Digital Forensics Incident Response Consultant, Data & Technology, Cybersecurity (Remote)

Ankura

Ankura is a team of excellence founded on innovation and growth.

Practice Overview

Ankura’s Cybersecurity Practice offers a full-service suite of information security and privacy solutions for clients, regardless of industry or size. We provide proactive preparedness, incident response, cyber resilience, and managed advisory services customized to clients’ requirements. The Cyber team is composed of leaders from the intelligence community, including former FBI and CIA personnel, private security firms, and pioneering technology companies. Our experts assess cyber risk and readiness, test and harden clients’ infrastructure, and respond instantly and decisively when threats arise. We regularly advise boards of directors, members of the C-suite, general counsel, outside counsel, IT leaders, and other stakeholders at all stages of any cyber incident.

Role Overview

Our Cybersecurity practice is a rapidly growing part of the Data & Technology segment of our business. Our professionals help our clients address their critical information security challenges, including incident investigation/response, as well as assessing and reducing information security risks.

This role is Remote, located in the United States.

Responsibilities

  • Participate in security incident investigations that involve computer crimes and require log, forensic, and malware analysis
  • Collect and analyze triage data, intrusion detection system alerts, firewall logs, network traffic logs, and host system logs to evaluate whether unauthorized access or information ex-filtration occurred
  • Perform forensic analyses to identify the presence of any malware, malware capabilities/actions, and what actions the malware took
  • Conduct security investigations in Linux, Apple, and/or Windows environments
  • Provide input into client communications, both written and oral, related to analyses performed for senior-level review

Qualifications

  • Bachelor’s or Master’s Degree in Computer Science/Cyber Security/MSIS or equivalent work experience
  • Experience working ransomware and BEC investigations
  • Approximately 2 – 5 years of experience working in the Incident Response space
  • Knowledge of malware reverse analysis utilizing leading industry toolsets.
  • Ability to conduct analysis of artifacts, disk images and perform memory forensics during incident response.
  • Understanding of how to communicate effectively and concisely with legal counsel, high-level management, and C-suite clients
  • Ability to approach and prioritize projects both from a long-range and immediate view
  • Experience working with non-Windows programs (such as Linux, Unix, Mac)
  • Comfortable/Experienced conducting command-line operations and utilizing scripts such as Python, PowerShell, Perl, or Bash
  • Strong desire to work on a team in a collaborative environment to achieve common goals
  • Preference is given to candidates with certifications such as CFCE, CCE, GCFE, GCFA, GCIH, GREM

For individuals assigned and/or hired to work in California, Colorado, or New York, Ankura is required to include a reasonable estimate of the compensation range for this role. This compensation range is specific to the said markets and considers a broad range of factors including but not limited to skill sets, experience and training, licensure and certifications, and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled.  The range does not include additional benefits outside of salary. At Ankura, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each role. A reasonable estimate of the current base pay range is between $65,000 to $155,000; this range is not a promise of a particular wage.

#LI-NT1

#LI-Remote

*

Ankura is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against based on disability. Equal Employment Opportunity Posters, if you have a disability and believe you need a reasonable accommodation to search for a job opening, submit an online application, or participate in an interview/assessment, please email accommodations@ankura.com or call toll-free +1.312-583-2122. This email and phone number are created exclusively to assist disabled job seekers whose disability prevents them from being able to apply online. Only messages left for this purpose will be returned. Messages left for other purposes, such as following up on an application or technical issues unrelated to a disability, will not receive a response.

To apply for this job please visit ankura.wd5.myworkdayjobs.com.