Digital Forensics Incident Response

3 weeks ago


Phoenix, United States Cypfer Full time
Job DescriptionJob DescriptionSalary:

About Us: 

Cypfer is a true first-responder Cybersecurity organization enabling clients to return to business rapidly, the right way, following a cyber-attack. We are a global market leader in ransomware post-breach remediation and cyber-attack first response. We deliver results that far surpass market statistics for cyber-extortion and ransomware events. Our team of cybersecurity professionals works with prominent global insurance carriers, leading law firms, and Fortune 1000 businesses.


We have an exciting opening for a Digital Forensics Incident Response (DFIR) Consultant. As a Digital Forensic and Incident Response Consultant you will engage in client-facing incident response projects and offer proactive incident response services. In a collaborative setting with our team and partners, you will  assist clients during incidents, enhancing their resilience. Utilizing your technical expertise, you'll analyze intrusions, identify incidents, and guide clients through high-stress responses, ensuring clear communication and providing after-hours support when required.

Ideally, we are looking for candidates located in Phoenix, AZ, Charlotte, NC, and Seattle, WA.

 

  • You will assist in the response process, covering detection, containment, forensic investigation, and remediation. Your tasks include
  • You will perform forensic analysis, implementing incident response procedures, and analyzing malware. Identifying attack vectors, threat tactics, and attacker techniques is a crucial part of your role.
  • You will deliver verbal and written reports to clients, and actively contribute to process development and documentation.
  • You will collaborate with other team members and ensure our team’s expertise and attention to quality is second to none.
  • You will strive to find innovative ways, processes and tools to deliver on objective, faster and at a higher quality while focusing on maximizing revenue generator for the company.
  • The team you will be a contributing part of will have the primary responsibility for responding to and recovering from security incidents. As a consultant you will have direct hands-on responsibility in leading engagements and acting as role-model to other team members.
  • You will possess an in-depth understanding of technical infrastructure and recovery techniques and have strong experience working in the field.
  • You will possess a strong ability to communicate to all levels of stakeholders and provide detailed deliverables which will include reporting and recommendations.
  • On the technical front, you will possess a strong skill-set in system, application and network technologies both in configuration, installation and optimization.
  • You will have a strong hands-on capabilities with various security tool-sets including to assess, hunt and remediate threats.
  • Developing strong and rapid working client relationships is a key aspect of the role. Exceptional attention to detail and uncompromising pursuit of quality are the foundation of this role.


The successful candidate will be responsible for the following:


TECHNICAL

  • Strong experience with Velociraptor, Axiom, X-Ways, FTK, SIFT, Volatility, Splunk, ELK and Timeline analysis.
  • Strong knowledge of Windows, Active Directory, MS-SQL, Azure, AWS, Linux/Unix and Mac OS/X.
  • Must understand Networking, Routing, Switching, Firewalls, Packet Captures and Netflow.
  • A strong background knowledge of Penetration testing/Threat Actor tools and tactics, Cobalt Strike, IP Scanners, Nessus, Nexpose Kali and Metasploit are highly preferred.
  • Desirable certifications such as MCFE, EnCE, ACE, GCFA, GCFE and CISSP.
  • 7+ years of senior technical support, system administration or related customer facing role.
  • Perform cybersecurity incident response and restoration engagements including live response, triage, containment and remediation
  • System, network, application rebuild and restoration activities
  • VMWare ESX/HyperV – Knowledge of design, use and troubleshooting.
  • Knowledgeable in the Windows environment, including Windows Service and Workstation, troubleshooting and diagnosing low-level operating systems and network issues.
  • Confident with a wide range of hardware platforms including NAS, SAN, server and networking devices.
  • Passion for solving customer issues and advocating for their success, in a fast paced, highly technical environment.
  • Ability to learn new technologies quickly.
  • Ability to work independently with little direct supervision and as a part of a team.
  • Outstanding analytical and organizational abilities.
  • Strong networking background including some of the following skills:

*Network routing protocols - OSPF, BGP, EIGRP, RIP along with other network protocols DHCP, DNS, VPN, IPV4 and IPV6

*Network switching – Understand L2 and L3 switch design to include VLANS and port security

*Enterprise wireless solutions – Cisco, Aruba, FortiNet

*Firewalls - Cisco ASA, Cisco FTD, CheckPoint, FortiNet PaloAlto, Cisco Meraki

*Network traffic capture and analysis


LEADERSHIP

  • Directly contribute to revenue targets in delivering engagements
  • Responsibility over certain tool selection, evaluation, management and evolution
  • Collaborate with management and teams to ensure agility and eliminate unnecessary delays
  • Support new services and offerings to the marketplace
  • Act as a technical leader and mentor to junior consultants

BUSINESS

  • Presence at the local office if needed – Primarily a remote role with attendance at client engagement is required as required
  • Work Independently, remotely and with minimal supervision while delivering high quality outputs
  • Display an aptitude and desire for continuous learning at the leading edge of security
  • Remain current on information security, technical infrastructure and recovery techniques, emerging threat trends, and tools including methodologies to combat the same
  • A high degree of comfort in customer facing / consulting situations
  • Travel as needed to customer locations to perform reactive and proactive engagements including frequent travel with little notice. Ability to travel internationally is required, primarily around North America.
  • Adhere to policies, procedures, and security practices in accordance with assigned customer’s established practices and internal policies
  • Take meticulous notes and demonstrate strong reporting capabilities with an emphasis on detail
  • Lead and support client scoping and kick-off calls if required
  • Ability to remain calm, composed and articulate when dealing with tough customer situations.
  • Excellent relationship management, customer service and communication skills in variety of forms (written, live chat, conference calls, in-person).

Preferred Skills:

  • Proactive
  • Risk assessment and troubleshooting skills
  • Deliver table-top engagements
  • Adequately communicate findings to the clients
  • Help maintain strong client relationships
  • Stay up to date by taking company-paid and self-training

Strongly Desired:

  • Experience supporting hybrid environments
  • Experience supporting security applications such as AV, VPN, Firewall, proxy.
  • Linux troubleshooting experience a plus
  • Experience with troubleshooting Windows and Mac
  • MCP or higher
  • Unix/Linux - Have experience designing and implementing different flavors, including troubleshooting
  • Macintosh – Knowledge of and use of Macintosh/Apple OS X to include troubleshooting


Cypfer is an equal opportunity employer. If you need any accommodations or adjustments throughout the interview process and beyond, please let us know. We celebrate our inclusive work environment and welcome members of all backgrounds and perspectives to apply.


We thank you for your interest in joining the Cypfer team While we welcome all applicants, only those who are selected for an interview will be contacted.


remote work

  • Phoenix, United States Ransomware Recovery Full time

    About Us: Cypfer is a true first-responder Cybersecurity organization enabling clients to return to business rapidly, the right way, following a cyber-attack. We are a global market leader in ransomware post-breach remediation and cyber-attack first response. We deliver results that far surpass market statistics for cyber-extortion and ransomware events. Our...


  • Phoenix, United States Cypfer Full time

    Job DescriptionJob DescriptionSalary: About Us: Cypfer is a true first-responder Cybersecurity organization enabling clients to return to business rapidly, the right way, following a cyber-attack. We are a global market leader in ransomware post-breach remediation and cyber-attack first response. We deliver results that far surpass market statistics for...


  • Phoenix, United States IMRI Technology & Engineering Solutions Full time

    Job DescriptionJob DescriptionJob Description:The Incident Response Engineer must have experience for leading and coordinating incident response activities to effectively detect, analyze, and mitigate security incidents. Strong background in cybersecurity, hands-on experience with incident response procedures and tools, and a commitment to maintaining the...


  • Phoenix, United States IMRI Technology & Engineering Solutions Full time

    Job DescriptionJob DescriptionJob Description:The Incident Response Engineer must have experience for leading and coordinating incident response activities to effectively detect, analyze, and mitigate security incidents. Strong background in cybersecurity, hands-on experience with incident response procedures and tools, and a commitment to maintaining the...


  • Phoenix, United States American Express Full time

    You Lead the Way. We’ve Got Your Back. With the right backing, people and businesses have the power to progress in incredible ways. When you join Team Amex, you become part of a global and diverse community of colleagues with an unwavering commitment to back our customers, communities and each other. Here, you’ll learn and grow as we help you create...

  • Evidence Screening

    3 weeks ago


    Phoenix, United States City of Phoenix Full time

    Job ID 54036 - Location Professional & Supervisory - Full/Part Time Full-Time - Regular/Temporary Regular **ABOUT THIS POSITION**: Are you ready to make a difference in your community and Rise to Serve? Join us in making a positive impact to ensure safety, uphold justice, and become a proud member of the Phoenix Police Department family! The mission of the...


  • Phoenix, United States SentinelOne Full time

    **About Us**: SentinelOne is defining the future of cybersecurity through our XDR platform that automatically prevents, detects, and responds to threats in real-time. Singularity XDR ingests data and leverages our patented AI models to deliver autonomous protection. With SentinelOne, organizations gain full transparency into everything happening across the...

  • Incident Manager

    2 months ago


    Phoenix, United States QData Full time

    Responsibilities Record and classify received Incidents and undertake an immediate effort in order to restore a failed IT Service as quickly as possible Assign unresolved Incidents to appropriate Tier 2 Support Group Log all Incident/Service Request details allocating categorization and prioritization codes Keep users informed about their Incidents’...

  • Incident Manager

    3 weeks ago


    Phoenix, United States QData Full time

    Responsibilities Record and classify received Incidents and undertake an immediate effort in order to restore a failed IT Service as quickly as possible Assign unresolved Incidents to appropriate Tier 2 Support Group Log all Incident/Service Request details allocating categorization and prioritization codes Keep users informed about their Incidents’...

  • Incident Manager

    3 weeks ago


    Phoenix, Arizona, United States QData Full time

    Responsibilities Record and classify received Incidents and undertake an immediate effort in order to restore a failed IT Service as quickly as possible Assign unresolved Incidents to appropriate Tier 2 Support Group Log all Incident/Service Request details allocating categorization and prioritization codes Keep users informed about their Incidents' status...

  • Incident Manager

    2 months ago


    Phoenix, Arizona, United States QData Full time

    Responsibilities Record and classify received Incidents and undertake an immediate effort in order to restore a failed IT Service as quickly as possible Assign unresolved Incidents to appropriate Tier 2 Support Group Log all Incident/Service Request details allocating categorization and prioritization codes Keep users informed about their Incidents' status...

  • Latent Print

    3 weeks ago


    Phoenix, United States City of Phoenix Full time

    Job ID 54295 - Location Public Safety - Full/Part Time Full-Time - Regular/Temporary Regular **ABOUT THIS POSITION**: Are you ready to make a difference in your community and Rise to Serve? Join us in making a positive impact to ensure safety, uphold justice, and become a proud member of the Phoenix Police Department family! The mission of the Phoenix...


  • Phoenix, United States City of Phoenix Full time

    Job ID 53629 - Location Public Safety - Full/Part Time Full-Time - Regular/Temporary Regular **ABOUT THIS POSITION**: Are you ready to make a difference in your community and Rise to Serve? Join us in making a positive impact to ensure safety, uphold justice, and become a proud member of the Phoenix Police Department family! The mission of the Phoenix...

  • Firearm Examiner

    2 weeks ago


    Phoenix, United States City of Phoenix Full time

    Job ID 53742 - Location Public Safety - Full/Part Time Full-Time - Regular/Temporary Regular **ABOUT THIS POSITION**: Are you ready to make a difference in your community and Rise to Serve? Join us in making a positive impact to ensure safety, uphold justice, and become a proud member of the Phoenix Police Department family! The mission of the Phoenix...

  • Incident Manager

    3 weeks ago


    Phoenix, United States TEKsystems Full time

    *Description:* PNC is looking to add an Incident Manager to their team for the Midnight - 23:00 ET - 07:30 ET Mon-Fri EST Hours (11 PM - 7:30 AM EST) This team is Event Management; they monitor infrastructure components through various tools; alerts they get determines the processes and the remediation- critical functions within PNC. Key responsibilities:...

  • Incident Manager

    3 weeks ago


    Phoenix, United States TEKsystems Full time

    *Description:* PNC is looking to add an Incident Manager to their team for the Midnight - 23:00 ET - 07:30 ET Mon-Fri EST Hours (11 PM - 7:30 AM EST) This team is Event Management; they monitor infrastructure components through various tools; alerts they get determines the processes and the remediation- critical functions within PNC. Key responsibilities:...


  • Phoenix, United States Diverse Lynx Full time

    Role : Cyber Security Analyst Onsite : Phoenix, Arizona Location FTE JD: Ensure incident identification, assessment, quantification, reporting, communication, mitigation and monitoring Co-ordination with stakeholders, build and maintain positive working relationships with them Handling Escalated L2 cases and guiding team to remediate Provide...


  • Phoenix, United States Diverse Lynx Full time

    Role : Cyber Security Analyst Onsite : Phoenix, Arizona Location FTE JD: Ensure incident identification, assessment, quantification, reporting, communication, mitigation and monitoring Co-ordination with stakeholders, build and maintain positive working relationships with them Handling Escalated L2 cases and guiding team to remediate Provide...


  • Phoenix, United States Cable ONE Full time

    Job Description: At Cable One and our family of brands, we keep our customers and associates connected to what matters most. For our associates, that means: a thriving and rewarding career, respect for the communities where they live and work, a focus on health and wellness, an excellent work/life balance, and an open and inclusive workplace. The Escalation...


  • Phoenix, United States Mastech Digital Full time

    Mastech Digital Inc. is a (certified) Minority owned business certified by NMSDC. Public traded firm under MHH at NYSE, Established in 1986. Headquartered in Pittsburgh, PA our operations are spread across 11 Global Recruiting & Sales offices across US.Role: Site Reliability EngineerLocation: Pheonix AZDuration: FulltimeMust have:SRE - Network Engineering &...