Incident Response Forensics
Cork Ireland
At Arctic Wolf were not just navigating the cybersecurity landscape - were redefining it. Our global team of dedicated Pack members is driving innovation and setting new industry standards every day. Our impact speaks for itself: weve earned recognition on theForbes Cloud 100 CNBC Disruptor 50 Fortune Future 50 and Fortune Cyber 60lists and we recently took home the2024 CRN Products of the Yearaward. Were proud to be named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services and earning a Customers Choice distinction from Gartner Peer Insights. Our Aurora Platform also received CRNs Products of the Year award in the inaugural Security Operations Platform category. Join a company thats not only leading but also shaping the future of security operations.
Our mission is simple: End Cyber Risk. Were looking for a Incident Response Forensics Analyst to be part of making this happen.
Responsibilities
General:
Perform as an educated mid to senior-level member of the Incident Response Forensics team and as a part of the greater Arctic Wolf Incident Response team.
Deep understanding of full life-cycle cyber incident investigations from end-to-end (triage/image/log collections and analysis EDR deployment securing the environment etc.)
Applied technical and digital forensics expertise with the ability to analyze and identify IOCs RPOC vulnerabilities threats malware malicious executables etc. on Windows and Linux based systems (some Mac OS based system analysis experience is a plus)
Assist with the forensic acquisition and analysis from Azure Amazon Web services (AWS) and Google Cloud Platform (GCP) environments
Demonstrated abilities and professional experience with host-based and network-based digital forensics and security
Conduct audits and peer review of incident reports when needed
Foster information sharing and collaboration among internal forensic analyst and restoration team members
Participate in weekday escalation and weekend/holiday on call schedules when needed
Communication and Client Management:
Actively participate in large scope high impact cyber incidents and support managing Incident Response workflow and activities during incident response efforts with the client.
Regularly communicates forensic findings and inquiries via email and calls directly with the client and/or counsel team(s)
A strong work ethic self-starter and self-sufficient while being committed to meeting tight deadlines
Demonstrates professionalism has a positive attitude and is an extension of Arctic Wolfs brand in the marketplace.
Excellent verbal and written communication skills with an emphasis on customer service
Ability to write both high-level and detailed technical and executive summary reports of digital forensic findings
Qualifications
Required:
Advanced progression and professional experience involving work directly related to incident response cyber incident cases involving digital forensics data preservation configuration troubleshooting of networks and general IT knowledge
Professional hands-on experience with IR and forensics tools such as Magnet Axiom EnCase FTK X-Ways SIFT Splunk RedlineVolatility Wireshark tcpdump and open-source forensic tools
End-to-end understanding of engagements and steps within the IR workflow:initial triage collections imaging securing and hardening of the environment and overall security posture restoring/rebuilding systems and getting the client functional
Can be relied upon as a trusted resource
Adept with supporting Microsoft Windows workstations and applications
Proficient with firewalls VPNs Active Directory Group Policy Linux and Windows systems
Professional work history and experience with Hypervisors including ESXI / VMWare Hyper-V
Provide well-thought-out findings and provide professional guidance both in technical and non-technical terms to help customers re-establish business operations
Excellent relationship management customer service and communication skills in multiple forms (written conference calls in-person/virtual meetings)
Prior consulting experience within digital forensics or incident response
Preferred:
Restoration and recovery experience such as: Skilled with promoting new domain controllers seizing Flexible Single Master Operations (FSMO) roles DNS troubleshooting rebuilding System Volumes (SYSVOL) and rebuilding Distributed File System Replication (DFSR) or File Replication Service (FRS); Expertise with rebuilding and recovering Exchange Systems from Server 2010 onwards; Proficient with Active Directory/Exchange administration; Familiarity with /recover server switch on setup rebuilding virtual directories repairing databases and using recovery databases
Passionate about technology and customers and stays current on industry trends
Experience navigating networking issues related to firewalls and routers
Understanding of various backup solutions (VEEAM Datto Barracuda etc.)
About Arctic Wolf
At Arctic Wolf we foster a collaborative and inclusive work environment that thrives on diversity of thought background and culture. This is reflected in our multiple awards including Top Workplace USA (2021-2024) Best Places to Work USA (2021-2024) Great Place to Work Canada (2021-2024) Great Place to Work UK (2024) and Kununu Top Company Germany (2024). Our commitment to bold growth and shaping the future of security operations is matched by our dedication to customer satisfaction with over 7000 customers worldwide and more than 2000 channel partners globally. As we continue to expand globally and enhance our technology Arctic Wolf remains the most trusted name in the industry.
Our Values:
Arctic Wolf recognizes that success comes from delighting our customers so we work together to ensure that happens every day. We believe in diversity and inclusion and truly value the unique qualities and unique perspectives all employees bring to the organization. And we appreciate thatby protecting peoples and organizations sensitive data and seeking to end cyber risk we get to work in an industry that is fundamental to the greater good.
We celebrate unique perspectives by creating a platform for all voices to be heard through our Pack Unity program. We encourage all employees to join or create a new alliance. See more about our Pack Unity here.
We also believe and practice corporate responsibility and have recently joined the Pledge 1% Movement ensuring that we continue to give back to our community. We know that through our mission to End Cyber Risk we will continue to engage and give back to our communities.
Arctic Wolf is an Equal Opportunity Employer and considers applicants for employment without regard to race color religion sex orientation national origin age disability genetics or any other basis forbidden under federal provincial or local law. Arctic Wolf is committed to fostering a welcoming accessible respectful and inclusive environment ensuring equal access and participation for people with disabilities. As such we strive to make our entireemployeeexperience as accessible as possible and provideaccommodationsas required for candidates and employees with disabilities and/or other specific needs where possible. Please let us know if you require any accommodations by emailing
Security Requirements
Conducts duties and responsibilities in accordance with AWNs Information Security policies standards processes and controls to protect the confidentiality integrity and availability of AWN business information (in accordance with our employee handbook and corporate policies).
Background checks are required for this position.
This position may require access to information protected under U.S. export control laws and regulations including the Export Administration Regulations (EAR).Please note that if applicable an offer for employment will be conditioned on authorization to receive software or technology controlled under these U.S. export control laws and regulations.
Ready to Make an ImpactApply now with your resumeand if available your references or work samples. Join one of the fastest-growing and most innovative cybersecurity companies in the world.
Required Experience:
IC
Arctic Wolf delivers dynamic, 24x7 AI-driven cybersecurity protection tailored to the needs of your organization. Ready to boost your cyber resilience?