(Sr.) Digital Forensics Analyst
Trend Micro (UK) · Taipei
Job description
Join Trend ‧ Join New Generation 趨勢科技 - 全球雲端資安領航者 / 全亞洲最大軟體公司 / 企業版圖橫跨五大洲 / 趨勢全球研發基地在台灣 =============================================================== Trend Micro Incorporated, a global cloud security leader, creates a world safe for exchanging digital information with its Internet content security and threat management solutions for businesses and consumers. A pioneer in server security with over 30 years' experience, we deliver top-ranked client, server and cloud-based security that fits our customers' and partners' needs, stops new threats faster, and protects data in physical, virtualized and cloud environments. Within our Information Security team, we need the best talents to help us continuously improve our security capabilities against the ever-changing threat landscape. As a Sr. Digital Forensics Analyst in InfoSec, you must be a trustworthy individual and well-versed in digital incident response principles and methodologies to help bring order to the chaos brought by security breaches. You must also be an inquisitive security researcher who can find and validate the latest vulnerabilities and offensive techniques that could affect the organization's assets. Responsibilities Collect and preserve digital evidence for analysis using traditional DFIR and XDR methods, including evidence collection and preservation across cloud assets and infrastructure Maintain proper chain of custody and evidence handling procedures to ensure findings are legally defensible and support potential HR/legal proceedings Collaborate on mitigation, recovery, and other response processes with corresponding service teams Perform root cause analysis and summarize all investigation and conclusions in an incident report Adapt and formulate new response approaches in investigations on the fly Develop and improve incident response toolset and playbook Research new attacker tactics, techniques, and procedures, and their mitigations to anticipate emerging attack trends Simulate attacker TTPs and assess potential impact to corporate information assets Document and communicate recommendations for risk mitigation to service teams Minimum qualifications Bachelor's degree in computer science, Information Security, or a related field (or equivalent practical experience) At least 5 years of relevant work experience conducting forensic analysis on both Windows and Linux operating systems Must have a strong sense of duty, be diligent in investigation, and have strong people interviewing skills Good verbal and written English communication skills, able to level with different management and technical teams Preferred qualifications Digital Forensic and Incident Response-related training and certification such as GCFA Cloud forensics experience across major platforms (e.g. AWS CloudTrail, Azure Sentinel, GCP Audit Logs), including evidence acquisition and log analysis in cloud/virtualized environments GIAC Cloud Forensics Responder (GCFR) or equivalent cloud forensics certification. Forensic experience in containerized and CI/CD environments (e.g. Docker, Kubernetes, container registries, build pipelines) including artifact and log acquisition specific to these environments Penetration Testing, Red Teaming, or Purple Teaming-related training and certification such as OSCP and GWAPT Strong knowledge of traditional digital forensic tools (e.g. F-Response, SANS SIFT, FTK) and live forensics tools including XDR platforms Coding experience using Python or any scripting language (bash, PowerShell) Experience conducting forensic investigations on AI/ML environments and systems (e.g. model endpoints, training pipelines, LLM application logs, vector stores, and AI agent/tool-use audit trails) Familiarity with applying AI-assisted techniques to forensic investigations (e.g. using AI/LLM tools for log triage, evidence correlation, timeline reconstruction, or investigative summarization) =============================================================== 連結智慧 守護世界 --- Connected Intelligence for Securing a Connected World
Verified and listed by ActiveJobs. Applications are made directly on Trend Micro (UK)'s own career page — we never sit in the middle.