About the position
Job Purpose
Conduct in-depth digital forensic investigations to identify, preserve, acquire, analyse and report on digital evidence relating to fraud, cybercrime, misconduct, insider threats, data breaches and other technology-related incidents. The role will ensure investigations are conducted in accordance with established digital forensic frameworks, legal requirements, evidentiary standards and organisational policies.
Key Responsibilities
1. Data Management and Analysis
- Gather, preserve, acquire, extract and analyse digital evidence from endpoints, servers, mobile devices, cloud environments, Microsoft 365, network infrastructure and other digital sources.
- Recover deleted, hidden, encrypted or damaged data using approved forensic methodologies and industry-standard tools.
- Conduct forensic analysis of user activity, email communications, authentication records, cloud audit logs, browser activity and application artefacts.
- Analyse digital evidence to establish timelines, user activity, indicators of compromise and other relevant investigative findings.
- Prepare detailed forensic reports, findings, conclusions, recommendations, statistics and trend analysis for relevant stakeholders.
- Maintain an accurate chain of custody and ensure the secure storage, management, retention and disposal of digital evidence in accordance with organisational requirements.
2. Technology and Digital Forensics
- Conduct endpoint, mobile, cloud, network, memory and malware forensic investigations.
- Perform forensic investigations across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform and SaaS environments.
- Utilise digital forensic, eDiscovery and security technologies such as EnCase, FTK, Magnet AXIOM, Cellebrite, MSAB XRY, Microsoft Sentinel, Microsoft Defender and Microsoft Purview.
- Apply appropriate forensic methodologies to identify, collect, preserve and analyse evidence while maintaining its integrity and admissibility.
- Stay abreast of emerging forensic technologies, techniques, digital threats and investigative methodologies.
3. Risk, Regulatory and Compliance
- Conduct digital forensic investigations in accordance with applicable legislation, regulatory requirements, organisational policies and evidentiary standards.
- Perform root cause analysis to identify control weaknesses, vulnerabilities and contributing factors.
- Recommend corrective and preventative actions to reduce the likelihood of recurrence.
- Prepare affidavits, witness statements, forensic reports and other evidential documentation for disciplinary, civil, regulatory and criminal proceedings.
- Present and explain forensic findings to senior stakeholders, legal representatives, investigators and other relevant parties.
- Provide expert evidence or testimony at disciplinary hearings, tribunals, regulatory proceedings or court proceedings when required.
- Identify and escalate emerging digital crime trends, risks, vulnerabilities and significant investigative findings.
Qualifications and Experience
Minimum Qualification
- Bachelor’s degree in Digital Forensics, Cyber Security, Computer Science, Information Security, Information Systems or a related field.
Minimum Experience
- 5–7 years’ experience in Digital Forensics, Digital Investigations, Incident Response, Cyber Investigations or a closely related discipline.
- Demonstrated experience conducting complex digital forensic investigations across multiple technology environments.
- Experience gathering, preserving and analysing digital evidence while maintaining proper chain-of-custody procedures.
- Experience preparing evidential/forensic reports and presenting findings to senior stakeholders, legal representatives, regulators or other relevant parties.
- Experience providing forensic evidence or testimony in disciplinary, regulatory, civil or criminal proceedings would be advantageous.
Preferred Certifications
- GIAC: GCFA, GCFE, GNFA, GCTI
- Digital Forensics: EnCE, CFCE, CCE, CHFI
- Information Security: CISSP, CISM
- Microsoft Security Certifications
- AWS Certified Security – Specialty
- Google Professional Cloud Security Engineer
Job Purpose
Conduct in-depth digital forensic investigations to identify, preserve, acquire, analyse and report on digital evidence relating to fraud, cybercrime, misconduct, insider threats, data breaches and other technology-related incidents. The role will ensure investigations are conducted in accordance with established digital forensic frameworks, legal requirements, evidentiary standards and organisational policies.
Key Responsibilities
1. Data Management and Analysis
- Gather, preserve, acquire, extract and analyse digital evidence from endpoints, servers, mobile devices, cloud environments, Microsoft 365, network infrastructure and other digital sources.
- Recover deleted, hidden, encrypted or damaged data using approved forensic methodologies and industry-standard tools.
- Conduct forensic analysis of user activity, email communications, authentication records, cloud audit logs, browser activity and application artefacts.
- Analyse digital evidence to establish timelines, user activity, indicators of compromise and other relevant investigative findings.
- Prepare detailed forensic reports, findings, conclusions, recommendations, statistics and trend analysis for relevant stakeholders.
- Maintain an accurate chain of custody and ensure the secure storage, management, retention and disposal of digital evidence in accordance with organisational requirements.
2. Technology and Digital Forensics
- Conduct endpoint, mobile, cloud, network, memory and malware forensic investigations.
- Perform forensic investigations across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform and SaaS environments.
- Utilise digital forensic, eDiscovery and security technologies such as EnCase, FTK, Magnet AXIOM, Cellebrite, MSAB XRY, Microsoft Sentinel, Microsoft Defender and Microsoft Purview.
- Apply appropriate forensic methodologies to identify, collect, preserve and analyse evidence while maintaining its integrity and admissibility.
- Stay abreast of emerging forensic technologies, techniques, digital threats and investigative methodologies.
3. Risk, Regulatory and Compliance
- Conduct digital forensic investigations in accordance with applicable legislation, regulatory requirements, organisational policies and evidentiary standards.
- Perform root cause analysis to identify control weaknesses, vulnerabilities and contributing factors.
- Recommend corrective and preventative actions to reduce the likelihood of recurrence.
- Prepare affidavits, witness statements, forensic reports and other evidential documentation for disciplinary, civil, regulatory and criminal proceedings.
- Present and explain forensic findings to senior stakeholders, legal representatives, investigators and other relevant parties.
- Provide expert evidence or testimony at disciplinary hearings, tribunals, regulatory proceedings or court proceedings when required.
- Identify and escalate emerging digital crime trends, risks, vulnerabilities and significant investigative findings.
Qualifications and Experience
Minimum Qualification
- Bachelor’s degree in Digital Forensics, Cyber Security, Computer Science, Information Security, Information Systems or a related field.
Minimum Experience
- 5–7 years’ experience in Digital Forensics, Digital Investigations, Incident Response, Cyber Investigations or a closely related discipline.
- Demonstrated experience conducting complex digital forensic investigations across multiple technology environments.
- Experience gathering, preserving and analysing digital evidence while maintaining proper chain-of-custody procedures.
- Experience preparing evidential/forensic reports and presenting findings to senior stakeholders, legal representatives, regulators or other relevant parties.
- Experience providing forensic evidence or testimony in disciplinary, regulatory, civil or criminal proceedings would be advantageous.
Preferred Certifications
- GIAC: GCFA, GCFE, GNFA, GCTI
- Digital Forensics: EnCE, CFCE, CCE, CHFI
- Information Security: CISSP, CISM
- Microsoft Security Certifications
- AWS Certified Security – Specialty
- Google Professional Cloud Security Engineer
Desired Skills:
- Incident Response
- Endpoint Forensics
- Cloud Forensics
Employer & Job Benefits: