Digital Forensics Analyst

Rolls-Royce
Indianapolis, IN, United States
1 day ago
Apply on rollsroyce.wd3.myworkdayjobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$98,566.0 - $160,169.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Linux Digital Forensics Event Logging Intrusion Detection and Prevention Python (Programming Language) Windows PowerShell
+17 more
Red Team (Cyber Security) Kusto Query Language Security Information and Event Management Data Logging Google Cloud Cloud Platform System Mitre Att&ck Malware Cyber Threat Analysis Imager Information Technology Cybercrime Microsoft Sentinel Purple Team (Cyber Security) Splunk Epic Prelude SentinelOne Expertise

Job description

We are seeking a highly motivated DFIR Specialist to join our Purple Team. This role bridges offensive and defensive security operations by combining incident response, threat hunting, digital forensics, adversary emulation, and detection engineering. The ideal candidate enjoys investigating real-world attacks, understanding adversary behavior, improving detection capabilities, and working collaboratively with red and blue teams to strengthen security posture.

What you will be doing:

Incident Response

  • Lead or support investigations involving malware, ransomware, insider threats, and advanced persistent threats.
  • Perform endpoint, memory, disk, and cloud forensics.
  • Conduct triage activities during security incidents.
  • Coordinate containment, eradication, and recovery efforts.
  • Develop incident response playbooks and procedures.
  • Produce executive and technical incident reports.

Threat Hunting

  • Conduct proactive hunts across endpoints, identity, cloud, and network telemetry.
  • Develop hypotheses based on emerging adversary techniques.
  • Analyze attack patterns using frameworks such as MITRE ATT&CK.
  • Identify gaps in visibility and logging.

Purple Team Operations

  • Collaborate with red team operators to emulate adversary tactics.
  • Validate detections against simulated attacks.
  • Assist in planning and executing purple team exercises.
  • Measure and improve detection coverage.
  • Map detections and hunting content to ATT&CK techniques.

Detection Engineering

  • Develop and tune detections within SIEM and EDR platforms.
  • Reduce false positives while improving fidelity.
  • Create custom analytics, dashboards, and monitoring content.
  • Automate repetitive investigation tasks through scripting.

Forensics

  • Acquire and analyze forensic artifacts from:
  • Windows systems
  • Linux systems
  • Cloud environments
  • Containers
  • Identity providers
  • Perform timeline reconstruction.
  • Analyze persistence mechanisms.

Requirements

  • Associate’s degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;
  • Master’s degree in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • PhD in Cybersecurity, Computer Science, Information Technology, Mathematics OR;
  • In lieu of a degree must have 6+ years’ experience in Cyber Security or Information Technology
  • Must be a US Citizen

Preferred Qualifications:

  • 3+ years focused on incident response, threat hunting, or DFIR.
  • 6+ years’ experience in Cyber Security or Information Technology
  • Experience with various memory acquisition techniques/tools:
  • FTK Imager
  • Volatility 3
  • Velociraptor for remote memory dumps
  • Experience with enterprise SIEM platforms such as:
  • Microsoft Sentinel
  • Splunk Enterprise Security
  • Elastic Security
  • Experience with EDR technologies including:
  • Microsoft Defender XDR
  • CrowdStrike Falcon
  • SentinelOne Singularity
  • Familiarity with:
  • Windows Event Logs
  • Sysmon
  • KQL
  • Sigma rules
  • YARA
  • PowerShell
  • Python
  • Memory analysis
  • Malware triage
  • Understanding of:
  • Attack chains
  • Identity-based attacks
  • Cloud attack techniques
  • Detection engineering principles
  • Experience with adversary emulation frameworks.
  • Familiarity with:
  • Caldera
  • Prelude Operator
  • Velociraptor
  • TheHive
  • Cloud security investigation experience in:
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud

Certifications:

  • GIAC certifications such as GCFA, GCIH, GCFE, etc.
  • Microsoft certifications such as SC-200, SC-400, AZ-500
  • CISSP, CCSP

Our vision is to ensure that the quality and dynamism that shaped our history continues into our future. It’s a bold pursuit, and we never stop striving to go further, faster, and better. We lead progress, creating the technologies that move us forward. If you’re driven to grow, to learn, and to make a lasting difference, this is where you belong.

Benefits & conditions

Rolls-Royce provides a comprehensive and competitive Total Rewards package that includes base pay and a discretionary bonus plan. Eligible employees may have the opportunity to enroll in other benefits, including health, dental, vision, disability, life and accidental death & dismemberment insurance; a flexible spending account; a health savings account; a 401(k) retirement savings plan with a company match; Employee Assistance Program; Paid Time Off; certain paid holidays; paid parental and family care leave; tuition reimbursement; and a long-term incentive plan. The options available to an employee may vary depending on eligibility factors such as date of hire, employment type, and the applicability of collective bargaining agreements.

About the company

At Rolls-Royce we are proud to be a business that has truly helped to shape the modern world and are committed to always being a force for progress; powering, protecting and connecting people everywhere.

By joining Rolls-Royce, you’ll have the opportunity to create world-class power and propulsion solutions, pushing your problem-solving and ingenuity, to deliver real impact that puts safety first.

You’ll be given responsibility and the opportunity to grow in our high-performance culture. This is Infinite Potential. And it’s your chance to really shine and contribute to one of the world’s most recognized brands and a beacon for engineering excellence.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on rollsroyce.wd3.myworkdayjobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:01 min

Live text-to-image generation and image editing implementation

Joerg Krall Joerg Krall · World Congress 2026 Europe

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

2:52 min

Directing image generation using contrastive language image pre-training

Ekaterina Sirazitdinova · LIVE

Videos

See all

Related articles

See all