Sign up
Sign up
We are seeking a skilled Senior DFIR Specialist to join our team in Franklin, TN. The first 90 days in this role will be fully in-person to ensure comprehensive onboarding and training. After the initial period, the position will transition to a hybrid model, with 2 days remote and 3 days in the office each week.
The Senior Digital Forensics and Incident Response (DFIR) Specialist will work with the Security Operations Center (SOC) Incident Response (IR) and Forensics and play a critical role in the detection, analysis, and response to cybersecurity threats and incidents. This position is responsible for leading and executing advanced security operations, incident response activities, threat analytics, and forensic investigations to protect our organization’s digital assets.
Security Operations:
Utilize advanced SIEM tools to aggregate, correlate, and analyze security event data from various sources.
Incident Response:
Coordinate incident response activities, including identification, containment, eradication, and recovery from security incidents.
Develop and implement additional incident response plans, ensuring readiness to respond to security breaches and incidents.
Conduct post-incident reviews and create detailed incident reports, identifying lessons learned and recommending improvements.
Develop containment and remediation strategies for risk mitigation.
Develop automated workflows for threat detection and response.
Forensics:
Perform digital forensics investigations to collect, analyze, and preserve digital evidence in response to security incidents.
Utilize advanced forensic tools and methodologies to identify root causes and impacts of security breaches.
Collaborate with legal and compliance teams to ensure that forensic processes adhere to regulatory and legal requirements.
Threat Intelligence:
Gather and analyze threat intelligence to understand emerging threats, tactics, techniques, and procedures (TTPs) used by adversaries.
Integrate threat intelligence into SOC operations and incident response processes to enhance detection and mitigation capabilities.
Develop and implement strategies to detect and respond to advanced persistent threats (APTs).
Utilize threat intelligence platforms (TIPs) to gather and analyze threat data.
Collaboration and Training:
Work closely with other cybersecurity team members, IT staff, and business units to improve the organization’s security posture.
Provide mentorship and training to junior SOC analysts and incident responders.
Participate in security awareness training and exercises to educate employees on security best practices and response procedures.
Operational Metrics and SLOs:
Define operational metrics and KPIs.
Establish quantifiable performance indicators.
Regularly review and refine operational metrics.
Develop and monitor service level objectives (SLOs) to ensure operational excellence.
Vulnerability Management:
Conduct regular vulnerability assessments and penetration tests to identify security gaps.
Work with IT teams to remediate vulnerabilities in a timely manner.
Red Teaming and Penetration Testing:
Plan and execute red team exercises to simulate adversary tactics and techniques.
Perform regular penetration testing to identify security weaknesses and provide recommendations for improvement.
Insider Threat Detection and Mitigation:
Identify potential insider threats, assess the likelihood and impact of these threats, and prioritize mitigation efforts.
Collect and analyze information about individuals with access to sensitive resources, including employees, contractors, and vendors.
Conduct investigations into suspected insider threats and assist in responding to and remediating incidents when they occur.
Recommend and implement strategies to mitigate insider threats, including policy changes, procedural updates, and technical controls.
Monitor emerging threat trends and technologies to ensure that the organization's insider threat program remains effective and relevant.
Other Functions:
Performs other tasks as assigned.
Standard Expectations:
Complies with organizational policies, procedures, performance improvement initiatives and maintains organizational and industry policies regarding confidentiality.
Communicate clearly and effectively to persons receiving services and their family members, guests, and other members of the health care team.
Develops constructive and cooperative working relationships with others and maintains them over time.
Encourages and builds mutual trust, respect and cooperation among team members.
Required Qualifications:
Preferred Qualifications:
NA
We are seeking a skilled Senior DFIR Specialist to join our team in Franklin, TN. The first 90 days in this role will be fully in-person to ensure comprehensive onboarding and training. After the initial period, the position will transition to a hybrid model, with 2 days remote and 3 days in the office each week.
The Senior Digital Forensics and Incident Response (DFIR) Specialist will work with the Security Operations Center (SOC) Incident Response (IR) and Forensics and play a critical role in the detection, analysis, and response to cybersecurity threats and incidents. This position is responsible for leading and executing advanced security operations, incident response activities, threat analytics, and forensic investigations to protect our organization’s digital assets.