Cybersecurity Analyst - Forensics/Risk
Indexed description
Job Description: Cyber Analyst- Forensics/Insider Threat
Position Type: Direct Hire
Compensation: $120,000-150,000
Location: Hybrid- Salt Lake City
Experience Level: 5+ years experience
Overview
A large, multi-site organization is seeking a Cybersecurity Engineer to support and mature insider risk, data loss prevention (DLP), and digital forensics capabilities within a security operations environment. This role blends hands-on investigation work with detection engineering, documentation, and cross-team collaboration.
What you’ll do
- Serve as a technical SME across security operations tooling and processes, including SIEM, EDR, and digital forensics platforms.
- Build and improve detections/monitoring use cases, insider risk procedures, playbooks, and technical documentation.
- Partner with security engineering/architecture stakeholders to enhance monitoring, alerting, and operational workflows.
- Mentor teammates on incident response practices, investigation methods, and tool usage.
- Respond to insider risk and DLP-related incidents, acting as an escalation point for complex or high-priority cases.
- Conduct digital forensic collections, preservation, and analysis to support internal investigations.
- Tune alerting and provide continuous improvement feedback to reduce false positives and improve fidelity.
- Support other security operations initiatives as needed.
What you bring (required)
- 2+ years of progressive hands-on experience in cybersecurity, with meaningful exposure to digital forensics and/or investigations (or an equivalent combination of education and experience).
- Experience with forensic evidence collection and investigation workflows.
- Experience supporting insider risk cases and handling sensitive investigation data with discretion.
- Experience triaging and resolving DLP incidents.
- Hands-on experience with one or more digital forensics tools/platforms (commercial or widely adopted industry tools).
- Hands-on SIEM experience, including building or refining alert logic/use cases (not only monitoring dashboards).
- Solid understanding of common attack techniques and phases of intrusion (recon ? access ? escalation ? persistence ? lateral movement ? cleanup/anti-forensics).
- Strong written and verbal communication skills; able to produce clear technical documentation.
Nice to have
- Networking fundamentals and traffic analysis familiarity (proxies, firewalls, routing/switching concepts).
- Windows and Linux/UNIX administration fundamentals.
- Scripting/automation (Python, PowerShell, Bash, JavaScript, etc.).
- Threat hunting experience or methodology exposure.
- Forensics or incident response certifications/training (or equivalent practical experience).
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search