drjobs Associate (Forensics Lead), Incident Response

Associate (Forensics Lead), Incident Response

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Hong Kong - Hong Kong

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

ASSOCIATE (FORENSICS LEAD) INCIDENT RESPONSE APAC

Who we are

S-RM is a global intelligence and cyber security consultancy. Since 2005 weve helped some of the most demanding clients in the world solve some of their toughest information security challenges.

Weve been able to do this because of our outstanding people. Were committed to developing sharp curious driven individuals who want to think critically solve complex problems and achieve success.

But we also know that work isnt everything. Its about the lives and careers it helps us build. Were immensely proud of this culture and we invest in our peoples wellbeing learning and ideas every day.

Were excited youre thinking about joining us

The role

Our Incident Response Associates are a critical part of our Cyber Security divisions success.

As a Forensics Lead on our Incident Response team you will deploy your expertise in a delivery role across our various incident response services with a particular focus on forensic investigations into complex cyber incidents.

You will work across the full lifecycle of security incidents to help our clients respond and recover including:

  • Supporting technical incident response from first contact through to closure: you will be a technical resource on response cases deploying your own expertise creating tailored strategies for response workstreams and offering guidance to colleagues on your project team. You may also be supported by more senior technical team members where appropriate.

Overseeing host- and network-based incident response investigations: including triage system recovery technical evidence collection and forensics log malware and root cause analyses..

  • Developing and sharing domain expertise: we will support you in growing your cyber expertise including sharing it with the wider team through internal initiatives and programs.
  • Participating in an on-call rotation to provide 24x7x365 client incident coverage.

Other features of the role include:

  • Variety of casework: no day will be the same. Our team responds to a huge variety of incidents for both public and corporate clients.
  • Range of opportunities: you will have opportunities to broaden your security awareness into testing and advisory projects in addition to deepening your incident response expertise.
  • Flexible working practices: responding to incidents can be intense high-pressure work. We are mindful of our teams work/life balance and offer flexible working options to support your wellbeing.

Were looking for:

  • Direct experience working in an Incident Response or Digital Forensics team is strongly preferred however candidates with exposure to working with Incident Response teams or those in roles reflecting aspects of Incident Response will be considered.
  • A fundamental understanding of computer systems and networks including:
    • Windows systems (e.g. Managing domains services creating standard build templates using SCCM moderate PowerShell capabilities etc.)
    • Networking (e.g. managing firewall rules providing guidance around network segmentation DNS etc.)
    • Virtualisation technologies (e.g. ESXi Hyper-V etc.)
    • Endpoint Detection & Response solutions.
  • The candidate must be able to demonstrate experience conducting forensic investigations in particular relating to Windows systems. Additional experience conducting investigations into Linux and MacOS systems is preferred.
  • Demonstrable understanding of core incident response workstreams including containment and restoration/recovery is a benefit.
  • A critical and investigative mindset. You should be comfortable solving problems with limited information and guidance developing proportionate strategies to achieve timely outcomes.
  • Clear demonstrable knowledge of cyber threat actors and their tactics techniques and procedures.
  • Strong communication skills. You should be comfortable speaking to people at all levels of an organization from the board of directors to the technical teams.
  • It is preferred but not required that candidates hold one of the following certifications (or equivalent) GCFE GCFA GCIH GNFA. However holding any of the following is beneficial: EnCE CFSR CISSP GREM CCNA MCFE OSCP Network and Security
  • A working proficiency in another language (such as Malay Tamil Mandarin Cantonese Vietnamese) is also beneficial although not required.

The successful candidate must have permission to work in Hong Kong by the start of their employment.


Required Experience:

IC

Employment Type

Full Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.