Digital Forensics Analyst Job at Professional Physical Therapy, Indianapolis, IN

  • Professional Physical Therapy
  • Indianapolis, IN

Job Description

Digital Forensics Analyst

Working Pattern: Fulltime - hybrid

Working location: Indianapolis, IN

Relocation assistance will be provided if applicable

Position Summary:

We are seeking a highly motivated DFIR Specialist to join our Purple Team. This role bridges offensive and defensive security operations by combining incident response, threat hunting, digital forensics, adversary emulation, and detection engineering. The ideal candidate enjoys investigating real-world attacks, understanding adversary behavior, improving detection capabilities, and working collaboratively with red and blue teams to strengthen security posture.

What you will be doing:

Incident Response
  • Lead or support investigations involving malware, ransomware, insider threats, and advanced persistent threats.
  • Perform endpoint, memory, disk, and cloud forensics.
  • Conduct triage activities during security incidents.
  • Coordinate containment, eradication, and recovery efforts.
  • Develop incident response playbooks and procedures.
  • Produce executive and technical incident reports.
Threat Hunting
  • Conduct proactive hunts across endpoints, identity, cloud, and network telemetry.
  • Develop hypotheses based on emerging adversary techniques.
  • Analyze attack patterns using frameworks such as MITRE ATT&CK.
  • Identify gaps in visibility and logging.
Purple Team Operations
  • Collaborate with red team operators to emulate adversary tactics.
  • Validate detections against simulated attacks.
  • Assist in planning and executing purple team exercises.
  • Measure and improve detection coverage.
  • Map detections and hunting content to ATT&CK techniques.
Detection Engineering
  • Develop and tune detections within SIEM and EDR platforms.
  • Reduce false positives while improving fidelity.
  • Create custom analytics, dashboards, and monitoring content.
  • Automate repetitive investigation tasks through scripting.
Forensics
  • Acquire and analyze forensic artifacts from:
    • Windows systems
    • Linux systems
    • Cloud environments
    • Containers
    • Identity providers
  • Perform timeline reconstruction.
  • Analyze persistence mechanisms.

Basic Qualifications:

  • Associate's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;
  • Master's degree in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • PhD in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • In lieu of a degree must have 6+ years' experience in Cyber Security or Information Technology
  • Must be a US Citizen

Preferred Qualifications:

  • 3+ years focused on incident response, threat hunting, or DFIR.
  • 6+ years' experience in Cyber Security or Information Technology
  • Experience with various memory acquisition techniques/tools:
    • FTK Imager
    • Volatility 3
    • Velociraptor for remote memory dumps
  • Experience with enterprise SIEM platforms such as:
    • Microsoft Sentinel
    • Splunk Enterprise Security
    • Elastic Security
  • Experience with EDR technologies including:
    • Microsoft Defender XDR
    • CrowdStrike Falcon
    • SentinelOne Singularity
  • Familiarity with:
    • Windows Event Logs
    • Sysmon
    • KQL
    • Sigma rules
    • YARA
    • PowerShell
    • Python
    • Memory analysis
    • Malware triage
  • Understanding of:
    • Attack chains
    • Identity-based attacks
    • Cloud attack techniques
    • Detection engineering principles
  • Experience with adversary emulation frameworks.
  • Familiarity with:
    • Caldera
    • Prelude Operator
    • Velociraptor
    • TheHive
  • Cloud security investigation experience in:
    • Microsoft Azure
    • Amazon AWS
    • Google Cloud

Certifications:

  • GIAC certifications such as GCFA, GCIH, GCFE, etc.
  • Microsoft certifications such as SC-200, SC-400, AZ-500
  • CISSP, CCSP

Our vision is to ensure that the quality and dynamism that shaped our history continues into our future. It's a bold pursuit, and we never stop striving to go further, faster, and better. We lead progress, creating the technologies that move us forward. If you're driven to grow, to learn, and to make a lasting difference, this is where you belong.

Rolls-Royce is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any protected characteristics. We are committed to providing a respectful and non-discriminatory workplace where individuality is valued and everyone can thrive.

Infinite Potential

Job Tags

Full time, Remote work, Relocation package

Similar Jobs

Blue Line Security Solutions LLC

Off Duty/Retired Police Officer Job at Blue Line Security Solutions LLC

 ...Description: Off-Duty Police Officer Required For Armed Security Shift Times: Part Time/ Weekends With Some Week Days/ Day Shift Available Hourly Pay: $35 Per Hour With Opportunities For Advancement. Location: Vernon Hills, Illinois Responsibilities:... 

Drive Time Transports

CDL-A drivers need for home WEEKLY, $.81-$.85 CPM, WEEKEND home time, $4K Bonus Job at Drive Time Transports

 ...CDL-A Regional Truck Driver Home Every Weekend , $4,000 Sign-On Bonus Pay & Miles ~$0.80 $0.85 CPM starting pay ~ Average weekly pay: $1,700+~$4,000 sign-on bonus ~ Performance bonus: up to +3 CPM based on safety, mileage, and productivity (starts first... 

Coca-Cola Company

Coca-Cola Warehouse Worker - General Laborer $18-$26/hr Job at Coca-Cola Company

Coca-Cola is seeking Warehouse Workers / General Laborers to work in distribution centers loading, unloading, picking, packing, and moving beverage products for delivery routes. Warehouse Workers are responsible for building pallets, picking orders, loading delivery trucks...

The UPS Store # 4797

The UPS Sales Associate Job at The UPS Store # 4797

 ...promptly resolve customer complaints and ensure maximum client satisfaction. To be successful as a Sales associate, you should stay up-to-date with product features and maintain our stores visual appearance in high standards. Ultimately, the duties of a sales associate... 

University of Pennsylvania

Research Associate - Epidemiology Job at University of Pennsylvania

 ...The Department of Biostatistics and Epidemiology at the Perelman School of Medicine at the University of Pennsylvania seeks candidates for several Research Associate positions in the Academic Support Staff. This appointment will be initially for one (1) year and continuation...