Cyber Defense Forensics Analyst
Listed on 2025-12-01
-
IT/Tech
Cybersecurity, IT Consultant, Information Security
At EY, you’ll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we’re counting on your unique voice and perspective to help EY become even better. Join us and build an exceptional experience for yourself, and a better working world for all.
TheOpportunity
Cyber Triage and Forensics (CTF) Incident Analyst will work as a senior member of the technical team responsible for security incident response an escalation point for suspected or confirmed security incidents, you will perform digital forensic analysis, follow security incident response standard methodologies, conduct malware analysis, identify indicators of compromise, support remediation or coordinate remediation efforts of a security incident, and develop documentation to support the security incident response process.
YourKey Responsibilities
- Investigate, coordinate, bring to resolution, and report on security incidents as they are brought up or identified.
- Forensically analyze end user systems and servers found to have possible indicators of compromise.
- Analyze artifacts collected during a security incident for forensic analysis.
- Identify security incidents through hunting operations within a SIEM and other relevant tools.
- Interface and connect with server owners, system custodians, and IT contacts to pursue security incident response activities, including obtaining access to systems, collecting digital artifacts, and containment and/or remediation actions.
- Provide consultation and assessment on perceived security threats.
- Maintain, manage, improve, and update security incident process and protocol documentation.
- Regularly provide reporting and metrics on case work.
- Resolve security incidents by identifying root cause and solutions.
- Analyze findings in investigative matters and develop fact‑based reports.
- Be on‑call to deliver global incident response.
- Resolution of security incidents by identifying root cause and solutions.
- Analyze findings in investigative matters and develop fact‑based reports.
- Proven integrity and judgment within a professional environment.
- Ability to appropriately balance work/personal priorities.
- Bachelor’s or Master’s Degree in Computer Science, Information Systems, Engineering or a related field.
- 5+ years experience in incident response, computer forensics analysis, and/or malware reverse engineering.
- Understanding of security threats, vulnerabilities, and incident response.
- Understanding of electronic investigation, forensic tools, and methodologies, including log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processes, and malware identification and analysis.
- Be familiar with legalities surrounding electronic discovery and analysis.
- Experience with SIEM technologies (e.g. Splunk).
- Deep understanding of both Windows and Unix/Linux based operating systems.
- Hold or be willing to pursue related professional certifications such as GCFE, GCFA, or GCIH.
- Background in security incident response in cloud‑based environments, such as Azure.
- Programming skills in Power Shell, Python, and/or C/C++.
- Understanding of the best security practices for network architecture and server configuration.
- Demonstrated integrity in a professional environment.
- Ability to work independently.
- Have a global mind‑set for working with different cultures and backgrounds.
- Knowledgeable in business industry standard security incident response process, procedures, and life cycle.
- Excellent teaming skills.
- Excellent written, verbal, and social communication skills.
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published U.S. salary range/s. At EY, we’ll develop you with future‑focused skills and equip you with world‑class experiences. We’ll empower you in a flexible environment and fuel you and your extraordinary…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).