role at Publicis Re:
Sources.
Publicis Re:
Sources is the backbone of Publicis Groupe, the world’s most valuable agency group. We are the only full-service, end-to-end shared service organization in the industry, enabling Groupe agencies to do what they do best: innovate and transform for their clients. Formed in 1998 as a small team to service a few Publicis Groupe firms, Publicis Re:
Sources has grown to 6,200+ employees globally. We provide technology solutions and business services including finance, accounting, legal, benefits, procurement, tax, real estate, treasury and risk management. We continually transform to keep pace with our ever-changing communications industry and thrive on a spirit of innovation felt around the globe. Learn more about Publicis Re:
Sources and the Publicis Groupe agencies we support at
- People First, Driving Success Together
- Problem Solving Mindset
- Respect Each Other
- Partner and Collaborate as One Team
- Commit to Quality and Standards
- Innovate and Embrace the Future
The Senior Associate, Information Security – Forensics is part of a global team and is responsible for incident response of cyber security incidents that are associated with our businesses, clients, and vendors; is technically skilled and ensures incident containment, remediation, and closure. This individual will be expected to work closely with the legal, data privacy, business, and client teams. They should be comfortable with interacting with senior executives, including C‑level staff.
Salary Range: $100‑125K/yr
- Visa Sponsorship is not available for this position*
- Incident Commander to lead investigation and response of cyber security incidents.
- Analyze compromised/potentially compromised systems utilizing forensics tools.
- Coordinate evidence/data gathering and document security incident reports.
- Manage, review, and present written and oral reports in a pertinent, concise, and accurate manner for distribution to management.
- Maintain current knowledge of tools and best practices in advanced persistent threats, tools, techniques, procedures of attackers, forensics, and incident response.
- Perform complex forensic investigations into system breaches, data leaks, and system weaknesses.
- Provide technical expertise to staff on security incident monitoring, triage, response, threat & vulnerability management, and security analysis.
- Provide strategic direction on types of Incident Management activities that will drive efficiencies across company, including automation with AI tools.
- EDR Experience – Crowd Strike and/or Sentinel One with experience investigating and analyzing malware and other malicious activity.
- Experience with forensics tools such as FTK, EnCase, Autopsy to collect and analyze file system artifacts, process history, application artifacts, memory collection and analysis for physical and cloud systems (Windows, Mac, Linux).
- 4 or more years of experience in an analytical role of either forensics analyst (Linux, Windows, or MacOS), threat analyst, incident response, SOC analyst, or security engineer/ consultant.
- Experience with cloud environments such as Azure, AWS, GCP – knowing how to collect and analyze logs from Guard Duty/ Defender and Cloud Trail, etc.
- Familiarity with the MITRE ATT&CK or related frameworks.
- Experience developing and managing incident response programs with focus on efficiency through AI development.
- Strong communication skills with confidence leading Incident Response calls with different stakeholders; followed by producing detailed incident reports.
- Proficient in social engineering, phishing, and related fraud schemes.
- Strong general knowledge of security concepts and expertise in network and web application security issues.
- Experience with a scripting language such as Python, Bash, Power Shell, or other scripting language in an incident handling environment.
All your information will be kept confidential according to EEO guidelines.
This job description in no way states or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).