Jobs · Information Technology

DFIR Cybersecurity Consultant (Remote)

PNG Cyber, LLC · United States · 4 days ago
RemoteRemoteInformation TechnologyFull-time

Written by Megan Coleman

About the role

The Consultant at PNG Cyber conducts forensics work for investigative cases, serves as the incident investigator, and participates in cyber investigations as a contributing team member. This includes collecting and analyzing data, documenting analysis processes and procedures, and updating the Senior Consultant and Case Manager on results for client updates and reports. The Consultant must determine how a system or network was impacted during a cyber incident and work effectively in a rapidly changing environment.

Responsibilities

  • Actively participate in forensic analysis during Incident Response and digital forensics engagements involving ransomware, business email compromises, litigation support, and other cyber incidents.
  • Demonstrate customer-service orientation and dedication to resolving issues effectively and efficiently.
  • Listen to and understand client needs, communicating findings in a digestible format.
  • Maintain high availability and responsiveness to deadlines.
  • Communicate and engage with threat actors to resolve cybersecurity incidents.
  • Contribute to creating, developing, and introducing modern forensic techniques or solutions.
  • Engage in continuous self-development and training regarding Incident Response and Digital Forensics best practices.
  • Perform audits of computer systems and networks.
  • Produce high-quality technical reports with a strong focus on grammar, spelling, formatting, and professionalism.
  • Collaborate with the team to ensure forensics processes and procedures adhere to industry standards.
  • Work on internal projects such as coding, scripting, documentation, and creating tools related to innovation and automation.
  • Assist with EDR deployment, monitoring, and triage collection.

Requirements

  • A Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Information Security, or related fields is preferred but not required.
  • 1 to 3 years of relevant experience with a proven track record in data analysis related to ransomware, business email compromise, litigation support, and other cyber incidents.
  • Professional certifications such as GCFE, GCFA, GCIH, GNFA, GASF, CISSP, and other relevant certifications are preferred.
  • Knowledge and experience utilizing forensic tools, software, and methodologies.
  • Knowledge of scripting languages, such as C, C++, Visual Basic, Python, PowerShell, and Bash, is desirable but not required.

Schedule

Incident Response often requires sporadic and unpredictable work hours. Weekend and non-traditional work hours are necessary for the position.

Location: Remote

Similar jobs