This position requires competency in computer forensics, evidence preservation, and information security. The primary purpose of this position is to conduct computer forensic investigations, data recovery, and incident response.
The candidate will be expected to have a solid foundation of technical experience and expertise, possess strong communication skills, and exceed our business expectations. The successful candidate will work within a CERT, under the responsibility of an Incident Response Manager and within an international cyber security group. A strong background in forensic lab practices and procedures, evidence handling, and testifying as an expert witness is required.
Experience in law enforcement, basic investigations, incident response or with a professional services firm is preferred. Will be responsible for quality of deliverables, assisting with business needs, and supporting incident response process and communication efforts.
As a Forensic Analyst within the CMA CGM group CERT, you will be: Leading and carrying out incident response investigations to determine the cause and extent of incidents. Participating in and managing forensic incident response missions (networks, systems, and malware analysis, etc.).
Conducting computer forensic investigations and electronic discovery requests for cyber security group and legal department, using proprietary methodologies and cutting-edge forensic tools.
Support the DFIR manager by communicating the progress and any issues of all assignments. • Other responsibilities:
o Participate to Cyber Defense Center transversal collaboration activities
o Participate to projects, improvements and compliance efforts related to CERT matters
Must be able to manage multiple projects and maintain a computer forensic lab on a daily basis. The ability to multi-task is critical. The successful candidate must be very detail-oriented and able to interact with other staff and clients, in person or by phone. Critical thinking, problem solving and the ability to endure long working hours is vital.
Candidate will have to pass in depth background check.
These activities are non-exhaustive and can evolve according to operational needs.
Skills
o Operating systems: Windows, Macintosh, Linux or UNIX, and DOS.
o Must have understanding of cloud technologies (Azure, AWS, etc..)
o Knowledge in Information systems security and network architecture
o General database concepts o Hardware and software troubleshooting
o Microsoft Office applications and mail systems o Intrusion and computer forensic tools such as EnCase, FTK and Magnet Axiom.
o Experience conducting security assessments, penetration testing, and ethical hacking are desirable.
o You hold relevant cybersecurity industry certifications, including: ▪ CCFE ▪ CCFP ▪ CFCE ▪ CHFI ▪ CISSP ▪ CEH
o The candidate must be able to conduct investigations on compromised computers and servers.
o Proficiency in conducting live analysis on networks, and multiple platforms is desired.
o Must possess the ability to articulate in written and oral communication.