Digital Forensics Response Automation Analyst; DFIR Automation Analyst
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Cloud Computing
Requisition : 289405
- Relocation Authorized:
None - Telework Type:
Full-Time Telework - Work Location:
Glendale, AZ - Salary Range: $109,190 - $166,510 annually (Determined by function, education, experience, and qualifications of the applicant.)
Job Summary:
As a DFIR Automation Analyst, you will design and implement automation solutions that enhance core incident response capabilities. You will leverage both commercial and open-source forensic tools to streamline investigative workflows and improve response efficiency. You will participate in the Incident Command pool and lead incident response efforts as needed. This role requires close collaboration across technical and business teams to refine processes and foster a secure-by-design culture.
Strong communication skills are essential, as you ll engage with stakeholders at all levels—translating complex technical concepts into clear, actionable insights.
- Design, implement, and continuously improve our incident response capabilities and modernize Bechtel s computer forensics operations.
- Assist efforts to modernize our digital forensics tooling and collection processes while leveraging SOAR, Cloud infrastructure, and CI/CD pipelines.
- Develop and maintain scripts, playbooks, and integrations for forensic data collection, analysis, and reporting.
- Conduct forensic investigations across cloud (e.g., AWS, Azure, GCP, SaaS, PaaS, and IaaS) and on-premise environments to identify, preserve, and analyze evidence.
- Collaborate with security operations, IT, and engineering teams to identify automation opportunities and implement scalable solutions.
- Lead and prioritize incident response command staff efforts across the enterprise, including providing forensic analysis support and/or serving as incident commander.
- Utilize your expert communication skills to produce greater awareness of goals, projects, and tasks amongst customers and stakeholders.
- Participate in post-incident reviews and help implement lessons learned into automation strategies.
- Bachelor s Degree in Information Technology, Computer Science, or a related field or 8 years equivalent experience (in lieu of degree).
- Must be a United States citizen.
- 5 or more years of general information technology experience with at least 2 of those years in the area of digital forensics or incident response.
- Familiarity with SOAR (Security Orchestration, Automation, and Response) software with an emphasis on building complex playbooks for automating routine incidents.
- Familiarity with Incident Response in cloud/hybrid environments (AWS, Azure, GCP, etc).
- Demonstrated experience with Gitops, CI/CD, and infrastructure as code (IaC) solutions.
- Demonstrated knowledge of Windows, Mac, and Linux operating systems.
- Strong working knowledge of Python, Power Shell, or similar scripting languages.
- Skilled in SIEM/XDR/EDR platforms (e.g., Splunk, Sentinel, Crowd Strike) including log analysis, correlation, and detection tuning.
- Solid experience applying all facets of digital forensics and incident response to on-prem and cloud environments.
- Proven ability to manage yourself, prioritize tasks, and produce high-quality results in a fast-paced environment.
- Able to work across team boundaries, reach consensus amongst disparate viewpoints, and graciously receive feedback.
- Strong analytical, documentation, and communication skills.
For decades, Bechtel has worked to inspire the next generation of employees and beyond. Because our teams face some of the world s toughest challenges, we offer robust benefits to ensure our people thrive. Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth.
Learn more at Bechtel Total Rewards.
As a global company, Bechtel has long been home to a vibrant multitude of nationalities, cultures, ethnicities, and life experiences. This diversity has made us a more trusted partner, more effective problem solvers and innovators, and a more attractive destination for leading…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).