Forensic Intern (Hyderabad)

Forensic Intern (Hyderabad)

27 Aug
|
Arete Event Staffing Firm
|
Hyderabad

27 Aug

Arete Event Staffing Firm

Hyderabad

SUMMARY The Forensic Intern will work and learn the processes, approach, and methodology to perform investigations of Business Email Compromise and Ransomware matters. The role of the Associate Forensic Analyst is to Forensic intern will work with the Forensic team members analysts on the Tiger Teams to learn and perform triage level analysis of the collected images, data, and available logs (e.g. SentinelOne, Firewall Logs, DLP Logs, etc.) and more deep dive advanced analysis under the direction and guidance of the Senior Analysts and Forensic Lead.

The Forensic intern will work Associate Forensic Analyst should work to help develop the narrative and story in conjunction with the Tiger Team members under the direction of the Forensic Lead or Senior Analysts.

The Digital

Forensics & Incident Response (DFIR) team works together to support Clients and help restore business operations during an incident through the identification of threat actor behavior and activity.

The Forensic Intern is a temporary role working to learn and understand DFIR delivery with an opportunity to advance to a full-time Associate Forensic Analyst role supports the Forensic Lead and Tiger Team on responsible for assisting the team with delivery of active Ransomware, Investigations, and Business Email Compromise projects assigned to the respective Tiger Team starting with.

ROLES & RESPONSIBILITIES

- With guidance, performs digital forensic analysis on Windows, Apple Mac, and Linux based operating systems, including the analysis of email log files, and log files for networking appliances including but not to, VPN and firewall appliances.
- Ability to leverage forensics tools including Encase, FTK, X-Ways, Axiom and other custom investigation tools to identify malicious activity that occurred within client environments
- The candidate should be able to performs forensic analysis with guidance on:
- Host-based systems including Windows and Mac OS X to identify indicators of threat actor activity and compromise.
- Analysis of M365 or Microsoft Exchange log files to identify evidence and artifacts of malicious and compromised activity.

- Learns and performs triage level analysis of the collected images, data, and available logs (e.g., SentinelOne, Firewall Logs, DLP Logs, etc.) with guidance
- Documents forensic findings in accordance with the standards set forth within the Arete Forensic Tracker and dLearns to develop a narrative story, master timeline, and visual attack map of the events based on the findings of analysis.
- Works with the DFIR-Forensic tiger teams to closely to provide develop status updates and summaries of findings to the Senior Forensics team members and Senior Forensic Analysts, Forensic Leads and DFIR leadership.
- Learns to identifies Indicators of Compromise (IOCs) and, Tactics, Techniques and Procedures (TTPs) for variants related to case delivery of Forensics findings.
- Learns to document provides data and deliver findings through Forensic trackers and Forensic updates, to the internal Tiger Team analysts team outlining the narrative story and the timeline of events based on the Forensic investigation findings.




- Documents analysis notes and captures data points related to investigations to enhance and inform our threat intelligence.
- Maintains ability to updated use project management systems and templates to document the forensic findings case analyst notes, the Forensic tracker, timeline and attack map for collaboration within the team in our centralized case location.
- Identifies the timing and persistence mechanism of the initial intrusion, adversary actions, timeline of activity/lateral movement, and indicators of data access and/or exfiltration based on the analysis
- Develops the forensic report for investigations related to ransomware and business email compromise
- Is responsible for integrity in analysis, quality in reports and deliverables, as well as documenting and gathering information and potential threat intelligence based on the caseload
- Able to manage multiple projects on a daily basis.
- Has due diligentce with documentation and the tracking of forensic findings. and allocating of hours to the Master Planner software to provide real-time visibility to DFIR leadership
- May perform other duties as assigned by management.

SKILLS AND KNOWLEDGE

- Basic understanding of Forensic artifacts, including (but not limited to) the analysis of operating system artifacts and the recovery of deleted items from Windows operating systems and Windows Event logs.
- Ability to use project management systems and templates to document the forensic findings for collaboration within the team in our centralized case location
- Ability to manage multiple projects on a daily basis
- Working knowledge and understanding of the NTFS, APFS, and Linux and Unix operating system structure.
- Experience analyzing the M365 and Exchange log files including Unified Audit Logs, Message Trace logs, and Purview logs
- Experience with Linux or Mac forensics desired but not required
- Experienced in performing host-based forensics, network forensics, malware analysis and data breach response
- Working knowledge and limited usage of experienced with EnCase, Magnet Axiom, X-Ways, FTK, SIFT, Splunk, ELK, Redline, Volatility, and other commercial and open-source forensic tools.
- Experienced with a common scripting or programming language, including Perl, Python, Bash, and/or PowerShell, preferred.
- Excellent verbal and written communication and experience working in a team environment
- Knowledge and/or experience with various database formats such as SQL, Elastic, Mongo, etc., preferred
- Some experience with Cyber insurance investigations, preferred.

JOB REQUIREMENTS

- Candidate must have collegiate or business experience in incident response or digital forensics with a passion for cyber security.
- Candidate should possess or be enrolled in an accredited degree program working towards an Associates or Bachelor's Degree in Information Security, Computer Science, Digital Forensics or Cyber Security.




- Possession our current pursuit of one or more of the following Certifications a plus:
- Security +, Network+, SANS GCFE, GCFA.

- Ability to work 40 hours per week or during non-business hours, etc.
- Temporary position for a period of 4 months.

DISCLAIMER

The above statements are intended to describe the general nature and level of work being performed. They are not intended to be an exhaustive list of all responsibilities, duties and skills required of personnel so classified.

WORK ENVIRONMENT

While performing the responsibilities of this position, the work environment characteristics listed below are representative of the environment the employee will encounter: Usual office working conditions. Reasonable accommodations may be made to enable people with disabilities to perform the essential functions of this job.

TERMS OF EMPLOYMENT

Salary and benefits shall be paid consistent with Arete's salary and benefit policy.

DECLARATION

The Arete Incident Response Human Resources Department retains the sole right and discretion to make changes to this .

EQUAL EMPLOYMENT PROSPECT

We’re proud to be an equal opportunity employer and celebrate our employees’ differences, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or Veteran status. Different makes us better. Arete Incident Response is an outstanding (and growing) company with a very dedicated, fun team. We offer competitive salaries, fully paid benefits including Medical/Dental, Life/Disability Insurance, 401(k) and the opportunity to work with some of the latest and greatest in the fast-growing cyber security industry.

When you join Arete…

You’ll be doing work that matters alongside other talented people, transforming the way people, businesses, and things connect with each other. Of course, we will offer you great pay and advantages, but we’re about more than that. Arete is a place where you can craft your own path to greatness. Whether you think in code, words, pictures or numbers, find your future at Arete, where experience matters.

Equal Employment Opportunity

We’re proud to be an equal opportunity employer- and celebrate our employees’ differences, regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or Veteran status. Different makes us better.

About Us

Arete Incident Response is an elite team of the world’s leading cybersecurity and digital forensics experts who combat today’s sophisticated cyberattacks. We work tirelessly to provide unparalleled capabilities and solutions throughout the entire cyber incident life cycle. These include incident response readiness assessments and penetration tests as well as post-incident response, remediation, containment, and eradication services. We work in close collaboration with industry leaders and government agencies along with leading cybersecurity technology platforms to deliver an innovative, intelligence-based approach to solving our client’s toughest challenges.

If you want to work with the most talented and experienced people in the industry with the desire to be a cyber hunter and industry expert, we want you to be a part of our team.

📌 Forensic Intern (Hyderabad)
🏢 Arete Event Staffing Firm
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: forensic intern (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: forensic intern (hyderabad) / hyderabad