Network Forensics Analyst - DT #7 - Remote

Compu-Vision - IT
Philadelphia, PA, United States
8 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Proxy Servers Network Analysis Computer Networks Dynamic Host Configuration Protocol Domain Name System (DNS) Networking Hardware IP Addressing Intrusion Detection and Prevention Intrusion Detection Systems Virtual Private Networks (VPN) Network Security Log Analysis
+12 more
Network Connections Network Forensics Routing Packet Analyzer Network Protocols Remote Access Technology Security Information and Event Management TCP/IP Tcpdump Wireshark Firewalls (Computer Science) Splunk

Job description

We are seeking an experienced Network Forensics Analyst to investigate cybersecurity incidents through the analysis of network traffic, communications, and related security telemetry. The role will focus on identifying malicious network activity, investigating attacker behavior, reconstructing attack timelines, and supporting incident response efforts. The ideal candidate will have strong hands-on experience with packet analysis, network security monitoring, firewall and IDS/IPS technologies, and network forensic investigation., * Analyze packet captures and network traffic associated with cybersecurity incidents.

  • Investigate suspicious network connections and anomalous communications.
  • Identify and analyze:

  • Lateral movement
  • Command-and-control (C2) traffic
  • Data exfiltration
  • Malicious protocols and network behavior
  • Analyze logs from:

  • Firewalls
  • Proxy servers
  • DNS infrastructure
  • VPN systems
  • IDS/IPS platforms
  • Network devices
  • Identify malicious or suspicious IP addresses, domains, protocols, and communication patterns.
  • Correlate network traffic with other security telemetry to reconstruct attack activity.
  • Develop detailed attack timelines and investigative findings.
  • Support incident response and threat investigation activities.
  • Document forensic evidence, analysis methodology, findings, and conclusions.
  • Prepare clear and defensible network forensic reports.
  • Communicate technical findings to security and incident response teams.

Key Technical Skills Network Analysis & Forensics

  • Wireshark
  • Zeek
  • tcpdump
  • NetworkMiner
  • Packet capture and deep packet analysis
  • Network traffic reconstruction
  • Network behavioral analysis

Security Monitoring

  • Splunk
  • Firewall technologies
  • IDS/IPS
  • VPN technologies
  • DNS/DHCP
  • Network security monitoring

Networking

  • TCP/IP
  • Network protocols
  • Routing and network communications
  • Network security architecture
  • Malicious traffic identification

Incident Response

  • Network-based incident investigation
  • Attack timeline development
  • Threat detection and analysis
  • Incident response methodologies
  • Evidence collection and documentation

Requirements

  • Proven experience in network forensics, network security analysis, or incident response.
  • Strong hands-on experience analyzing packet captures and network traffic.
  • Experience investigating suspicious communications and network-based attacks.
  • Strong understanding of TCP/IP, DNS, DHCP, and common network protocols.
  • Experience analyzing firewall, proxy, DNS, VPN, IDS/IPS, and network-device logs.
  • Ability to identify malicious IPs, domains, protocols, and network behaviors.
  • Experience investigating lateral movement, C2 communications, and data exfiltration.
  • Proficiency with tools such as Wireshark, Zeek, tcpdump, or NetworkMiner.
  • Experience using SIEM platforms such as Splunk for security investigations.
  • Strong analytical, investigative, and technical documentation skills.
  • Ability to work independently in a remote environment.

About the company

Cooper University Health Care

  • Camden, NJ About Us: At Cooper University Health Care, our commitment to providing extraordinary health care begins with our team. Our extraordinary professionals are continuously discoveri…

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Introduction to eBPF as a secure virtual machine

Ayesha Kaleem · World Congress 2023

5:02 min

Mapping distributed compute paradigms to modern vehicles

Joachim Werner · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

57 sec

Analyzing network traffic locally with open source security tooling

Chris Heilmann +2 · LIVE

4:19 min

Introduction to network security and endpoint monitoring architectures

Christoph Ruggenthaler · LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters · World Congress 2022

Videos

See all

Related articles

See all