Experteer Overview
As a Digital Forensics u0026amp; Incident Response Specialist, you will investigate cybersecurity incidents, perform digital forensics, and support containment and remediation across SITA’s global environment. You will collaborate with Security Operations, CSIRT, Cloud u0026amp; Infrastructure, and Product Security to identify root causes and minimize impact.
You’ll strengthen incident response capabilities and forensic readiness within the Enterprise Information Security Office. This role suits a proactive security professional focused on incident response, forensics, and continuous improvement. You’ll work in a fast-paced, cross-functional setting with meaningful impact across the air transport ecosystem.
Compensaciones / Incentivos
- Investigate and manage cybersecurity incidents through the full incident response lifecycle (analysis, containment, recovery, post-incident review)
- Coordinate with SOC, CSIRT, IT, Cloud, Infrastructure, and Engineering teams to drive remediation
- Produce incident reports and technical findings while refining response playbooks and procedures
- Conduct digital forensic investigations across endpoints, servers, cloud, network, and SaaS environments
- Preserve and analyze forensic evidence, determine root causes and business impact, and support malware, ransomware, or data breach investigations
- Support insider threat investigations and provide technical evidence to Legal, Compliance, HR, and stakeholders
- Identify and recommend security control improvements to reduce insider threat risks
- Develop and maintain automation, scripts, and tools to enhance evidence collection, analysis, and response workflows
- Leverage AI-driven analytics and telemetry to improve investigative efficiency and response effectiveness
- Improve logging, forensic readiness, tooling, and operational processes across enterprise environments
Responsabilidades
- Proven experience in digital forensics, incident response, and cyber investigations in large enterprises
- Hands-on expertise with EDR/XDR platforms, SIEM, forensic tools, and security monitoring technologies
- Ability to investigate incidents across endpoints, servers, cloud, networks, and identity platforms
- Proficiency in Python and/or Power Shell; working knowledge of KQL and security query languages
- Solid understanding of threat actor TTPs and MITRE ATTu0026CK framework
- Excellent analytical, problem-solving, and communication skills for documenting and presenting findings
- Nice-to-have: DFIR certifications and cloud security investigation experience; familiarity with aviation or OT environments
Requisitos principales
- Flex Week: work from home up to 2 days/week
- Flex Day: flexible workday scheduling
- Flex Location: up to 30 days/year remote work
- Employee Wellbeing: 24/7 EAP and Champion Health platform
- Professional Development: Linked In Learning and internal training
- Competitive Benefits: country- and contract-type tailored
📌 Senior Specialist, Incident Response | Spécialiste principal, Réponse aux incidents (Mont-ral)
🏢 Suez
📍 Mont-ral