This job is no longer available. Continue your job search here.
CIRT Forensic Inv Associate
Mandaluyong City
Job No. r00229212
Full-time
Job Description
Triage and assess reported security events to determine if an information security incident has occurred, appropriate crisis, escalation level and key communication required. Execute documented processes within all activities of the CIRT playbook and security incident response lifecycle.
Collect, preserve and process volatile information and evidences needed to conduct highly-confidential forensic investigations. Investigation of digital evidences may include:
- Storage media (i.e. hard drives, optical and flash media)
- Electronic data (i.e. electronic files, pictures, web data, technology device logs)
- Mobile devices (i.e. mobile phones, tablets)
- Volatile media (i.e. workstation memory)
Preserve the admissibility of collected evidences and Chain of Custody, in accordance with team and industry best practices. Ensure forensic evidences, and corresponding documentation, are identified, recorded, secured and accurately tracked. Investigate low to medium complexity incidents cases assigned such as, but not limited to:
- Acceptable Use Policy / Code of Business Ethics Violation
- Malware
- Fraud, Intellectual Property Theft, Industrial Espionage
- Cyber Attack / Hacking / APT / Security Breaches
- Investigation of digital evidences may include:
- •Storage media (i.e. hard drives, optical and flash media)
- Electronic data (i.e. electronic files, pictures, web data, technology device logs)
Follow forensic investigation and incident response procedures, processes, policies, guidelines.
Examine and analyze security events or incidents, and investigate low to medium complexity issues, related to technology infrastructure. Employ technical, investigative and analytical skills to solve assigned issues or problems.
Carry out or coordinate containment and remediation steps, until security incident closure, as advised by Incident Response Specialist or Manager.
Produce detailed written reports outlining the circumstances around the incident, present forensic evidences and communicate investigation results and relevant findings to a non-technical audience
Complete varied low to medium complexity and non-standard tasks in an assigned area of responsibility.
Assist with eDiscovery and litigation support to identify, preserve, collect, process, review and produce electronically stored information (ESI) for litigation purposes.
Qualifications
- Bachelor’s degree in Computer Forensic or Digital Forensic or Cyber Security
- Industry certification in multiple operating systems and/or network
- Strong hardware/ software/ OS experience
- Thinks out of the box and goes beyond the guidelines/playbook in order to resolve an issue/escalation