Senior Digital Forensic Investigator
Santa Clara County, CA - USA
Job Summary
Interested candidates based outside of the designated areas are welcome to apply provided they have the indefinite right to work in the job location.
Cohesity is a leader in AI-powered data security and management. Aided by an extensive ecosystem of partners Cohesity makes it easy to secure protect manage and get value from data across the data center edge and cloud. Cohesity helps organizations defend against cybersecurity threats with comprehensive data security and management capabilities including immutable backup snapshots AI-based threat detection monitoring for malicious behavior and rapid recovery at scale.
Weve been named a Leader by multiple analyst firms and have been globally recognized for Innovation Product Strength and Simplicity in Design.
Join us on our mission to shape the future of our industry.
We are seeking a Senior Digital Forensic Investigator to serve as the operational manager of our Santa Clara Forensic Laboratory. This role combines hands-on forensic expertise with lab management and operational leadership. The successful candidate will oversee all aspects of the labs forensic acquisition imaging and chain-of-custody operations while independently executing complex investigations and supporting both the Investigations & Forensics team and Security Incident Response Team (SIRT). This role is based on-site at our Santa Clara facility with minimum 3 days/week in the lab.
Lab management responsibilities include maintaining forensic equipment managing evidence intake and processing workflows ensuring strict adherence to chain-of-custody protocols administering forensic licensing and compliance standards training team members on proper evidence handling procedures and supporting Bay Area field operations. You will exercise strong independent judgment communicate with precision and maintain the highest standards of evidentiary integrity your work directly impacts the defensibility of investigations and litigation outcomes.
HOW YOULL SPEND YOUR TIME HERE:
Forensic Investigations
Lead and execute end-to-end digital forensic investigations across endpoint cloud email identity and SaaS environments.
Conduct deep-dive analysis for insider threat data exfiltration IP theft fraud employee misconduct and ethics matter investigations.
Support SIRT as the Advanced Forensic Tier on high-severity security incidents establishing attribution root cause and precise forensic timelines.
Perform forensic imaging and acquisition of endpoints and storage media in accordance with established forensic standards and chain of custody protocols ensuring evidence integrity from collection through analysis.
Conduct structured forensic analysis using industry-standard platforms including Magnet AXIOM Cyber Cellebrite Endpoint Collector Cellebrite Endpoint Investigator and Sumuri Recon.
Collect preserve and analyze digital evidence in a forensically sound manner maintaining chain of custody and evidentiary integrity throughout.
Produce executive-quality investigation reports suitable for HR proceedings legal review litigation support and regulatory disclosure.
Lab Operations & Management
Manage the Santa Clara Forensic Laboratory as the day-to-day operational lead: oversee evidence intake storage processing workflows and maintain strict adherence to chain-of-custody protocols and forensic standards.
Maintain forensic hardware software and tools (Magnet AXIOM Cellebrite Sumuri write blockers imaging devices etc.) to ensure consistent availability and compliance with licensing and certification requirements.
Train and mentor team members on proper evidence handling forensic imaging procedures and chain-of-custody protocols; ensure compliance with internal standards and external legal/regulatory requirements.
Support field evidence collection operations across the Bay Area including onsite imaging at corporate facilities and remote locations as needed.
eDiscovery & Legal Support
Execute eDiscovery collections from Exchange/O365 cloud platforms and endpoints in response to legal holds and regulatory requests.
Work closely with Legal to scope collect and produce electronically stored information (ESI) with defensible methodology.
Apply custodian-level data scoping deduplication and privilege filtering aligned with counsels requirements.
Technical Analysis & Tooling
Perform advanced log analysis in Google SecOps/Chronicle (YARA-L) and Splunk (SPL).
Extract and correlate forensic artifacts from CrowdStrike Falcon EDR telemetry across endpoint and cloud workloads.
Query device management platforms (JAMF Intune SCCM) to build custodian device profiles and establish asset attribution in support of investigations.
Analyze authentication and access events across identity platforms including Azure AD Okta and Zscaler.
Contribute to the development and refinement of internal forensic tooling detection playbooks and investigative frameworks.
AI-Augmented Investigation Capability
Design and build AI-assisted investigative workflows using platforms such as Anthropic Claude Microsoft Copilot and related enterprise AI tools.
Develop prompt engineering frameworks structured analysis pipelines and automation logic that apply large language models to forensic triage timeline reconstruction and report drafting.
Evaluate emerging AI capabilities for investigative applicability and lead proof-of-concept development within the teams forensic environment.
Document and operationalize AI-augmented workflows so that investigative capability is repeatable auditable and defensible.
Stakeholder Engagement
Partner with HR Legal and Ethics teams as a trusted technical advisor translating complex forensic findings into clear actionable conclusions.
Maintain strict confidentiality and exercise mature judgment when handling matters involving current and former employees at all organizational levels.
Provide testimony or declarations in support of legal proceedings where required.
WED LOVE TO TALK TO YOU IF YOU HAVE MANY OF THE FOLLOWING:
7 years of progressive experience in digital forensics cybersecurity investigations or a closely related discipline.
Demonstrated expertise conducting insider threat data exfiltration and employee misconduct investigations in enterprise environments.
Proficiency with enterprise forensic platforms: Magnet AXIOM Cyber Cellebrite Endpoint Collector and Endpoint Investigator and Sumuri Recon or comparable tooling.
Strong working knowledge of forensic imaging standards and acquisition methodologies including write-blocking hash verification and documented chain of custody consistent with industry frameworks such as ACPO SWGDE or equivalent.
Hands-on proficiency with EDR platforms particularly CrowdStrike Falcon for behavioral analysis process telemetry and forensic artifact review.
Strong working knowledge of Microsoft 365 forensics: Exchange Online mail flow and Recoverable Items Azure AD sign-in and audit logs Purview Compliance and MDE.
Solid understanding of endpoint forensics across Windows and macOS: file system artifacts registry analysis prefetch/MRU data browser forensics and OS-level event logs.
Working knowledge of cloud and SaaS forensic investigation: OAuth and SAML authentication flows conditional access logs cloud storage access patterns and admin audit trails.
Familiarity with network-layer investigation fundamentals: DNS proxy VPN and firewall log analysis sufficient to reconstruct data movement and access patterns.
Proficiency in Google SecOps/Chronicle (YARA-L) for investigation and threat hunting.
Experience using device management platforms (JAMF Intune SCCM) for custodian device attribution and asset profiling in the context of investigations.
Proven ability to produce legally defensible executive-quality investigation reports with precise evidentiary grounding.
Experience supporting eDiscovery processes including ESI collection legal hold execution and custodian data scoping.
AI Capability Building Required
This team actively develops AI-augmented investigative workflows. The ability to build with AI tools is a core requirement not a nice-to-have.
Demonstrated hands-on experience using large language model (LLM) platforms such as Anthropic Claude or Microsoft Copilot to augment investigative analytical or reporting workflows.
Ability to design and implement structured prompting frameworks analysis pipelines or automation logic that apply AI to forensic use cases such as timeline synthesis log triage anomaly narration or report generation.
Comfort evaluating AI-generated output critically understanding where LLM reasoning aids investigation and where human judgment must govern evidentiary conclusions.
Experience or strong aptitude for building lightweight investigative tooling using Python PowerShell or similar with AI as a reasoning or enrichment layer.
Demonstrated ability to leverage AI tools to enhance productivity streamline workflows and support decision making
Preferred Qualifications
Experience working within or directly supporting corporate Legal HR or Ethics functions on sensitive employment or litigation matters.
Solid grounding in incident response methodology including initial triage scoping containment sequencing and post-incident analysis with experience leading or co-leading high-impact security incidents.
Proficiency in Google SecOps/Chronicle and Splunk (SPL).
Familiarity with Zscaler proxy log analysis and cloud access security broker (CASB) telemetry.
Prior experience testifying or providing declarations in legal arbitration or regulatory proceedings.
Relevant certifications: GCFE GCFA EnCE CFCE CISSP or equivalent.
What You Need to Succeed
Beyond technical skill this role demands a specific kind of professional character. You will routinely handle information that is legally privileged deeply sensitive and consequential for the individuals and the company involved.
Absolute discretion and professional confidentiality without exception.
The ability to operate independently with minimal oversight making sound judgments under ambiguity.
Strong analytical and critical thinking skills; comfort working with incomplete or conflicting data.
Clear precise written and verbal communication you know how to write for a legal audience without over-qualifying.
A bias toward evidence: you document what the data shows and you resist pressure to overreach beyond what the evidence supports.
Comfort engaging with executives legal counsel HR leadership and external parties in a professional measured manner.
A collaborative mindset this team is small trusted and operates as a unit.
Demonstrated ability to leverage AI tools to enhance productivity streamline workflows and support decision making.
Must have English language proficiency (Can interact with a degree of fluency when speaking reading and writing in a professional and specialized setting).
What Makes This Role Unique
This is not a typical SOC or DFIR role. You will be embedded in one of the most consequential investigative functions at Cohesity one that operates with the full trust and authority of Legal HR and the executive team. Your work will directly influence employment decisions litigation strategy and enterprise security posture.
You will have access to the full breadth of the enterprise forensic environment and the latitude to build improve and innovate within it. AI integration and forensic tooling development are active areas of investment for this team and you will have a meaningful role in shaping how those capabilities evolve.
#LI-EM1
Disclosure Pursuant to Applicable State Equal Pay Transparency Laws - This position has a starting pay range as listed below. Actual salary depends upon many factors including a candidates skills qualifications and experience location and salary expectations and therefore a starting salary at the low end high end or even above the stated range may be offered. This position may also be eligible for bonus compensation commission (if in a sales function) and/or equity grants. Additionally full-time employees are eligible to participate in ourcomprehensive benefits framework including health and wellness benefits vacation paid holidays and refresh days 401(k) retirement plan life and disability insurance coverages and other benefits the Company may offer from time to time.
Pay Range :
The compensation noted above is based on an annualized hourly rate assuming normal full-time employment.
Data Privacy Notice for Job Candidates:
For information on personal data processing please see our .
Equal Employment Opportunity Employer (EEOE)
Cohesity is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color creed religion sex sexual orientation national origin or nationality ancestry age disability gender identity or expression marital status veteran status or any other category protected by law.
If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process or are limited in the ability or unable to access or use this online application process and need an alternative method for applying you may contact us atCOHESITY or for assistance.
In-Office Expectations
Cohesity employees who are within a reasonable commute (e.g. within a forty-five (45) minute average travel time) work out of our core offices 2-3 days a week of their choosing.
Interested candidates based outside of the designated areas are welcome to apply provided they have the right to work in the job location.
Required Experience:
Senior IC
About Company
Cohesity gives you both data security and data management. Defend against ransomware with immutable backup, AI-based early threat detection, and rapid data recovery.