Senior Investigations Analyst – Digital Forensics
Listed on 2026-05-05
-
IT/Tech
Cybersecurity, Data Security
Who We Are
At Corebridge Financial, we believe action is everything. That’s why every day we partner with financial professionals and institutions to make it possible for more people to take action in their financial lives, for today and tomorrow.
Values- We are stronger as one:
We collaborate across the enterprise, scale what works and act decisively for our customers and partners. - We deliver on commitments:
We are accountable, empower each other and go above and beyond for our stakeholders. - We learn, improve and innovate:
We get better each day by challenging the status quo and equipping ourselves for the future. - We are inclusive:
We embrace different perspectives, enabling our colleagues to make an impact and bring their whole selves to work.
The Information Technology organization is the technological foundation of our business and works in collaboration with our partners from across the company. The team drives technology and digital transformation, partners with business leaders to design and execute new strategies through IT and operations services and ensures the necessary IT risk management and security measures are in place and aligned with enterprise architecture standards and principles.
AboutThe Role
As a Senior Investigations Analyst, you are the lead "digital detective" for the organization. You will be responsible for conducting complex, forensically sound investigations into security breaches, policy violations, and potential litigation matters. You will leverage advanced forensic suites—with a particular focus on Nuix—to parse massive datasets, recover "hidden" evidence, and build a factual narrative for legal, HR, and executive stakeholders.
ResponsibilitiesForensic Acquisition & Preservation
- Chain of Custody:
Lead the collection and preservation of digital evidence (workstations, mobile, cloud, and server logs) ensuring strict adherence to forensic standards and chain‑of‑custody protocols. - Imaging & Extraction:
Perform live and dead-box imaging of systems across diverse OS environments (Windows, macOS, Linux). - Remote Collections:
Utilize enterprise forensic tools to perform stealthy, remote data acquisitions without disrupting business operations.
- Axiom/Nuix Power User:
Utilize forensic toolsets to ingest, process, and analyze multi-terabyte datasets. You will be expected to create complex search queries, perform deduplication, and identify communication patterns across disparate data sources. - Artifact Analysis:
Investigate system artifacts (e.g. Registry, MFT, Shellbags, LNK files) to reconstruct user activity and timeline events. - Data Recovery:
Perform file carving and unallocated space analysis to recover deleted or obscured evidence. - Email & Communication Forensics:
Conduct deep-dive analysis of PST/OST files and cloud-based mail (O365/Gmail) to identify evidence of data exfiltration or collusion.
- Expert Reporting:
Translate technical forensic findings into clear, "plain English" investigative reports suitable for legal proceedings or executive review. - Interdisciplinary
Collaboration:
Act as the technical liaison for Legal, HR, and Internal Audit teams to define the scope of investigations and provide status updates on high-sensitivity cases. - Continuous Improvement:
Refine forensic workflows and laboratory standards to ensure the team stays ahead of anti-forensic techniques.
- Experience:
4+ years of experience in digital forensics and/or corporate investigations. - Forensic Toolset Mastery:
Axiom or Nuix (Highly Preferred) - Other Tools:
Advanced experience with at least two of the following:
EnCase, FTK, Autopsy or X-Ways Forensics. - Mobile Forensics:
Experience with Cellebrite UFED or Magnet Gray Key. - DLP:
Purview
- Deep understanding of file systems (NTFS, APFS, Ext4), memory forensics (Volatility), and cloud-native logging (Azure Unified Audit Log, AWS Cloud Trail).
- Scripting (Plus):
Basic ability to use Python or SQL to automate data parsing or query large investigative databases. - Preferred
Certifications:
Tool-Specific:
Nuix Workstation Forensic…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).