> Markdown version of [/jobs/ext/1275286-senior-associate-information-security-forensics](https://www.wearedevelopers.com/jobs/ext/1275286-senior-associate-information-security-forensics). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Associate, Information Security - Forensics - **Company:** Publicis Groupe - **Location:** Boston, MA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Macintosh Computers, Apple Mac Systems, Microsoft Azure, Bash Shell, Cyber Security, Linux, File Systems, Forensics Tools (Digital Forensics Software), Python (Programming Language), Log Analysis, Windows PowerShell, Phishing, Web Application Security, Software Vulnerability Management, Forensic Toolkit, Scripting, Google Cloud, Cloud Platform System, Mitre Att&ck, Malware, Cyber Threat Analysis, Encase, SentinelOne Expertise - **Published:** July 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d9b2c997f21b3175 ## About the Role * EDR Experience- CrowdStrike and/or SentinelOne with experience investigating and analyzing malware and other malicious activity. * Experience with forensics tools such as FTK, EnCase, Autopsy to collect and analyze file system artifacts, process history, application artifacts, memory collection and analysis for physical and cloud systems (Windows, Mac, Linux). * 4 or more years of experience in an analytical role of either forensics analyst (Linux, Windows, or MacOS), threat analyst, incident response, SOC analyst, or security engineer/ consultant. * Experience with cloud environments such as: Azure, AWS, GCP - knowing how to collect and analyze logs from Guard Duty/ Defender and CloudTrail, etc. * Familiarity with the MITRE ATT&CK or related frameworks. * Experience developing and managing incident response programs with focus on efficiency through AI development. * Strong communication skills with confidence leading Incident Response calls with different stakeholders; followed by producing detailed incident reports. * Proficient in social engineering, phishing, and related fraud schemes. * Strong general knowledge of security concepts and expertise in network and web application security issues. * Experience with a scripting language such as Python, Bash, PowerShell, or other scripting language in an incident handling environment. ## Description The Senior Associate, Information Security - Forensics is part of a global team and is responsible for incident response of cyber security incidents that are associated with our businesses, clients, and vendors; is technically skilled and ensures incident containment, remediation, and closure. This individual will be expected to work closely with the legal, data privacy, business, and client teams. They should be comfortable with interacting with senior executives, including C-level staff. * Visa Sponsorship is not available for this position including H1b or OPT EAD* * Incident Commander to lead investigation and response of cyber security incidents. * Analyze compromised/potentially compromised systems utilizing forensics tools. * Coordinate evidence/data gathering and document security incident reports. * Manage, review, and present written and oral reports in a pertinent, concise, and accurate manner for distribution to management. * Maintain current knowledge of tools and best practices in advanced persistent threats, tools, techniques, procedures of attackers, forensics, and incident response. * Perform complex forensic investigations into system breaches, data leaks, and system weaknesses. * Provide technical expertise to staff on security incident monitoring, triage, response, threat & vulnerability management, and security analysis. * Provide strategic direction on types of Incident Management activities that will drive efficiencies across company, including automation with AI tools. ## Related Videos - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)