Senior Associate, Information Security - Forensics

Publicis Groupe
Boston, MA, United States
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Artificial Intelligence Amazon Web Services Macintosh Computers Apple Mac Systems Microsoft Azure Bash Shell Cyber Security Linux File Systems Forensics Tools (Digital Forensics Software) Python (Programming Language)
+14 more
Log Analysis Windows PowerShell Phishing Web Application Security Software Vulnerability Management Forensic Toolkit Scripting Google Cloud Cloud Platform System Mitre Att&ck Malware Cyber Threat Analysis Encase SentinelOne Expertise

Job description

The Senior Associate, Information Security - Forensics is part of a global team and is responsible for incident response of cyber security incidents that are associated with our businesses, clients, and vendors; is technically skilled and ensures incident containment, remediation, and closure. This individual will be expected to work closely with the legal, data privacy, business, and client teams. They should be comfortable with interacting with senior executives, including C-level staff.

  • Visa Sponsorship is not available for this position including H1b or OPT EAD*
  • Incident Commander to lead investigation and response of cyber security incidents.
  • Analyze compromised/potentially compromised systems utilizing forensics tools.
  • Coordinate evidence/data gathering and document security incident reports.
  • Manage, review, and present written and oral reports in a pertinent, concise, and accurate manner for distribution to management.
  • Maintain current knowledge of tools and best practices in advanced persistent threats, tools, techniques, procedures of attackers, forensics, and incident response.
  • Perform complex forensic investigations into system breaches, data leaks, and system weaknesses.
  • Provide technical expertise to staff on security incident monitoring, triage, response, threat & vulnerability management, and security analysis.
  • Provide strategic direction on types of Incident Management activities that will drive efficiencies across company, including automation with AI tools.

Requirements

  • EDR Experience- CrowdStrike and/or SentinelOne with experience investigating and analyzing malware and other malicious activity.
  • Experience with forensics tools such as FTK, EnCase, Autopsy to collect and analyze file system artifacts, process history, application artifacts, memory collection and analysis for physical and cloud systems (Windows, Mac, Linux).
  • 4 or more years of experience in an analytical role of either forensics analyst (Linux, Windows, or MacOS), threat analyst, incident response, SOC analyst, or security engineer/ consultant.
  • Experience with cloud environments such as: Azure, AWS, GCP - knowing how to collect and analyze logs from Guard Duty/ Defender and CloudTrail, etc.
  • Familiarity with the MITRE ATT&CK or related frameworks.
  • Experience developing and managing incident response programs with focus on efficiency through AI development.
  • Strong communication skills with confidence leading Incident Response calls with different stakeholders; followed by producing detailed incident reports.
  • Proficient in social engineering, phishing, and related fraud schemes.
  • Strong general knowledge of security concepts and expertise in network and web application security issues.
  • Experience with a scripting language such as Python, Bash, PowerShell, or other scripting language in an incident handling environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

Videos

See all

Related articles

See all