Forensics SOC Analyst- INTL India
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Investigates cyberattacks, suspicious activity, insider threats, and data leaks. Collects and preserves digital evidence from computers, emails, cloud systems, and user accounts. Partners with Security, Legal, Compliance, and HR teams on employee investigations and legal matters. Helps contain security incidents and prevent them from happening again. Creates investigation playbooks, response procedures, and improves the company’s Incident Response Program.
Requirements
eDiscovery Purview Microsoft 365 Microsoft Sentinel SIEM
· Experience conducting digital forensic investigations, including evidence collection, preservation, and timeline analysis. · Strong understanding of the eDiscovery lifecycle, legal holds, data preservation, and electronically stored information (ESI). · Experience with Microsoft Purview eDiscovery and Microsoft 365 investigative capabilities. · An investigative mindset focused on following evidence, validating assumptions, and maintaining objectivity throughout investigations. · Strong analytical skills with the ability to efficiently review large datasets and identify relevant information. · Excellent documentation and communication skills, with the ability to present findings clearly to both technical and non-technical stakeholders. · Strong attention to detail and an understanding of evidentiary handling and chain-of-custody considerations.
· While technical expertise is important, qualities such as curiosity, critical thinking, objectivity, and strong documentation skills are equally valuable for this role. Tools can be learned; an investigative mindset is much more difficult to develop. · Given our environment, candidates with experience supporting incident response, insider investigations, legal requests, or compliance-related investigations would be particularly strong fits. · These are my recommendations as we begin the hiring process. This individual will also play a key role in building the Incident Response program, developing playbooks, and enhancing the overall Incident Response Plan (IRP).
Benefits & conditions
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Top-Paying Tech Jobs (with Salaries)
Is Software Engineering Over-Saturated?
Fully Remote Software Engineer Jobs