Job Description
The Security Engineer (DFIR Lab) at Group 42 is responsible for managing and maintaining the Digital Forensics and Incident Response (DFIR) Lab infrastructure which operates with high performance, fortified security and efficient operational processes. The role requires deployment of forensic tools together with protection of laboratory spaces and assistance with cybersecurity incident investigations while the team works to improve forensic capabilities through internal and external partnerships.
Job ID: 2035
Date Posted: NA
Expiration Date: NA
Apply: Click Here
Main Duties
- Maintain DFIR Lab facilities including all hardware and software and system components to deliver uninterrupted service and operational efficiency.
- Deployment of operational management of forensic and incident response tools which include EnCase and Magnet Axiom and FTK.
- Enabling security controls which implement access management, logging and monitoring and audit trails.
- Develop automation scripts and optimize workflows to improve operational efficiency and investigation processes.
- Collaborate with teams and customers to support cyber incident response and forensic investigations.
Essential Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology or any related field.
- Five years of work experience in DFIR labs or data centers or technical system environments.
- Extensive knowledge of Digital Forensics and Incident Response tools together with their associated methods.
- Possesses experience in managing enterprise IT infrastructure which includes Linux systems and networking devices.
- Practical experience with virtualization platforms and storage systems and cloud-based environments.
Preferred Qualifications
- Relevant certifications such as CCE, CHFI, GCFE, or cloud and security certifications preferred.
- Demonstrate expertise in using forensic hardware tools and handling evidence while conducting laboratory-based data acquisition procedures.
- Knowledge of SIEM, EDR, NDR, and security monitoring systems used in enterprise environments.
- Documentation abilities that include creating standard operating procedures and documenting forensic processes.