Cyber Defense Forensics Analyst
$87.7k - $164kErnst & Young
At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your unique voice and perspective to help EY become even better. Join us and build an exceptional experience for yourself, and a better working world for all.
The exceptional EY experience. It's yours to build.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
Today's world is fuelled by vast amounts of information. Data is more valuable than ever before. Protecting data and information systems is central to doing business, and everyone in EY Information Security has a critical role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Our Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond to security events as they happen. Together, the efforts of our dedicated team helps protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting and enabling the business through innovative, secure solutions that provide speed to market and business value.
The opportunity
Cyber Triage and Forensics (CTF) Incident Analyst will work as a senior member of the technical team responsible for security incident response for EY. The candidate will work as an escalation point for suspect or confirmed security incidents. Responsibilities include performing digital forensic analysis, following security incident response standard methodologies, malware analysis, identify indicators of compromise, support remediation or coordinate remediation efforts of a security incident, and develop documentation to support the security incident response process.
Your key responsibilities
Investigate, coordinate, bring to resolution, and report on security incidents as they are brought up or identified
Forensically analyze end user systems and servers found to have possible indicators of compromise
Analysis of artifacts collected during a security incident/forensic analysis
Identify security incidents through 'Hunting' operations within a SIEM and other relevant tools
Interface and connect with server owners, system custodians, and IT contacts to pursue security incident response activities, including: obtaining access to systems, digital artifact collection, and containment and/or remediation actions
Provide consultation and assessment on perceived security threats
Maintain, manage, improve and update security incident process and protocol documentation
Regularly provide reporting and metrics on case work
Resolution of security incidents by identifying root cause and solutions
Analyze findings in investigative matters, and develop fact based reports
Be on-call to deliver global incident response
Skills and attributes for success
Resolution of security incidents by identifying root cause and solutions
Analyze findings in investigative matters, and develop fact-based reports
Proven integrity and judgment within a professional environment
Ability to appropriately balance work/personal priorities
To qualify for the role you must have
Bachelors or Masters Degree in Computer Science, Information Systems, Engineering or a related field
5+ years experience in incident response, computer forensics analysis and/or malware reverse engineering;
Understanding of security threats, vulnerabilities, and incident response;
Understanding of electronic investigation, forensic tools, and methodologies, including: log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processes, malware identification and analysis;
Be familiar with legalities surrounding electronic discovery and analysis;
Experience with SIEM technologies (i.e. Splunk);
Deep understanding of both Windows and Unix/Linux based operating systems;
Ideally, you'll also have
Hold or be willing to pursue related professional certifications such as GCFE, GCFA or GCIH
Background in security incident response in Cloud-based environments, such as Azure
Programming skills in PowerShell, Python and/or C/C++ Understanding of the best security practices for network architecture and server configuration
What we look for
Demonstrated integrity in a professional environment
Ability to work independently
Have a global mind-set for working with different cultures and backgrounds
Knowledgeable in business industry standard security incident response process, procedures, and life cycle
Excellent teaming skills
Excellent social, communication, and writing skills
What we offer you
The compensation ranges below are provided in order to comply with United States pay transparency laws. Other geographies will follow their local salary guidelines, which may not be a direct conversion of published US salary range/s. At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $87,700 to $164,000. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $105,200 to $186,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Are you ready to shape your future with confidence? Apply today.
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
EY | Building a better working world
EY is building a better working world by creating new value for clients, people, society, and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy, and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.?
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at View email address on click.appcast.io .
$40 per hour
A cybersecurity-focused AI company is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. This role offers flexibility as it's a remote position with hourly pay starting at $40+. Applicants should have ...CyberRemote jobHourly pay$40 per hour
A leading cybersecurity firm is seeking experienced professionals to evaluate AI-generated security content and solve technical problems in cybersecurity. In this remote position, you can choose your projects and work on your schedule. Ideal candidates will have at least...CyberRemote jobHourly payFlexible hours$95.17k - $156.36k
...role sits at the intersection of hands-on incident response, cyber defense and threat mitigation. You will be part of a highly collaborative... ...of overall cybersecurity experience, with a focus in digital forensics, incident response, SOC, or threat mitigation. ~ Broad and...CyberWork at officeVisa sponsorshipWork visa3 days per week$40 per hour
A tech company is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical cybersecurity problems. This remote position allows you to choose projects and work on your own schedule, offering pay starting at $40+ per hour...CyberRemote jobHourly pay- ...their team in the United States. In this role, you will assess information security risks, support IT asset security, and implement cyber security technology while providing training to various teams. Your expertise in information security, risk management, and communication...CyberRelocation package
- ...NC, SC, MI, MS, TN at V Group Job Title: Incident Response & Forensics Analyst Duration: 6+ Months Location: Remote with Occasional visit to... ...position is a part of the IT Threat Intelligence group within the Cyber Security Operations Center and will be expected to provide...CyberContract workWork at officeLocal areaRemote work
- ...Senior Computer Forensics Analyst Provide senior and expertise skill level in digital forensics principles when acquiring, collecting, preserving... ..., GCFA, GCFE, EnCE, ACE, CCME, or similar certification. ~ Cyber/network related certifications: (one or more): Network+,...CyberWork experience placementRemote work
- ...a structured orchestration following the cyber technical incident response plan. Collaborate... ...Perform malware analysis and deep‑dive forensic examinations on endpoints, servers,... ...Handler - GCIH GIAC Certified Forensic Analyst - GCFA GIAC Certified Forensic Examiner-...Cyber
$128.1k - $239.6k
...prevents, detects, responds and mitigates cyber-risk, protecting EY and client data, and... ...systems. The opportunity The Active Defense team is responsible for four core areas:... ...security. In an Active Defense Analyst, we are looking for someone who has experience...CyberSummer holidayLocal areaRemote workFlexible hoursNight shiftWeekend work$128.1k - $239.6k
EY Technology The opportunity The Active Defense team is responsible for four core areas:... ...Trapping and Coercion. This function allows the Cyber Defense Team to fortify and mature the firm’s enterprise security. Active Defense Analyst In an Active Defense Analyst, we are...CyberSummer holidayLocal areaFlexible hoursNight shiftWeekend work$90.6k - $150.44k
...Position Title Cloud/Cyber Risk Management Analyst Sr Location New York, NY 10018 Job Summary ***This is an Onsite role in Midtown NYC*** As a key member of the second line of defense Technology, Cyber, Third Party Risk Management & Resilience Risk...CyberLocal area$90.6k - $150.44k
Position Title: Cloud/Cyber Risk Management Analyst Sr | Location: New York, NY 10018 Job Summary This is an Onsite role in Midtown NYC. As a key member of the second line of defense team, the analyst will support the Cyber Risk team to fulfill the Bank’s Second Line of...CyberLocal area$40 per hour
A cybersecurity innovations company is seeking experienced professionals to evaluate AI-generated security content and solve technical cybersecurity problems. Candidates should have at least 2 years of hands-on cybersecurity experience and be fluent in English. This offers...CyberRemote jobHourly payFlexible hours$40 per hour
A leading AI training firm is seeking experienced cybersecurity professionals for a remote role focused on evaluating and improving AI-generated security content. Candidates should have over 2 years of hands-on cybersecurity experience and some coding skills. Responsibilities...CyberRemote jobHourly payFlexible hours- Clearwaters Industry Solutions, LLC. is seeking a mid-level Information Security Analyst to enhance the cyber security program at Wright-Patterson Medical Center in Ohio. This fully on-site role involves implementing security features to protect information systems, ensuring...Cyber
- .... L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs... ...connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Program Financial Analyst Job Code: 37486 Job Location: Clifton...CyberLocal areaDay shift
$72k - $133.5k
...do. L3Harris is the Trusted Disruptor in defense tech. With customers’ mission-critical needs... ...solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title Operations Cost Analyst Job Code 37486 Job Location Clifton, NJ...CyberLocal areaDay shift- Alignerr is seeking an Incident Response Analyst to analyze security events, shape AI responses, and work flexibly from anywhere. Work spans... ...of SOC experience and is skilled at identifying meaningful cyber threats, communicating findings clearly, and working independently...CyberRemote job10 hours per week
- ...Job Title: Incident Response Sr. Analyst Location: Jersey City, NJ [Hybrid - Week... ...Bachelor's degree in Information Technology, Cyber Security, Computer Science, or related... ...domains including Incident Response and Forensics, Security Governance and Oversight, Security...CyberLocal area
$55k - $115k
A cybersecurity firm is hiring a Cyber Defense Infrastructure Support Specialist. This fully remote role involves maintaining and enhancing cyber defense infrastructure, monitoring network activity, and managing security measures. Candidates should have a bachelor's degree...CyberRemote job- Neevsys LLC is seeking a Cybersecurity Analyst responsible for ensuring the confidentiality, integrity, and availability of IT systems. You will monitor security events, conduct vulnerability assessments, and ensure compliance with federal security requirements. The ideal...Cyber
- ...global immigration services, is hiring a Cyber Security Engineer to join their... ...role focuses on incident response, digital forensics, and improving threat detection capabilities... ...strengthening Fragomen’s security posture while mentoring junior analysts. #J-18808-Ljbffr FragomenCyber
- A governmental services provider is seeking a Cyber Command Forensic Analyst to investigate network intrusions and cyber incidents. Responsibilities include developing forensic techniques, managing analysis labs, and ensuring evidence integrity. Ideal candidates will have...Cyber
$77k - $202k
PwC is seeking a Senior Associate in Cybersecurity Incident Management in New York City. This role involves analyzing complex cybersecurity challenges and mentoring junior team members. Applicants should have a Bachelor’s Degree in a relevant field and at least 3 years ...Cyber- A cybersecurity firm in Georgia is looking for an individual to perform assessments of networks and systems to ensure compliance with cybersecurity regulations. Responsibilities include conducting risk assessments and preparing audit reports. Applicants should have a Bachelor...Cyber
$1,803 - $2,215 per month
...University, through The Chronicle Of Higher Education, Inc., is seeking adjunct faculty for the Fall 2026 semester to teach courses in Cyber Security, Mathematics, and Computer Science. Successful candidates will conduct face-to-face classes on the Queens campus and engage...Cyber- Concept Plus is looking for a Senior Information Assurance / Cyber Analyst to support a critical Air Force program. This role involves maintaining cybersecurity posture, preparing Risk Management Framework documentation, and ensuring compliance with DoD policies. The ideal...Cyber
$100k - $185k
A global intelligence firm is seeking a Cyber Incident Response Analyst to join its Cyber Defence team. The successful candidate will coordinate cybersecurity responses, integrate threat intelligence, and develop operational playbooks. Candidates should have a solid grasp...Cyber$60k - $80k
A leading technology company in the US is seeking a Security Analyst to enhance their cybersecurity posture. This role involves monitoring... ...-functional teams. Candidates should have formal education in Cyber Security, effective communication skills, and experience in security...CyberRemote job$100k - $110k
Sony Music Entertainment in New York is looking for a motivated Cyber Security Testing Analyst to join our Global Information Security team. You will contribute to technical security testing of applications and collaborate with engineering teams to enhance security measures...Cyber
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cyber Defense Forensics Analyst. Be the first to apply!

