Cybersecurity Engineer- Forensics/Risk
Listed on 2026-08-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description
Cyber Analyst
- Forensics/Insider Threat
Position Type:
Direct Hire
Compensation: $,000
Location:
Hybrid
- Salt Lake City
Experience Level: 5+ years experience
OverviewA large, multi-site organization is seeking a Cybersecurity Engineer to support and matureinsider risk,data loss prevention (DLP), and digital forensicscapabilities within a security operations environment. This role blends hands-on investigation work with detection engineering, documentation, and cross-team collaboration.
What you’ll do- Serve as a technical SME across security operations tooling and processes, including SIEM, EDR, and digital forensics platforms.
- Build and improve detections/monitoring use cases, insider risk procedures, playbooks, and technical documentation.
- Partner with security engineering/architecture stakeholders to enhance monitoring, alerting, and operational workflows.
- Mentor teammates on incident response practices, investigation methods, and tool usage.
- Respond to insider risk and DLP-related incidents, acting as an escalation point for complex or high-priority cases.
- Conduct digital forensic collections, preservation, and analysis to support internal investigations.
- Tune alerting and provide continuous improvement feedback to reduce false positives and improve fidelity.
- Support other security operations initiatives as needed.
- 2+ years of progressive hands-on experience in cybersecurity, with meaningful exposure to digital forensics and/or investigations (or an equivalent combination of education and experience).
- Experience with forensic evidence collection and investigation workflows.
- Experience supporting insider risk cases and handling sensitive investigation data with discretion.
- Experience triaging and resolving DLP incidents.
- Hands-on experience with one or more digital forensics tools/platforms (commercial or widely adopted industry tools).
- Hands-on SIEM experience, including building or refining alert logic/use cases (not only monitoring dashboards).
- Solid understanding of common attack techniques and phases of intrusion (recon? access? escalation? persistence? lateral movement? cleanup/anti-forensics).
- Strong written and verbal communication skills; able to produce clear technical documentation.
- Networking fundamentals and traffic analysis familiarity (proxies, firewalls, routing/switching concepts).
- Windows and Linux/UNIX administration fundamentals.
- Scripting/automation (Python, Power Shell, Bash, JavaScript, etc.).
- Threat hunting experience or methodology exposure.
- Forensics or incident response certifications/training (or equivalent practical experience).
Equal Employment Opportunity Statement
Gravity IT Resources is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees and applicants. We do not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, veteran status, or any other legally protected characteristic. All employment decisions are based on qualifications, merit, and business needs.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).