DFIR Consultant

3 months ago


Canada, CA NCC Group Full time

The Opportunity:

As a consultant, you will collaborate with various individuals and divisions within our business including the Cyber Incident Response Team, Threat Intelligence teams, Security Operations Centre teams, and our esteemed Red Team.

Key Accountabilities:

  • Execution of technical tasks within our engagements.
  • Responding to emergency incidents, including mitigation and remediation activities.
  • Maintaining composure and effectiveness in client Incident Management scenarios.
  • Providing clients with high-quality technical investigations.
  • Collaborating in the identification, resolution, and documentation of security incidents.
  • The ability to discuss wider technology and security posture with a client ultimately to perform Cyber Threat assessments.
  • Strong documentation and written communication skills with technical report writing experience.

Requirements:

  • 2 to 4 years of experience in incident response, security operations or strategic security consulting
  • Experience evaluating client security controls, architecture, and operations.
  • Familiarity with coding, scripting languages (BASH, Powershell, Python, PERL, RUBY etc.) or software development frameworks (.NET).
  • Experience supporting a SOC program in incident response tools and techniques, specifically with forensics tools such as EnCase, Forensic Toolkit, etc.
  • Experience with static and dynamic malware analysis, including reverse engineering of binaries.
  • Ability to develop rules, filters, views, signatures, countermeasures and operationally relevant applications and scripts to support analysis and detection efforts.
  • Experience triaging Windows and Linux hosts.
  • Experience with Network Traffic Analysis (PCAP data).
  • Experience with Log Data Analysis.
  • Ability to produce high-quality written and verbal reports, presentations, recommendations, and findings to clients.
  • Ability to evaluate/enhance processes and procedures.
  • Experience with Cloud environments.

Behaviours:

  • Focusing on Clients and Customers
  • Working as One NCC
  • Being Inclusive and Respectful
  • Delivering Brilliantly
#J-18808-Ljbffr