Experteer Overview
As a Digital Forensics u0026amp; Incident Response Specialist, you will investigate cybersecurity incidents, perform digital forensics, and support containment and remediation across SITA’s general environment. You will collaborate with Security Operations, CSIRT, Cloud u0026amp; Infrastructure, and Product Security to identify root causes and minimize impact. You’ll strengthen incident response capabilities and forensic readiness within the Enterprise Information Security Office. This role suits a proactive security professional focused on incident response, forensics, and continuous improvement. You’ll work in a fast-paced, cross-functional setting with meaningful impact across the air transport ecosystem.
Compensaciones / Beneficios
• Investigate and manage cybersecurity incidents through the full incident response lifecycle (analysis, containment, recovery, post-incident review)
• Coordinate with SOC, CSIRT, IT, Cloud, Infrastructure, and Engineering teams to drive remediation
• Produce incident reports and technical findings while refining response playbooks and procedures
• Conduct digital forensic investigations across endpoints, servers, cloud, network, and SaaS environments
• Preserve and analyze forensic evidence, determine root causes and business impact, and support malware, ransomware, or data breach investigations
• Support insider threat investigations and provide technical evidence to Legal, Compliance, HR, and stakeholders
• Identify and recommend security control improvements to reduce insider threat risks
• Develop and maintain automation, scripts, and tools to enhance evidence collection, analysis, and response workflows
• Leverage AI-driven analytics and telemetry to improve investigative efficiency and response effectiveness
• Improve logging, forensic readiness, tooling, and operational processes across enterprise environments
Responsabilidades
• Proven experience in digital forensics, incident response, and cyber investigations in large enterprises
• Hands-on expertise with EDR/XDR platforms, SIEM, forensic tools, and security monitoring technologies
• Ability to investigate incidents across endpoints, servers, cloud, networks, and identity platforms
• Proficiency in Python and/or PowerShell; working knowledge of KQL and security query languages
• Solid understanding of threat actor TTPs and MITRE ATTu0026CK framework
• Excellent analytical, problem-solving, and communication skills for documenting and presenting findings
• Nice-to-have: DFIR certifications and cloud security investigation experience; familiarity with aviation or OT environments
Requisitos principales
• Flex Week: work from home up to 2 days/week
• Flex Day: flexible workday scheduling
• Flex Location: up to 30 days/year remote work
• Employee Wellbeing: 24/7 EAP and Champion Health platform
• Professional Development: LinkedIn Learning and internal training
• Competitive Benefits: country- and contract-type tailored
📌 Senior Specialist, Incident Response | Spécialiste principal, Réponse aux incidents (Mont-ral)
🏢 Suez
📍 Mont-ral