Senior Security Researcher - Digital Forensics Expert
- Hunt and investigate targeted intrusions, long-dwell compromises, and espionage- driven activity across enterprise, cloud, identity, and network environments.
- Perform advanced forensics across operating systems, cloud, memory, and network telemetry; correlate signals to determine the scope of compromise.
- Build innovative tooling, research systems, and hunting/investigation workflows; identify capability gaps and propose automations to close them.
- Produce clear reports, forensic timelines, threat-actor assessments, and actionable detection and remediation guidance.
- Support internal security, threat intelligence, detection engineering, and investigation teams with expert forensic findings and technical analysis.
- Partner with the Threat Intelligence team to resolve complex intrusions in customer networks.
- Represent the organization through conference talks, workshops, and original research.
- Extensive hands-on APT hunting, intrusion investigation, and digital forensics.
- Deep understanding of APT tradecraft - stealth, persistence, credential abuse, defense evasion, living-off-the-land, custom tooling, supply-chain compromise, and command-and-control.
- Broad forensic expertise across operating systems, cloud platforms, network and edge infrastructure, and memory, using industry-standard forensic and hunting tools.
- Telemetry analysis across security platforms (EDR, SIEM, network, and identity systems) and the ability to build detection and hunting logic.
- Strong development skills in Python (and ideally another language such as Go, C/C++, or PowerShell) to build tooling, automations, and analysis pipelines.
- Strong communication for technical and executive audiences, including conference-grade presentations.
- Represents the organization publicly, delivering talks, workshops, and research at top-tier cybersecurity and forensics conferences.
Nice to Have
- Malware analysis and reverse engineering.
- Experience with enterprise EDR/XDR and SIEM platforms.
- Container, SaaS, and hybrid-cloud investigation experience.
- Threat-intel collaboration; published research or prior conference talks.