Senior Analyst, Investigations and Forensics
- Salary
- $75.4/hrUSD per hour
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 27, 2026
Is this job info correct?
Senior Analyst, Investigations And Forensics
Job Details
Job Details
- Senior Analyst, Investigations and Forensics
- Location: Remote (Est preferred, but open)
- Duration: 10/12/2026 - 02/28/2027 (Contract)
- Team: Cyber Security & Response
- Serve as the team’s deep technical specialist for endpoint, cloud, and identity forensics, independently leading and executing complex investigations across insider threat, employee misconduct, IP theft, fraud, ethics breaches, and security incidents.
- Produce legally defensible findings and executive-quality investigation reports to support HR actions, litigation, regulatory response, and executive decision-making.
- Contribute to proactive detection capability development, forensic tooling, and the integration of AI into investigative workflows while maintaining evidentiary integrity and chain of custody.
- Forensic Investigations: Lead and execute end-to-end digital forensic investigations across endpoint, cloud, email, identity, and SaaS environments; perform forensic imaging and acquisition consistent with forensic standards and chain of custody.
- Forensic Investigations: Conduct deep-dive analysis for insider threat, data exfiltration, IP theft, fraud, employee misconduct, and ethics matters; support SIRT as the Advanced Forensic Tier on high-severity incidents to establish attribution, root cause, and forensic timelines.
- Forensic Investigations: Collect, preserve, and analyze digital evidence in a forensically sound manner and produce executive-quality investigation reports suitable for HR, legal review, litigation support, and regulatory disclosure.
- eDiscovery & Legal Support: Execute eDiscovery collections from Exchange/O365, cloud platforms, and endpoints in response to legal holds and regulatory requests; work with Legal to scope, collect, and produce ESI with defensible methodology and apply custodian-level scoping, deduplication, and privilege filtering.
- Technical Analysis & Tooling: Perform advanced log analysis in Google SecOps/Chronicle (YARA-L) and Splunk (SPL); extract and correlate forensic artifacts from CrowdStrike Falcon EDR; query device management platforms (JAMF, Intune, SCCM) for device attribution.
- Technical Analysis & Tooling: Analyze authentication and access events across identity platforms including Azure AD, Okta, and Zscaler; contribute to development and refinement of internal forensic tooling, detection playbooks, and investigative frameworks.
- AI-Augmented Investigation Capability: Design and build AI-assisted investigative workflows using platforms such as Anthropic Claude and Microsoft Copilot; develop prompt engineering frameworks, structured analysis pipelines, and automation logic for LLM-assisted forensic triage, timeline reconstruction, and report drafting.
- AI-Augmented Investigation Capability: Evaluate emerging AI capabilities for investigative applicability, lead proofs-of-concept, and document operationalized, auditable AI-augmented workflows.
- Stakeholder Engagement: Partner with HR, Legal, and Ethics teams as a technical advisor; maintain strict confidentiality, translate complex forensic findings into clear actionable conclusions, and provide testimony or declarations when required.
- 4+ years of progressive experience in digital forensics, cybersecurity investigations, or a closely related discipline.
- Demonstrated expertise conducting insider threat, data exfiltration, and employee misconduct investigations in enterprise environments.
- Proficiency with enterprise forensic platforms including Magnet AXIOM Cyber, Cellebrite Endpoint Collector and Endpoint Investigator, and Sumuri Recon or comparable tooling.
- Strong working knowledge of forensic imaging standards and acquisition methodologies (write-blocking, hash verification, chain of custody) aligned with frameworks such as ACPO or SWGDE.
- Hands-on proficiency with EDR platforms, particularly CrowdStrike Falcon, for behavioral analysis and forensic artifact review.
- Working knowledge of Microsoft 365 forensics including Exchange Online, Azure AD sign-ins and audit logs, Purview Compliance, and MDE.
- Solid understanding of endpoint forensics across Windows and macOS (file system artifacts, registry analysis, prefetch/MRU, browser forensics, OS-level event logs).
- Working knowledge of cloud and SaaS forensic investigation including OAuth/SAML flows, conditional access logs, cloud storage access patterns, and admin audit trails.
- Familiarity with network-layer investigation fundamentals (DNS, proxy, VPN, firewall log analysis) sufficient to reconstruct data movement and access patterns.
- Proficiency in Google SecOps/Chronicle (YARA-L) and experience using device management platforms (JAMF, Intune, SCCM) for custodian device attribution.
- Proven ability to produce legally defensible, executive-quality investigation reports.
- Experience supporting eDiscovery processes including ESI collection, legal hold execution, and custodian data scoping.
- AI Capability Building — Demonstrated hands-on experience using LLM platforms (for example Anthropic Claude or Microsoft Copilot) to augment investigative workflows; ability to design and implement structured prompting frameworks, analysis pipelines, or automation logic applying AI to forensic use cases.
- Comfort building lightweight investigative tooling using Python, PowerShell, or similar, with AI as a reasoning or enrichment layer.
- Experience working within or directly supporting corporate Legal, HR, or Ethics functions on sensitive employment or litigation matters.
- Solid grounding in incident response methodology, with experience leading or co-leading high-impact security incidents.
- Proficiency in Google SecOps/Chronicle and Splunk (SPL).
- Familiarity with Zscaler proxy log analysis and CASB telemetry.
- Prior experience testifying or providing declarations in legal, arbitration, or regulatory proceedings.
- Relevant certifications such as GCFE, GCFA, EnCE, CFCE, or CISSP.
- Pay Rate: $75.35 per hour