Location: Remote Duration: 1–2 Weeks with potential extension
Position Overview
We are seeking an experienced Network Forensics Analyst to investigate cybersecurity incidents through the analysis of network traffic, communications, and related security telemetry.
The role will focus on identifying malicious network activity, investigating attacker behavior, reconstructing attack timelines, and supporting incident response efforts. The ideal candidate will have strong hands-on experience with packet analysis, network security monitoring, firewall and IDS/IPS technologies, and network forensic investigation.
Key Responsibilities
Analyze packet captures and network traffic associated with cybersecurity incidents.
Investigate suspicious network connections and anomalous communications.
Identify and analyze:
Lateral movement
Command-and-control (C2) traffic
Data exfiltration
Malicious protocols and network behavior
Analyze logs from:
Firewalls
Proxy servers
DNS infrastructure
VPN systems
IDS/IPS platforms
Network devices
Identify malicious or suspicious IP addresses, domains, protocols, and communication patterns.
Correlate network traffic with other security telemetry to reconstruct attack activity.
Develop detailed attack timelines and investigative findings.
Support incident response and threat investigation activities.
Document forensic evidence, analysis methodology, findings, and conclusions.
Prepare clear and defensible network forensic reports.
Communicate technical findings to security and incident response teams.
Key Technical Skills
Network Analysis & Forensics
Wireshark
Zeek
tcpdump
NetworkMiner
Packet capture and deep packet analysis
Network traffic reconstruction
Network behavioral analysis
Security Monitoring
Splunk
Firewall technologies
IDS/IPS
VPN technologies
DNS/DHCP
Network security monitoring
Networking
TCP/IP
Network protocols
Routing and network communications
Network security architecture
Malicious traffic identification
Incident Response
Network-based incident investigation
Attack timeline development
Threat detection and analysis
Incident response methodologies
Evidence collection and documentation
Required Qualifications
Proven experience in network forensics, network security analysis, or incident response.
Strong hands-on experience analyzing packet captures and network traffic.
Experience investigating suspicious communications and network-based attacks.
Strong understanding of TCP/IP, DNS, DHCP, and common network protocols.
Experience analyzing firewall, proxy, DNS, VPN, IDS/IPS, and network-device logs.
Ability to identify malicious IPs, domains, protocols, and network behaviors.
Experience investigating lateral movement, C2 communications, and data exfiltration.
Proficiency with tools such as Wireshark, Zeek, tcpdump, or NetworkMiner.
Experience using SIEM platforms such as Splunk for security investigations.
Strong analytical, investigative, and technical documentation skills.
Ability to work independently in a remote environment.