About the role
This specialist leads the response when security incidents occur, acting as a digital detective to investigate incidents. They collect and analyse evidence from compromised systems, coordinate containment efforts, and help restore normal operations. The role involves examining digital evidence and preparing detailed incident reports for management.
Core Responsibilities:
- Coordinate all stages of incident response: detection, triage, containment, eradication, recovery, and post-incident review;
- Conduct digital forensic investigations, including acquisition, preservation, analysis, and reporting of evidence from systems, networks, endpoints as required;
- Develop, maintain, and execute forensic readiness and incident response plans, playbooks, procedures, and standard operating guidelines;
- Maintain logs and case documentation in compliance with regulatory requirements; and
- Support threat hunting and proactive detection.
Core Requirements:
- GIAC Certified Forensic Analyst (GCFA) or GIAC Certified Incident Handler (GCIH) or other recognised digital forensics or incident response certifications;
- A minimum of THREE (3) years of experience in cybersecurity incident response, digital forensics, or cybersecuritydisciplines;
- Hands-on experience with digital forensics tools;
- Familiarity with Windows, Linux, and cloud environments;
- Understanding of SIEM, EDR/endpoint security tools, log aggregation, threat intelligence feeds;
- Excellent written and verbal communication skills, with ability to explain technical findings to both technical and non-technical stakeholders; and
- Familiarity with incident response frameworks (NIST, SANS, ISO, MITRE ATT&CK).