Digital Forensics Response Automation Analyst; DFIR Automation Analyst
Listed on 2026-02-07
-
IT/Tech
Cybersecurity, Cloud Computing
Salary Information
Salary Range: $109,190 - $166,510 annually (Determined by function, education, experience, and qualifications of the applicant.)
- Relocation Authorized:
None - Telework Type:
Full-Time Telework - Work Location:
Glendale, AZ
Since 1898, we have helped customers complete more than 25,000 projects in 160 countries on all seven continents that have created jobs, grown economies, improved the resiliency of the world's infrastructure, increased access to energy, resources, and vital services, and made the world a safer, cleaner place. Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers' objectives to create a lasting positive impact.
We serve the Infrastructure;
Nuclear, Security & Environmental;
Energy;
Mining & Metals, and the Manufacturing and Technology markets. Our services span from initial planning and investment, through start-up and operations. Core to Bechtel is our Vision, Values and Commitments. They are what we believe, what customers can expect, and how we deliver. Learn more about our extraordinary teams building inspiring projects in our Impact Report.
As a DFIR Automation Analyst, you will design and implement automation solutions that enhance core incident response capabilities. Leveraging both commercial and open-source forensic tools, you will streamline investigative workflows and improve response efficiency. You will also participate in our Incident Command pool and will lead incident response efforts as needed. This role requires close collaboration across technical and business teams to refine processes and foster a secure-by-design culture.
Strong communication skills are essential, as you’ll engage with stakeholders at all levels—translating complex technical concepts into clear, actionable insights.
- Design, implement, and continuously improve our incident response capabilities and modernize Bechtel’s computer forensics operations.
- Assist efforts to modernize our digital forensics tooling and collection processes while leveraging SOAR, Cloud infrastructure, and CI/CD pipelines.
- Develop and maintain scripts, playbooks, and integrations for forensic data collection, analysis, and reporting.
- Conduct forensic investigations across cloud (e.g., AWS, Azure, GCP, SaaS, PaaS, and IaaS) and on-premise environments to identify, preserve, and analyze evidence.
- Collaborate with security operations, IT, and engineering teams to identify automation opportunities and implement scalable solutions.
- Lead and prioritize incident response command staff efforts across the enterprise, including providing forensic analysis support and/or serving as incident commander.
- Utilize your expert communication skills to produce greater awareness of goals, projects, and tasks among customers and stakeholders.
- Participate in post-incident reviews and help implement lessons learned into automation strategies.
- Bachelor's Degree in Information Technology, Computer Science, or a related field or 8 years equivalent experience (in lieu of degree).
- Must be a United States citizen.
- 5 or more years of general information technology experience with at least 2 of those years in the area of digital forensics or incident response.
- Familiarity with SOAR (Security Orchestration, Automation, and Response) software with an emphasis on building complex playbooks for automating routine incidents.
- Familiarity with Incident Response in cloud/hybrid environments (AWS, Azure, GCP, etc).
- Demonstrated experience with Gitops, CI/CD, and infrastructure as code (IaC) solutions.
- Demonstrated knowledge of Windows, Mac, and Linux operating systems.
- Strong working knowledge of Python, Power Shell, or similar scripting languages.
- Skilled in SIEM/XDR/EDR platforms (e.g., Splunk, Sentinel, Crowd Strike) including log analysis, correlation, and detection tuning.
- Solid experience applying all facets of digital forensics and incident response to on-prem and cloud environments.
- Proven ability to manage…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).