CISO Cybersecurity Forensic Analyst

IBM

Confirmed live 2 days ago Trusted

Quick summary

Work type
On-site
Location
Posted
26 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

How this pay compares to similar roles

Similar $160k
$105k most similar roles pay here $208k

This listing doesn't post a salary. Most similar roles pay $135,000–$184,325.

Based on 238 similar postings.

Employer

About IBM

IBM is a US-based global technology company providing hybrid cloud, AI, consulting, enterprise software, and IT infrastructure products and services.

IBM currently has 506 open roles on FindRole.

Listed pay typically runs $174,632–$197,165 across 5 roles with salary data.

Most-posted roles

View all roles at IBM

At a glance

TL;DR · CISO Cybersecurity Forensic Analyst

IBM CISO - Cybersecurity Forensic Analyst joins the Cyber Security Incident Response Team (CSIRT) to support investigation and response to cybersecurity incidents across the Americas region. This hands-on analytical role involves conducting forensic investigations on endpoint, network, and cloud environments while collecting and analyzing digital evidence to ensure chain of custody. The analyst will reconstruct attack timelines, identify root causes, and translate complex technical findings into actionable reports for both technical and non-technical stakeholders. Key responsibilities include collaborating with SOC, Legal, and Compliance teams to manage triage, containment, and remediation. Required expertise includes experience with tools like EnCase, FTK, Autopsy, Crowdstrike, or Microsoft Defender for Endpoint. Candidates must possess skills in analyzing disk images, logs, and network artifacts across Windows, Mac, and Linux systems while utilizing Python or PowerShell for automation.

What you'll do

  • Conduct forensic investigations across endpoint, network, and cloud environments.
  • Collect, preserve, and analyze digital evidence while maintaining a strict chain of custody.
  • Support incident response activities including triage, containment, eradication, and recovery.
  • Correlate forensic evidence with threat intelligence and detection signals to identify root causes.
  • Analyze disk images, system logs, and recovered data to reconstruct attack timelines.
  • Produce clear, defensible technical reports for both technical and non-technical stakeholders.
  • Contribute to post-incident reviews and the continuous improvement of response capabilities.

What we're looking for

  • Associate's Degree or College Diploma.
  • Bachelor's Degree (preferred).
  • 3-5 years of experience in Incident Response, SOC, and/or Digital Forensics in a global corporate environment.
  • Expertise in digital forensics across endpoints, systems, and network artifacts using tools like EnCase, FTK, or Autopsy.
  • Proficiency in analyzing disk images, logs, and network data to reconstruct attack timelines and identify root causes.
  • Experience with EDR platforms (e.g., Crowdstrike, Microsoft Defender for Endpoint) and knowledge of cloud environments (IBM Cloud, AWS, Azure).
  • Strong technical writing skills to produce clear reports for both technical and non-technical stakeholders.
  • Certifications such as GCFA, CHFI, or GCIH are preferred.

More like this

Similar roles

CISO Cybersecurity Forensic Analyst

IBM

26 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows
3+ yrs exp

CISO Cybersecurity Forensic Analyst

IBM

9 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows Mac
3+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 18 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Fort Belvoir, VA 18 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 18 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 18 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid