We are seeking a skilled Cybersecurity Forensics Analyst to support corporate cybersecurity investigations, threat analysis, and incident response activities. The analyst will investigate suspicious activity, security alerts, and potential security breaches while using forensic and threat intelligence techniques to determine the scope, impact, and root cause of incidents.
The ideal candidate will have strong experience across SIEM/SOAR, EDR/XDR, network and endpoint forensics, threat intelligence, malware analysis, and security investigation methodologies.
Key Responsibilities
Investigate suspicious activities, security alerts, and potential cybersecurity breaches.
Analyze endpoint, network, application, and authentication logs.
Perform forensic analysis to determine the scope, impact, and nature of security incidents.
Identify Indicators of Compromise (IOCs) and attacker techniques.
Analyze evidence to identify patterns of malicious or unauthorized activity.
Support SOC and Incident Response teams during security investigations.
Conduct threat analysis and correlate security events across multiple data sources.
Apply MITRE ATT&CK techniques to understand and document adversary behavior.
Perform malware analysis and investigate potentially malicious files and artifacts.
Develop detailed investigation reports documenting findings, evidence, and recommendations.
Prepare concise executive-level summaries for security leadership and stakeholders.
Recommend security improvements based on investigation findings and observed attack patterns.
Assist with threat intelligence and ongoing security monitoring activities.
Key Technical Skills
Security Monitoring & Response
SIEM / SOAR
EDR / XDR
Security alert investigation
Incident response
Digital Forensics
Endpoint forensics
Network forensics
Log analysis
Authentication and application log analysis
Digital evidence analysis
Threat Analysis
Threat intelligence
MITRE ATT&CK
Indicators of Compromise (IOCs)
Attacker technique analysis
Malware analysis
Scripting & Automation
Scripting for security investigation and automation
Data collection, analysis, and correlation
Required Qualifications
Proven experience in cybersecurity investigations and digital forensics.
Strong understanding of security monitoring and incident investigation processes.
Hands-on experience with SIEM/SOAR and EDR/XDR technologies.
Experience performing endpoint and network forensic investigations.
Strong log-analysis and event-correlation skills.
Experience identifying IOCs and attacker behaviors.
Knowledge of MITRE ATT&CK and modern attack techniques.
Experience with malware analysis and threat intelligence.
Strong analytical and problem-solving skills.
Excellent technical documentation and communication abilities.
Ability to produce both detailed technical reports and concise executive summaries.
Ability to work independently in a remote environment.
Numbers & Facts
Location
Philadelphia, PA (Remote)
Skills
Analysis Skillsunmatched
Authenticationunmatched
Automationunmatched
Communication Skillsunmatched
Computer Forensicsunmatched
Computer Hackingunmatched
Computer Securityunmatched
Data Analysisunmatched
Data Collectionunmatched
Documentationunmatched
Event Correlationunmatched
Forensic Scienceunmatched
Incident Responseunmatched
Internet Securityunmatched
Investigative Reportsunmatched
Leadershipunmatched
Malware Analysisunmatched
Network Performance/Analysisunmatched
Problem Solving Skillsunmatched
Scripting (Scripting Languages)unmatched
Security Analysisunmatched
Security Attacksunmatched
Security Information and Event Management (SIEM)unmatched
Security Monitoringunmatched
Technical Writingunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.