CISO Cybersecurity Forensic Analyst

IBM

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Posted
9 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

How this pay compares to similar roles

Similar $160k
$105k most similar roles pay here $208k

This listing doesn't post a salary. Most similar roles pay $135,000–$184,325.

Based on 238 similar postings.

Employer

About IBM

IBM is a US-based global technology company providing hybrid cloud, AI, consulting, enterprise software, and IT infrastructure products and services.

IBM currently has 506 open roles on FindRole.

Listed pay typically runs $174,632–$197,165 across 5 roles with salary data.

Most-posted roles

View all roles at IBM

At a glance

TL;DR · CISO Cybersecurity Forensic Analyst

IBM CISO - Cybersecurity Forensic Analyst joins the Cyber Security Incident Response Team (CSIRT) to support investigation and response to cybersecurity incidents across the Americas region. This hands-on analytical role involves conducting forensic investigations on endpoint, network, and cloud environments while collecting, preserving, and analyzing digital evidence. The analyst will reconstruct attack timelines, identify root causes, and translate complex technical findings into actionable reports for both technical and non-technical stakeholders. Key responsibilities include collaborating with SOC, Legal, and Compliance teams to manage triage, containment, and recovery. Required skills include expertise in tools like EnCase, FTK, Autopsy, Crowdstrike, or Microsoft Defender for Endpoint, along with proficiency in Windows, Mac, and Linux systems. The role requires experience with SIEM platforms, network artifacts, and potentially scripting in Python or PowerShell to solve critical security incidents.

What you'll do

  • Conduct forensic investigations across endpoint, network, and cloud environments.
  • Collect, preserve, and analyze digital evidence while maintaining a strict chain of custody.
  • Execute incident response activities including triage, containment, eradication, and recovery.
  • Correlate forensic evidence with threat intelligence to identify root causes and attack timelines.
  • Analyze disk images, system logs, and recovered data using industry-standard forensic tools.
  • Produce clear, defensible technical reports for both technical teams and executive stakeholders.
  • Contribute to post-incident reviews to improve internal response capabilities and processes.

What we're looking for

  • An Associate's Degree or College Diploma is required.
  • A Bachelor's Degree is preferred.
  • 3-5 years of experience in Incident Response, SOC, and/or Digital Forensics in a global corporate environment are required.
  • Proficiency in digital forensics across endpoints, systems, and network artifacts using tools like EnCase, FTK, or Autopsy is required.
  • Ability to collect, preserve, and analyze evidence while maintaining chain of custody and audit readiness is required.
  • Experience with EDR platforms (e.g., Crowdstrike, Microsoft Defender for Endpoint) and SIEM tools in active incident environments is required.
  • Strong technical writing skills are required to produce clear reports for both technical and non-technical stakeholders.
  • Knowledge of Windows, Mac, and Linux operating systems and networking technologies like firewalls and proxies is required.

More like this

Similar roles

CISO Cybersecurity Forensic Analyst

IBM

26 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows
3+ yrs exp

CISO Cybersecurity Forensic Analyst

IBM

26 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows
3+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Fort Belvoir, VA 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS AWS Microsoft Azure Google Cloud Platform Oracle Cloud NetFlow Packet Capture TCP/IP Unix Incident Response Cyber Kill Chain SaaS Security+ CE CSSP-Infrastructure Support Vulnerability Management Network Security
4+ yrs exp Hybrid

Cyber Security Analyst

Leidos

Adelphi, MD 17 days ago $87,100$157,450
SIEM IDS Incident Response NetFlow Packet Capture AWS Microsoft Azure Google Cloud Platform Oracle Cloud TCP/IP Unix Cyber Kill Chain SaaS Vulnerability Management Network Security Security+ CE CSSP-Infrastructure Support
4+ yrs exp Hybrid