Principal Analyst Cyber Security Ops - Digital...

Fresenius Medical Care
Waltham, United States of America
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 196K

Job location

Remote
Waltham, United States of America

Tech stack

Microsoft Windows
Amazon Web Services (AWS)
Audit Trail
User Authentication
Azure
Software as a Service
Cloud Computing
Computer Security
Digital Forensics
Intrusion Detection and Prevention
Python
Pcap
Linux kernel
Powershell
Zero Trust Network Access
Wireshark
Data Logging
Cloud Platform System
Okta
Office365
Mitre Att&ck
Information Technology
Gsuite
Splunk

Job description

Fresenius Medical Care's Cyber Security Operations Center (CSOC) is seeking a highly experienced Principal Analyst The Principal Cyber Security Analyst specializing in Digital Forensics serves as the senior technical authority for forensic investigations across the enterprise. This role leads complex incident response cases, conducts advanced forensic analysis of endpoints, servers, cloud environments, and networks, and provides strategic insight to reduce organizational risk. The Principal Analyst acts as the highestlevel escalation point for investigative matters and mentors other analysts in evidence handling, methodology, and tooling.

This is a U.S.-based remote position supporting Fresenius Medical Care's global Cyber Security Operations Center., + Leadenterpriselevelforensic investigations involving malware, insider threats, credential compromise, data exfiltration, fraud, and targeted attacks.

  • Act as technical commander during priority incidents, directing scoping, containment, eradication, androotcauseanalysis in partnership with IR, IT, and Cloud teams.

  • Conductrootcause, impact, and attribution analysis for major cyberevents;drive corrective and preventive actions.

  • Leadpostincidentreviews and oversee closure of remediation tasks, translating findings into hardening and control improvements.

  • Develop andmaintainforensic methodologies,chainofcustodyprocedures, andevidencehandlingstandards.

  • Serve as the primary liaison with Legal, Privacy, HR, and external law enforcement during escalated or sensitive investigations.

  • Correlate forensic artifacts withthreatintelligenceinsights toidentifyadversaries, campaigns, and TTPs.

  • Establish and maintainforensicreadinessstrategies, including tooling optimization, logging enhancements, anddataretentionstandards.

  • Develop lightweight tools and scripts (Python/PowerShell) for artifact parsing, timeline generation, triage capabilities, andcloudlognormalization.

Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent professional experience)., + 10+ years in Incident Response/DFIR, including leadership of complex,enterprise scaleinvestigations.

  • Cloud & Identity: Sentinel/Splunk, Microsoft 365/Azure logs, AWS/GCP logging, Entra/Okta audit trails.

  • Network: Zeek, Suricata, Brim/Wireshark, PCAP/flow analytics.

  • Experience inevidencehandling, legal hold/eDiscovery coordination, and working with Legal/HR/Privacy.

  • Mastery of Windows and Linux internals, authentication flows, common persistence/mechanisms, and lateral movement TTPs.

  • Proficientin Python or PowerShell for automation and artifact analysis.

  • Excellent written and verbal communication-able to brief executives clearly under time pressure.

Preferred:

  • Industry certifications (one or more): GCFA, GCFE, GNFA, GREM, GCIH, CISA, CISSP, Azure Security, AWS Security.

  • Experience with Zero Trust controls, identity threat detection, and SaaS forensics (O365, Google Workspace).

  • Familiarity with EPSS/SSVC, threat modeling, andpurpleteam/ATT&CK evaluation practices.

  • Background in regulated environments (e.g., healthcare, financial services, manufacturing) and associated audit expectations.

Benefits & conditions

The rate of pay for this position will depend on the successful candidate's work location and qualifications, including relevant education, work experience, skills, and competencies. Annual Rate: $117,700.00 - $196,200.00 for Waltham, MA location

Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave and potential for performance-based bonuses depending on company and individual performance., + The physical demands and workenvironmentcharacteristicsrepresentthose typicallyencounteredwhile performing essential duties. Reasonable accommodation may be made as needed.This is a remote role with availability expected during core hours and during escalations asrequired.

Apply for this position