Talent.com
Digital Forensic & Incident Response Lead Engineer (hybrid)
Digital Forensic & Incident Response Lead Engineer (hybrid)Cencora • Carrollton, TX
Digital Forensic & Incident Response Lead Engineer (hybrid)

Digital Forensic & Incident Response Lead Engineer (hybrid)

Cencora • Carrollton, TX
30+ days ago
Job type
  • Full-time
Job description

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!

Job Details

As a highly skilled Digital Forensic & Incident Response Lead Engineer , you will be in a foundational role in the Cencora Global Security Operations Center. You will contribute thought leadership and expertise to the continued growth of our digital forensics incident response program. You will work closely with other team members to perform threat detection and incident response while providing provide expert-level guidance to junior analysts and other teams within the organization.

The ideal candidate will have extensive experience in digital and network forensics, incident response, and cybersecurity operations in large, international organizations. Must be comfortable leading internal investigations and forensic examination including evidence acquisition from cloud, on-premise, and remote systems while ensuring chain of custody is maintained and that applicable rules of evidence are adhered to.

This position offers hybrid work options in Carrollton, TX

Manage overall case load and assist with forensic analysis and reporting of case workload when required.

Manage evidence Intake / Outtake and Evidence Storage.

Use advanced network traffic analysis techniques to identify compromised systems, negate denial of service attacks, and pinpoint resource anomalies.

Leads cyber incident response engagements as a senior incident response leader.

Serves as a backup to the Continuous Security Operations Regional Manager.

Support Continuous Security Operations colleagues with complex and comprehensive event and incident analysis.

Collaborates with Cyber Engineering, Vulnerability Management, Threat Intelligence, Attack Surface Reduction, Data Protection and Enterprise IT to elevate Cencora’s security posture to next level of maturity.

Oversee development of staff to ensure digital forensics procedures are conducted in accordance with policy and best practices.

Effectively investigative and conduct root cause analysis, identifying indicators of attack or compromise, attack vectors.

Deliver verbal and written reports as needed.

Participates in on-call rotation (including weekends) to ensure continuous operations.

Participates in internal incident response exercises and drills.

Conducts knowledge transfer training sessions to Security Operations team upon technology implementation.

Develops, reviews, follows, and implements new runbooks and standard operating procedures.

BA / BS degree highly desired but flexible with experience

Six (6) or more years of combined security work experience across Cyber Security, Digital Forensics, and Incident Response.

Strong experience with Axiom, FTK, SIFT, Volatility, and Timeline analysis.

Two (2) years of experience in a lead role (highly desired)

Strong knowledge of Microsoft Windows, Active Directory, MS-SQL, Azure, etc.

Strong knowledge of Linux / Unix, Mac and AWS.

Understand networking, packet captures and NetFlow.

Hands-on experience and the following tool categories : SIEM, EDR, email securitygateway, SOAR, Firewall, Anti-virus, secure web gateway, DNS

Practical experience handling sophisticated and high-priority cyber incidents

Deep understanding of cyber security industry frameworks (e.g. MITRE ATT&CK, D3FEND, NIST, Cyber Killschain, etc.)

Experience in Python, PowerShell, Bash or any other scripting languages.

Excellent written communication skills, with a focus on translating technically complex issues into simple, easy-to-understand concepts in English.

Must have DFIR related certification such as GCFE, GCFA, GNFA, CFCE, etc.

Preferred certifications include MCCE, MCFE, GCFR.

#LI-MD1

What Cencora offers

We provide compensation, benefits, and resources that enable a highly inclusive culture and support our team members’ ability to live with purpose every day. In addition to traditional offerings like medical, dental, and vision care, we also provide a comprehensive suite of benefits that focus on the physical, emotional, financial, and social aspects of wellness. This encompasses support for working families, which may include backup dependent care, adoption assistance, infertility coverage, family building support, behavioral health solutions, paid parental leave, and paid caregiver leave. To encourage your personal growth, we also offer a variety of training programs, professional development resources, and opportunities to participate in mentorship programs, employee resource groups, volunteer activities, and much more.

Create a job alert for this search

Incident Response Engineer • Carrollton, TX

Related jobs
Security Practice Lead (Nationwide)

Security Practice Lead (Nationwide)

Presidio Networked Solutions, LLC • Irving, TX, United States
Full-time
Presidio, Where Teamwork and Innovation Shape the Future.AtPresidio, we're at the forefront of a global technology revolution, transforming industries throughcutting-edge digital solutions and next...Show more
Last updated: 30+ days ago • Promoted
Cyber Incident Manager III

Cyber Incident Manager III

NewGen Technologies • Arlington, Texas, USA
Full-time
Our Partner is support a US Government customer to provide support for onsite incident response to civilian Government agencies and critical asset owners who experience cyber-attacks bringing immed...Show more
Last updated: 21 days ago • Promoted
Lean Capability Development Leader

Lean Capability Development Leader

Brinks • Coppell, TX, US
Full-time
The Brink's Company (NYSE : BCO) is a leading global provider of cash and valuables management, digital retail solutions, and ATM managed services. Our customers include financial institutions, re...Show more
Last updated: 30+ days ago • Promoted
Cyber Security Architect

Cyber Security Architect

Arkadia Search Recruiting • Arlington, TX, United States
Full-time
Our client is growing a highly trusted Cybersecurity function with executive level support and the freedom to implement advanced solutions. This team plays a critical role in protecting company syst...Show more
Last updated: 5 days ago • Promoted
Enterprise Business Analyst – IT Governance & Compliance Projects

Enterprise Business Analyst – IT Governance & Compliance Projects

Jobot • Coppell, TX, US
Full-time
Hybrid Oppty - Exciting opportunity for an Enterprise Business Analyst kto drive structured analysis and documentation across IT Governance & Compliance Projects!. This Jobot Consulting Job is hoste...Show more
Last updated: 30+ days ago • Promoted
Lead, Security Assurance (Coppell)

Lead, Security Assurance (Coppell)

Request Technology, LLC • Coppell, TX, United States
Full-time
Location : Chicago, IL or Coppell, TX.Hybrid : 3 days onsite, 2 days remote.We are unable to provide sponsorship for this role •. Information Security experience, preferably within previous work in Com...Show more
Last updated: 5 days ago • Promoted
Cybersecurity Architect (Arlington)

Cybersecurity Architect (Arlington)

Talent Groups • Arlington, TX, United States
Full-time +1
Full-Time, Direct Hire (No C2C or sponsorship available).Talent Groups is seeking an experienced Cybersecurity Architect to provide strategic security guidance across complex IT and business enviro...Show more
Last updated: 5 days ago • Promoted
Senior Director - Catastrophe Management Analytics

Senior Director - Catastrophe Management Analytics

Aon • Farmers Branch, TX, United States
Full-time +1
Aon is looking for a Senior Director - Catastrophe Modeling - Boston, NYC, Bloomington, Atlanta, Dallas or Chicago.Senior Director of Catastrophe Risk Management. As part of the Catastrophe Manageme...Show more
Last updated: 30+ days ago • Promoted
Remote AI Content Reviewer

Remote AI Content Reviewer

Outlier • Little Elm, TX, United States
Remote
Full-time
Earn up to $15 / hour + performance bonuses.Outlier, a platform owned and operated by Scale AI, is looking for.If you're passionate about improving models and excited by the future of AI, this is you...Show more
Last updated: 7 days ago • Promoted
Lead Engineer - Critical Environments

Lead Engineer - Critical Environments

JLL • Carrollton, Texas, United States
Full-time
This job is with JLL, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.JLL empowers you to ...Show more
Last updated: 4 days ago • Promoted
Journeyman Digital Forensic Analyst

Journeyman Digital Forensic Analyst

Peraton • Arlington, Texas, USA
Full-time +1
Digital Forensic Analyst - Journeyman.Federal Strategic Cyber programs to support a high-impact cybersecurity and technology program focused on securing global infrastructure and enabling innovativ...Show more
Last updated: 19 days ago • Promoted
Director, Change and Incident Management

Director, Change and Incident Management

Vizient, Inc. • Irving, TX, United States
Full-time
When you're the best, we're the best.We instill an environment where employees feel engaged, satisfied and able to contribute their unique skills and talents. We provide extensive opportunities for ...Show more
Last updated: 30+ days ago • Promoted
Principal AI Architect

Principal AI Architect

Paycom Payroll Llc • Grapevine, TX, US
Full-time +1
Paycom is seeking a self-motivated AI Architect with a passion for building innovative products and driving beyond expectations. In this role, you will collaborate closely with software engineers to...Show more
Last updated: 1 hour ago • Promoted • New!
Endpoint Security Engineer Lead (CrowdStrike)

Endpoint Security Engineer Lead (CrowdStrike)

Leidos • Arlington, Texas, USA
Full-time
Leidos has an immediate need for a lead Endpoint Security Engineer for a customer on a highly visible and strategic Cybersecurity Task Order. The Security Engineer will need to be a self-starter wit...Show more
Last updated: 6 days ago • Promoted
Audit / Compliance Manager

Audit / Compliance Manager

Vaco by Highspring • Little Elm, Texas, United States
Permanent
One of Vaco's longstanding clients in the healthcare space reached out to have us assist in finding an Audit / SOX Compliance Manager. This is a legacy client where we've placed multiple people with t...Show more
Last updated: 30+ days ago • Promoted
Senior Solutions Architect - Mid Market / General Business (Central)

Senior Solutions Architect - Mid Market / General Business (Central)

Elastic • Little Elm, TX, United States
Full-time
Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale - unleashing the potential of businesses and people.The Elastic Search AI...Show more
Last updated: 29 days ago • Promoted
ML Platform Engineer (Senior)

ML Platform Engineer (Senior)

Duetto Research • Arlington, Texas, United States
Full-time
We are an ambitious, well-funded, high-growth global technology company transforming the hotel industry.At Duetto, we are passionate about creating innovative analytical solutions to help hoteliers...Show more
Last updated: 30+ days ago • Promoted
Incident Manager

Incident Manager

BCMC • Arlington, Texas, USA
Full-time
BCMC is supporting a customer by delivering intelligence support to customer through proactively identifying analyzing and responding to cyber threats to inform the customers vulnerability manageme...Show more
Last updated: 11 days ago • Promoted