IBM CISO - Cybersecurity Forensic Analyst
IBM
Introduction
The Office of the CISO has the responsibility to safeguard not only IBM systems but those of clients we support around the globe. The IBM CISO office is comprised of teams that cover all aspects of security - from Vulnerabilty Management, Threat Detection, Security Operations, Product Security, Mail Security, System Inventory, Endpoint Detection, as well as Computer Security Incidence Response. CSIRT is responsible for maintaining and managing the IBM internal global incident response process for cybersecurity and data privacy cases across IBM.
IBM's Cyber Security Incident Response Team (CSIRT) is seeking a high-performing Incident Response Forensic Analyst to support the investigation and response to cybersecurity incidents across the Americas region.
In this role, you will work at the intersection of incident response, digital forensics, and threat analysis, partnering closely with responders, threat detection teams, and leadership to investigate security events, preserve forensic evidence, and drive timely containment and remediation.
This is a hands-on analytical role requiring the ability to translate complex technical findings into actionable insights, enabling both operational response and executive decision-making. The successful candidate will demonstrate strong technical depth, investigative rigor, and the ability to operate effectively in high-pressure environments. Key Responsibilities:
-Conduct forensic investigations on endpoint, network, and cloud environments
-Collect, preserve, and analyze digital evidence in accordance with established standards
-Support incident response activities, including triage, containment, eradication, and recovery
-Correlate forensic evidence with threat intelligence and detection signals
-Ability to analyze disk images, logs, and recovered data
-Reconstruct attack timelines and identify root cause and impact
-Document findings and produce clear, defensible reports for technical and non-technical stakeholders
-Collaborate across CSIRT, SOC, Legal, and Compliance teams as needed
-Contribute to post-incident reviews and continuous improvement of response capabilities Required education
Associate's Degree/College Diploma
Preferred education
Bachelor's Degree
Required technical and professional expertise
- 3-5 years of experience in Incident Response, SOC and/or Digital Forensics in a global corporate environment
- Key Technical Skills
- Strong digital forensics expertise across endpoints, systems, and network artifacts; experience with industry-standard tools (e.g., EnCase, FTK, Autopsy)
- Ability to collect, preserve, and analyze evidence while maintaining chain of custody and audit readiness
- Strong investigative and analytical skills, including correlation of logs, endpoint, and network data to determine root cause and reconstruct timelines
- Experience operating within incident response workflows and using EDR, SIEM, and detection platforms in active incident environments
- Understanding of attacker TTPs, with exposure to malware analysis or memory forensics preferred
- Analysis using EDR tooling such as Crowdstrike or Microsoft Defender for Endpoint (MDE)
- Basic scripting/automation skills (e.g., Python, PowerShell) are a plus
- Solid working knowledge of networking topology, technology and tools, such as firewalls, proxies, IDS/IPS, EDR
Event analysis and correlation
Excellent technical writing and presentation skills
- The ability to work independently and effectively, as well as in a group setting required.
Preferred technical and professional experience
- Demonstrated computer forensic investigations experience
- Demonstrated knowledge of commercial and open-source forensic tools, such as X-Ways, Axiom, Autopsy, ELK, SIFT, Plaso, etc
- Familiarity with enterprise cybersecurity tooling (EDR, SIEM, forensic
platforms) Scripting & Automation (Nice to Have)
- Certifications such as: GCFA, CHFI, GCIH (or equivalent experience, nice to have)
- Demonstrated knowledge of analysis with EDR tooling, such as Crowdstrike or Microsoft Defender for Endpoint (MDE)
- Knowledge of incident response and analysis in cloud environments, such as IBM Cloud, AWS, or Azure
- Ability to successfully lead and facilitate information gathering meetings
- Experience managing small and large scale cyber security incidents ABOUT BUSINESS UNIT IBM Systems helps IT leaders think differently about their infrastructure. IBM servers and storage are no longer inanimate - they can understand, reason, and learn so our clients can innovate while avoiding IT issues. Our systems power the world's most important industries and our clients are the architects of the future. Join us to help build our leading-edge technology portfolio designed for cognitive business and optimized for cloud computing.
YOUR LIFE @ IBM In a world where technology never stands still, we understand that, dedication to our clients success, innovation that matters, and trust and personal responsibility in all our relationships, lives in what we do as IBMers as we strive to be the catalyst that makes the world work better. Being an IBMer means you'll be able to learn and develop yourself and your career, you'll be encouraged to be courageous and experiment everyday, all whilst having continuous trust and support in an environment where everyone can thrive whatever their personal or professional background. Our IBMers are growth minded, always staying curious, open to feedback and learning new information and skills to constantly transform themselves and our company. They are trusted to provide on-going feedback to help other IBMers grow, as well as collaborate with colleagues keeping in mind a team focused approach to include different perspectives to drive exceptional outcomes for our customers. The courage our IBMers have to make critical decisions everyday is essential to IBM becoming the catalyst for progress, always embracing challenges with resources they have to hand, a can-do attitude and always striving for an outcome focused approach within everything that they do. Are you ready to be an IBMer? ABOUT IBM IBM's greatest invention is the IBMer. We believe that through the application of intelligence, reason and science, we can improve business, society and the human condition, bringing the power of an open hybrid cloud and AI strategy to life for our clients and partners around the world. Restlessly reinventing since 1911, we are not only one of the largest corporate organizations in the world, we're also one of the biggest technology and consulting employers, with many of the Fortune 500 companies relying on the IBM Cloud to run their business.
At IBM, we pride ourselves on being an early adopter of artificial intelligence, quantum computing and blockchain. Now it's time for you to join us on our journey to being a responsible technology innovator and a force for good in the world. IBM is proud to be an equal-opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetics, pregnancy, disability, neurodivergence, age, or other characteristics protected by the applicable law. IBM is also committed to compliance with all fair employment practices regarding citizenship and immigration status. OTHER RELEVANT JOB DETAILS IBM offers a competitive and comprehensive benefits program. Eligible employees may have access to:
- Healthcare benefits including medical & prescription drug coverage, dental, vision, and mental health & well being
- Financial programs such as 401(k), the IBM Employee Stock Purchase Plan, financial counseling, life insurance, short & long- term disability coverage, and opportunities for performance based salary incentive programs
- Generous paid time off including 12 holidays, minimum 56 hours sick time, 120 hours vacation, 12 weeks parental bonding leave in accordance with IBM Policy, and other Paid Care Leave programs. IBM also offers paid family leave benefits to eligible employees where required by applicable law
- Training and educational resources on our personalized, AI-driven learning platform where IBMers can grow skills and obtain industry-recognized certifications to achieve their career goals
- Diverse and inclusive employee resource groups, giving & volunteer opportunities, and discounts on retail products, services & experiences
We consider qualified applicants with criminal histories, consistent with applicable law. This position was posted on the date cited in the key job details section and is anticipated to remain posted for 21 days from this date or less if not needed to fill the role. IBM will not be providing visa sponsorship for this position now or in the future. Therefore, in order to be considered for this position, you must have the ability to work without a need for current or future visa sponsorship. The compensation range and benefits for this position are based on a full-time schedule for a full calendar year. The salary will vary depending on your job-related skills, experience and location. Pay increment and frequency of pay will be in accordance with employment classification and applicable laws. For part time roles, your compensation and benefits will be adjusted to reflect your hours. Benefits may be pro-rated for those who start working during the calendar year.
- ...'ll go through your first few weeks together, learning about IBM and the skills you'll be attaining throughout your apprenticeship... ...who start working during the calendar year. Job Title Cybersecurity Analyst Apprentice Date posted 03-Aug-2026 Job ID 117976...IbmFull timeContract workPart timeApprenticeshipFixed term contractInternshipWork at officeLocal areaRelocationShift work
$130k - $152.5k
...complex business concerns.Position OverviewCRA is seeking a Cybersecurity Consultant (Assessments / Due Diligence / Advisory) to support... ...engagements is a plus.Experience collaborating with incident response, forensic, or crisis management teams to translate post-incident...SuggestedWork at officeWork from home3 days per week- Charles River Associates is seeking candidates for a security and forensics-focused role in the United States. The position involves investigations into data security matters, including breaches and fraud, and applying digital forensics techniques across systems. Responsibilities...Suggested
$114k - $154k
...Salary: $114,000 - 154,000 per year Requirements: We ask for an undergraduate degree, preferably in Digital Forensic Science or Computer Science/Engineering. We look for at least 1 year of relevant experience with the forensic lifecycle, scoping, evidence acquisition...SuggestedFull timeWork at officeRemote workFlexible hours$117k - $147.7k
...penetration testing techniquesSolid programming/debugging skillsExperience of using a variety of tools, included, but not limited to, IBM AppScan, Burp and SQL MapThreat AnalysisInnovative ThinkingTechnology Systems AssessmentTechnical DocumentationAdvisoryDesired:CISSP,...IbmFull timeWork at officeShift workDay shift- ...areas of our business, and our global Cyber Investigation and Forensic Response (CIFR) practice is at the heart of how we help... ...consulting experience in infrastructure, enterprise architecture, cybersecurity, or a closely related disciplineMinimum 2 years of experience...Full timeLive inWork at officeLocal areaShift work
- ...Job Title: Cybersecurity Analyst II Location: Hybrid Onsite in Chicago, IL or Austin, TX 3x/week Type: Direct Hire Bottom Line / In a Nutshell: ~3-4 years+ experience minimum ~ Microsoft Sentinel ~ SIEM ~ Google SecOps ~ SOAR (...Extra incomeWork at office
$65k - $110k
...Chicago, IL Direct Hire Salary Range : $65,000 - $110,000 Benefits : Full benefits - in file Position Title: Cybersecurity Analyst Location: Chicago, IL (Hybrid) Department: Technology Solutions Firm Overview Our client is...Work at office- ...00 query or SQL" "• Languages: RPG Free format ILE, RPG ILE, RPG/400, RPG III, RPG II, CL, SQL• Operating Systems: OS/400• Hardware: IBM I-Series, AS/400 • Other: DB2/400, Turnover, Aldon, SQL, FTP, MQ Series, Robot• Core IT skills (Word, Excel, PowerPoint, Visio, SQL)MQ...IbmPermanent employment
$93.54k - $103.32k
...against today's most advanced cyber threats? We are seeking a Cybersecurity Analyst - Tier 2 to monitor alerts, investigate incidents, and... ...playbooksCollaborates effectively with cross-functional teams, including forensics, threat intelligence, IT, and network...Permanent employmentTemporary workLocal areaShift work$99k - $232k
...SectorNot ApplicableSpecialismCybersecurity & PrivacyManagement LevelManagerJob Description & SummaryThe OpportunityAs a Cybersecurity, Privacy and Forensics - Data Protection - PKI Implementation Manager, you will specialize in providing advice and guidance to clients on...Full timeH1b$116.2k - $229.1k
...development using BIRTExperience with at least one Maximo add-on (Maximo Spatial, Maximo Transportation, Maximo Utilities, and others)IBM Maximo certification with Maximo 7.6.xExperience using artificial intelligence (AI)-enabled tools and digital technologies to improve...IbmLocal area$93.54k - $103.32k
A leading cybersecurity firm in Illinois is seeking a Cybersecurity Analyst - Tier 2 to monitor alerts and respond to incidents. The role requires 3+ years of experience in an SOC and a Bachelor's degree in a related field. Responsibilities include real-time monitoring,...Night shift- 401K, Medical Insurance, Dental Insurance, Vision Insurance, Life Insurance Full-Time | On-site Required Skills Cybersecurity Analyst CloudNova Systems Job Description We are looking for a Cybersecurity Analyst to help protect our organization's information systems and...Full time
$140k - $170k
...platforms) across assigned accountsResearch and maintain platform and competitive intelligence (e.g., Schneider EcoStruxure, Vertiv Trellis, IBM TRIRIGA/Envizi, Nlyte, Device42) to inform advisory recommendationsHelp identify whitespace opportunities within existing accounts...IbmFull timeInternshipLocal areaRemote workNight shift- ...RoleJob DescriptionWe are seeking a skilled Mainframe Logical Security Engineer to design, implement, and manage security controls across IBM z/OS environments. The role ensures the confidentiality, integrity, and availability of enterprise systems and data by enforcing...IbmFull timeLive inRelocation3 days per week
- ...direction of the Chief Information Security Officer (CISO), the Senior Cybersecurity Operations Analyst will be responsible for analyzing events from... ...or incident investigation. Experience in conducting forensic analysis and digital investigations as part of an incident...Work experience placement
$116k - $144k
Cybersecurity Assessment and Test Analyst II At Kirkland & Ellis, we don’t just meet the standard for legal excellence — we set it. Our culture is built... ...function led by the Chief Information Security Officer (CISO), this role offers high visibility and the opportunity...WorldwideFlexible hours- ...Largest IT Staffing Company in the US, according to Staffing Industry Analysts' 2012 annual report. Artech provides technical expertise to fill... ...requirement and mapping the data.- Knowledge about SWIFT and IBM Message Queue- Technical knowledge on XML and XSLTAdditional...IbmImmediate start
- ...Production environments Understand how Performance Metrics is generated for an application Familiarity with End to End Automation , IBM MQ Event processing Trouble shooting skills include problem triage, analysis , recommendation and root cause where possible Work in...IbmWork experience placement
- ...security monitoring across on-prem and cloud. You will coordinate investigations, implement playbooks, and oversee data preservation for forensics and post-incident analysis. The role requires 5+ years in security operations, hands-on expertise with threat analysis, forensics,...
- ...architectures.The role will lead security architecture efforts across all cybersecurity domains for new technology implementations, major system... ..., and mainstream platforms (e.g., Microsoft, Oracle, IBM, etc.)CNO Financial Group offers the following benefits for this...IbmFull timeWork experience placementWork at officeRemote workFlexible hours
- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...
- ...Description Job Description Chief Information Security Officer (CISO): In Person Downtown Chicago, IL About Caregenix:... ...and Qualifications: Experience ~ Required 12 plus years in Cybersecurity and 3 plus years in Senior Leadership Role. Technical Expertise...Monday to FridayShift work
- ...Role/Skills: Middleware AI consultant Location - Onsite, Chicago. Description: Core Middleware Expertise IBM WebSphere Application Server (WAS) 7.x, 8.x, 8.5.x, 9.x WebSphere Network Deployment (ND) Cell, node, cluster, and...Ibm
- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry... ...the company should have a minimum of 10 years' experience in cybersecurity, with at least 5 years in senior security leadership,...
- ...Vignesh Chandran KRG Technologies Inc (***) ***-**** EXT 405 Job Description · Configuration and administration of IBM z/OS mainframe network software. · Configuration and administration of network related 3rd party system software. · Provision of...IbmFull timeLocal area
- ...Client primarily looking for assembler development experienceSkills Required:10+ years of experience required in the following areas:IBM Mainrame experienceJCLDB2Strong SQL SkillsExperience in developing Stored proceduresStrong Assembler programming / debugging skillsCOBOL...Ibm
- A healthcare organization in Chicago is seeking a Cyber Security Analyst to identify and mitigate risks to the confidentiality and security of its services. The role involves articulating security requirements, collaborating with senior team members, and participating in...
- ...both on the job and through formal training programs.Job DescriptionSr. QA analyst: Excellent understanding of FIX protocol (preferably FIXML) Strong API testing experience using Sonic JMS / IBM MQ / Knowledge on test and defect management tools ( Quality Center, Jira...Ibm
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IBM CISO - Cybersecurity Forensic Analyst. Be the first to apply!
- chief information security officer Chicago, IL
- business information security officer Chicago, IL
- ciso Chicago, IL
- chief information security officer ciso Chicago, IL
- information security officer Chicago, IL
- senior cybersecurity analyst Chicago, IL
- cyber security consultant Chicago, IL
- cyber security specialist Chicago, IL
- ibm work from home Chicago, IL
- ibm api connect Chicago, IL



