Digital Forensics Incident Response Analyst_

3 days ago


Chicago, United States Insight Global Full time

Job Description * Performing rapid response and triage of security incidents, data breaches, malware infection, & other system compromises as escalated by the Cyber Defense Operations Center (CDOC) * Perform containment & eradication by assessing the situation, containing threats, & eradicating it from affected systems * Adhere to strict procedures for evidence collection, ensuring the integrity of digital evidence throughout the investigation (Chain of Custody) * Facilitate communication and collaborate with internal teams, management, and external stakeholders to provide timely updates on incident progress 2. Support forensics & investigations on Windows, Mac, and Linux platforms as well as Cloud environments (AWS, GCP, Azure) and Microsoft 365 3. Demonstrate familiarity with security controls/tooling used by TransUnion in an IR capacity, such as: * Splunk and Elasticsearch * Splunk SOAR (For case management) * Endpoint: Microsoft Defender for Endpoint, CrowdStrike, Wazuh, & Tanium * Network: Netskope SWG and CASB, Palo Alto IPS, CloudFlare WAF, Extrahop, & NetWitness * IAM: Azure AD 4. Demonstrate and provide in-depth knowledge with Threat Actor tactics, techniques, and procedures (TTPs), log analysis, network traffic analysis, and analyzing system artifacts (file system, memory, running processes, network connections) for indicators of infection/compromise 5. Provide forensic tool expertise with proficiency in using software such as Magnet Forensics, Joe Sandbox, IDA Pro, and/or Wireshark 6. Support Malware Analysis to understand its behavior and impact as well as identifying indicators of compromise (IOCs) 7. Document investigative findings in a manner aligned with TU Processes & DFIR best practices 8. Support Incident Reporting for management, legal, and regulatory purposes 9. Organize, perform, and support Cybersecurity tabletop exercises 10. When not addressing an active IR Investigation: * Lead & assist with IR process workflow improvements * Lead & assist with Threat Hunting activities to identify unknown threats and posture gaps We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com . To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: om/workforce-privacy-policy/ . Skills and Requirements * Performing rapid response and triage of security incidents, data breaches, malware infection, & other system compromises as escalated by the Cyber Defense Operations Center (CDOC) * Perform containment & eradication by assessing the situation, containing threats, & eradicating it from affected systems * Adhere to strict procedures for evidence collection, ensuring the integrity of digital evidence throughout the investigation (Chain of Custody) * Facilitate communication and collaborate with internal teams, management, and external stakeholders to provide timely updates on incident progress 2. Support forensics & investigations on Windows, Mac, and Linux platforms as well as Cloud environments (AWS, GCP, Azure) and Microsoft 365 3. Demonstrate familiarity with security controls/tooling used by TransUnion in an IR capacity, such as: * Splunk and Elasticsearch * Splunk SOAR (For case management) * Endpoint: Microsoft Defender for Endpoint, CrowdStrike, Wazuh, & Tanium * Network: Netskope SWG and CASB, Palo Alto IPS, CloudFlare WAF, Extrahop, & NetWitness * IAM: Azure AD 4. Demonstrate and provide in-depth knowledge with Threat Actor tactics, techniques, and procedures (TTPs), log analysis, network traffic analysis, and analyzing system artifacts (file system, memory, running processes, network connections) for indicators of infection/compromise 5. Provide forensic tool expertise with proficiency in using software such as Magnet Forensics, Joe Sandbox, IDA Pro, and/or Wireshark 6. Support Malware Analysis to understand its behavior and impact as well as identifying indicators of compromise (IOCs) 7. Document investigative findings in a manner aligned with TU Processes & DFIR best practices 8. Support Incident Reporting for management, legal, and regulatory purposes 9. Organize, perform, and support Cybersecurity tabletop exercises 10. When not addressing an active IR Investigation: * Lead & assist with IR process workflow improvements * Lead & assist with Threat Hunting activities to identify unknown threats and posture gaps null We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion,sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military oruniformed service member status, or any other status or characteristic protected by applicable laws, regulations, andordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to HR@insightglobal.com.



  • Chicago, United States Booz Allen Hamilton Full time

    Digital Forensics and Incident Response Analyst, Senior Key Role: Display professional and expert knowledge of incident response processes, tools, and techniques. Handle incident investigation with little oversight and make significant contributions to any incident response efforts. Participate in cyber incident response investigations requiring forensic,...


  • Chicago, United States Charles River Associates Full time

    Job OverviewCRA’s practice supports companies’ commitment to integrity by assisting them and their counsel in independently responding to allegations of fraud, waste, abuse, misconduct, and non-compliance. We are noted for deploying cross-trained teams of forensic professionals to assist our clients in gaining deeper insights and greater value more...


  • Chicago, United States Charles River Associates Full time

    About Charles River AssociatesCRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services – economic...


  • Chicago, United States bioStrategies Group Full time

    **About Charles River Associates** CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services -...


  • Chicago, United States bioStrategies Group Full time

    **About Charles River Associates** CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services -...


  • Chicago, United States Sentinel Full time

    **Responsibilities**: Qualifications: - Minimum of 3 years of experience in digital forensics, incident response, or related field - Proficiency with digital forensic tools such as EnCase, FTK, and Autopsy. - Inquisitive and curious nature to solve problems in an ever-evolving threat environment - Strong and proven knowledge of network protocols, operating...


  • Chicago, United States Palo Alto Networks Inc. Full time

    Company Description Our Mission At Palo Alto Networks everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done,...


  • Chicago, United States Civilian Office of Police Accountability Full time

    This position is open to current BIDDERS from AMERICAN FEDERATION OF STATE, COUNTY AND MUNICIPAL EMPLOYEES (AFSCME) and the PUBLIC including current City of Chicago employees in other unions or non-union positions. Only current City employees covered under the Citys collective bargaining agreement with AFSCME are considered BIDDERS and are eligible to bid....


  • Chicago, United States United Airlines Full time

    **Description**: There’s never been a more exciting time to join United Airlines. We’re on a path towards becoming the best airline in the history of aviation. Our shared purpose - Connecting People, Uniting the World - is about more than getting people from one place to another. It also means that as a global company that operates in hundreds of...


  • Chicago, United States bioStrategies Group Full time

    **About Charles River Associates** CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services -...


  • Chicago, United States TransUnion Full time

    TransUnion's Job Applicant Privacy Notice Personal Information We Collect Your Privacy Choices **What We'll Bring**: At TransUnion, we have a welcoming and energetic environment that encourages collaboration and innovation. We are consistently exploring new technologies and tools to be agile. This environment gives our people the opportunity to hone...


  • Chicago, United States bioStrategies Group Full time

    **About Charles River Associates** CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services -...


  • Chicago, United States City of Chicago Full time

    **Job Number**:395013** **Description** BID/JOB ANNOUNCEMENT - Digital Forensic Analyst - Civilian Office of Police Accountability (COPA) **Number of Positions: 1 (Additional vacancies possible pending budget approval)** **This position is open to the public and all current city employees covered under the City’s Collective Bargaining Agreement with...


  • Chicago, United States Cyber Armor Solutions Full time

    Seeking mid Detailed Position Description: We have an exciting opportunity for mid-level (4th - 6th year) associates and senior associates (7+ years) to join our Digital Assets and Data Management Group, which consists of more than 100 attorneys across the country. The associates practice would focus on proactive and reactive privacy and data protection...


  • Chicago, United States Palo Alto Networks Inc. Full time

    Company Description Our Mission At Palo Alto Networks everything starts and ends with our mission: Being the cybersecurity partner of choice, protecting our digital way of life. Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done,...


  • Chicago, Illinois, United States Charles River Associates Full time

    About Charles River AssociatesCRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strategy and operational issues to become more profitable, and advises governments on the economic impact of policies and regulations. Our two main services – economic...


  • Chicago, Illinois, United States Grant Thornton Full time

    As a Forensic Technology Senior Associate, you will get the opportunity to grow and contribute to our clients' business needs by helping them identify, mitigate, and respond to fraud, regulations, litigation, and other issues so that they can take rapid protective action, restore confidence, and get back to creating value within the Forensic Technology...


  • Chicago, United States Capgemini Full time

    **Job Description** Capgemini is looking for a consultant to manage optimization/personalization engagements and help us grow those services within our Digital Marketing practice (strategy focused, non-technical role). The ideal candidate is both analytical and creative, having a fascination with how customers engage with websites, and the knowhow to improve...


  • Chicago, Illinois, United States Danaher Full time

    At first glance, you'll see Danaher's scale. Our 65,000+ associates work across the globe at more than 15 unique operating companies within three platforms—life sciences, diagnostics, and biotechnology.Look again and you'll see the opportunity to build a meaningful career, be creative, and take risks with the support you need to be successful. You'll find...

  • DFIR Manager

    7 days ago


    Chicago, United States Iceberg Cyber Security Full time

    DFIR SPECIALIST NEEDED !!!!!!We are working with a Global leader in the Forensics industry who are looking for 2 very technical DFIR specialists. In this role you will be joining a specialized DFIR team that was set up in the early 2000s and has been renowned for dealing with some of the most high profile projects in North America.The role consists of around...