← Zurück zur Liste
Stelle · Mid-level

German Digital Forensics and Incident Response (DFIR) Consultant

Security Engineer • Mid-level • Remote • Vollzeit Niederlande Niederlande

CYPFER, a cybersecurity firm, is hiring a bilingual (English/German) DFIR consultant to handle incident response engagements, collect and analyze forensic evidence, and help remediate cyber threats.

Stack

Responsibilities

  • Engage on behalf of CYPFER in incident response tasks, interacting with insurance partners, legal counsel, incident response units, and client teams
  • Utilize standard tools and methodologies to collect forensic artifacts and images from affected systems
  • Assist with Windows forensics and triage to assess compromise and investigations
  • Apply malware analysis tools and methodologies
  • Apply mitigation strategies to remediate identified threats
  • Analyze triage collections/artifacts for indicators of compromise (IOCs) and malicious activity
  • Review logs from host systems and appliances to identify suspicious activity
  • Collect forensic disk and memory images from physical and virtual endpoints and servers
  • Correlate events and build timelines
  • Maintain current knowledge on emerging threats and vulnerabilities
  • Analyze files for IOCs using various techniques
  • Participate in a rotating on-call schedule, including weekends and outside normal business hours

Requirements

  • Bilingual English and German
  • 2+ years of experience in digital forensics, incident response, or a similar role
  • Knowledge of Windows and Unix/Linux operating systems
  • Understanding of EDR/EPP technology functionality
  • Familiarity with forensic acquisition and analysis of physical and virtual systems
  • Working knowledge of storage technologies (RAID, NAS, SAN, Fiber Channel, iSCSI, NFS)
  • Ability to analyze and interpret logs from various sources
  • Ability to perform threat research and analyze current threats
  • Understanding of business email compromise (BEC) cases and investigation techniques
  • Willingness to travel on short notice, up to 50%, to client sites

Nice to have

  • Understanding of obfuscation techniques used to conceal malicious commands and traffic
  • Familiarity with exfiltration techniques used by threat actors
  • Knowledge of SIEM and SOAR solutions
  • Experience with e-discovery tools and methodologies
  • Proficiency collecting and analyzing data from mobile devices
  • Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCF

Soft skills

Strong customer service and consulting skillsAbility to work independently with minimal supervisionCalm and composed under tough customer situationsExcellent relationship management and communication skills

About the company

CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. It is a global market leader in ransomware post-breach remediation and cyber-attack first response, collaborating with prominent insurance carriers, law firms, and Fortune 1000 businesses.

Languages: Angol: Felsőfok, Német: Felsőfok

Ähnliche Stellen