Lead - Info Security Forensics | Full Time
Henry Ford Health System | |
United States, Michigan, Detroit | |
Jan 21, 2025 | |
GENERAL SUMMARY: The Information Security Forensic Lead position is a valued member of the IPSO department and will work closely with other members of the SOC, IPSO (Risk, Privacy, etc.) and IT programs to develop and implement a comprehensive approach to the management of security risks and forensics. The Information Security Forensic Lead conducts thorough investigations into the nature of the attack. The Information Security Forensic Lead looks deeper into security incidents and assist in investigating cyber incidents. The primary purpose of this position is to conduct high-level security investigations, computer forensic investigations, data recovery, and electronic discovery. The candidate will be expected to have a solid foundation of technical experience and expertise and possess strong communication skills. The Information Security Forensic Lead leads and addresses real security incidents and evaluates incidents identified by SOC Analyst analysts. The Information Security Forensic Lead uses threat intelligence such as updated rules and Indicators of Compromise (IOCs) to pinpoint affected systems and the extent of the attack. Analyzes running processes and configs on affected systems taking forensic imaging as needed and analyzing forensic images with approved legal forensic software (encase, FTK). Carries out in-depth threat intelligence analysis to find the perpetrator, the type of attack, and the data or systems impacted. Creates and implements a strategy for containment and recovery formulate plans to repair damaged assets, keep other assets safe, and work to remove the threat. Working with all aspects of the SOC and IT teams to focus on containment, repel attacks, and repair affected systems. Intelligence gathered after an incident is often shared with authorities and other organizations and can be used as a basis to prevent future attacks. EDUCATION/EXPERIENCE:
CERTIFICATIONS/LICENSURES:
Additional Information
|