Senior Specialist, Incident Response | Digital Forensics and Incident Response (DFIR) Specialist
TechnologieDescription
ABOUT THE ROLE & TEAM
As a Digital Forensics and Incident Response (DFIR) Specialist, you will play a key role in investigating cybersecurity incidents, conducting digital forensics analyses, and supporting containment and remediation activities of security threats within SITA's global environment. You will collaborate closely with the Security Operations, CSIRT Threat, Cloud & Infrastructure, Product Security, and Corporate IT teams to address threats, preserve evidence, and determine the root causes and impacts of security incidents.
Within the Enterprise Information Security Office (EISO) and the CSIRT Response team, you will contribute to enhancing the organization's incident response capabilities, forensic investigation readiness, and cyber resilience, while supporting the protection of SITA, its clients, and the entire aviation ecosystem.
This role is ideally suited for a proactive and field-oriented cybersecurity professional, with strong investigative and analytical skills, passionate about incident response, digital forensics, and continuous improvement.
Incident Response and Coordination
- Investigate and manage cybersecurity incidents throughout the incident response lifecycle, from analysis and containment to business resumption and post-incident analysis.
- Collaborate with SOC, CSIRT, TI, Cloud, Infrastructure, and Engineering teams to effectively coordinate incident response activities and drive remediation actions.
- Produce incident reports and technical analyses, while continuously improving processes, operational guides (playbooks), and response procedures.
Digital Forensics and Evidence Management
- Conduct digital forensics investigations on workstations, servers, cloud environments, networks, and SaaS platforms, including evidence collection, preservation, analysis, and documentation.
- Analyze forensic artifacts to identify malicious activities, determine root causes, assess business impact, and support malware, ransomware, account compromise, and data breach investigations.
- Maintain rigorous evidence management and documentation practices in accordance with legal, regulatory, and industry standards.
Internal Threats and Risk Management
- Support investigations related to internal threats, policy violations, abusive use of privileged access, and potential data loss incidents, providing technical evidence and conclusions to Legal, Compliance, Human Resources, and other stakeholders.
- Identify and recommend improvements to security controls to mitigate internal threat risks and enhance the organization's overall security posture.
Tools, Automation, and Telemetry
- Develop and maintain scripts, tools, and automation solutions to enhance evidence collection, analysis, and incident response workflows.
- Leverage AI-based intelligence, security analytics, and telemetry data to improve investigation efficiency and incident response speed.
- Enhance DFIR capabilities by improving logging, forensic readiness, specialized tools, and operational processes within enterprise environments.
ABOUT YOUR SKILLS
- Demonstrated experience in digital forensics, incident response, and cybersecurity investigations in large enterprise environments.
- Practical expertise in EDR/XDR platforms, SIEM solutions, forensic tools, and security monitoring technologies.
- Strong ability to investigate and analyze security incidents affecting workstations, servers, cloud environments, networks, and identity management platforms.
- Proficiency in Python and/or PowerShell, along with good knowledge of KQL (Kusto Query Language) and other security-oriented query languages.
- Strong understanding of Tactics, Techniques, and Procedures (TTP) used by threat actors, particularly within the MITRE ATT&CK framework.
- Excellent analytical, problem-solving, and communication skills, with the ability to clearly document technical findings and present them to diverse stakeholders.
Additional Assets
- Professional certifications such as GCFA, GNFA, GCIH, GREM, GCFE, CISSP, OSCP, or equivalent certifications in DFIR and cybersecurity.
- Practical experience in cloud security investigations and DFIR activities in Azure, AWS, and/or Google Cloud Platform (GCP) environments.
- Strong mastery of digital forensics methodologies and tools, including FTK, EnCase, Velociraptor, KAPE, Autopsy, Volatility, or similar platforms.
- Experience in the aviation, transportation, critical infrastructure, or operational technology (OT) sectors, along with good knowledge of security automation and orchestration (SAO) and AI-assisted investigation techniques to improve incident response efficiency.
WHAT WE OFFER
Diversity is our reason to be. We are present in 200 countries and speak 60 different languages and cultures. We are very proud of our inclusive environment. Our offices are comfortable and pleasant workplaces, and we ensure you can also work from home. Discover what it's like to join our team and take a step further towards your best life.
Flexible Week: Work from home up to 2 days/week (depending on your team's needs).
Flexible Day: Adapt your workday to your life and projects.
Flexible Work Location: Take up to 30 days per year to work from anywhere in the world.
Employee Well-being: We cover you with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days a year. We also offer Champion Health - a personalized platform that supports a range of professional needs.
Professional Development: Enhance your skills through our training platforms, including LinkedIn Learning!
Competitive Benefits: Competitive benefits that make sense both with your local market and your employment status.
*SITA is an equal opportunity employer. We value the diversity of our workforce. As part of our employment equity program, we encourage women, Indigenous peoples, visible minorities, and/or persons with disabilities to apply and identify themselves in the application process.
- You will be required to interact with international colleagues, hence the need for excellent English language proficiency.
Cette offre a été agrégée depuis indeed. Groupe Sentinella n'est pas l'employeur; postuler vous redirige vers le site original. Le texte intégral appartient à l'auteur de l'offre.
Envie qu'on travaille pour vous ?
Inscrivez-vous au banc de talents Sentinella. On vous contacte dès qu'un mandat correspond à votre profil — y compris des postes comme celui-ci.
Rejoindre le banc de talents