Data First Jobs

Central Business Solutions Inc.

Analyst Investigations and Forensics (Google SecOps/Chronicle)

Contract · In Office · USA

Posted Sep 10, 2026

Work Options
Cloud Stack
Industry
Job Type
Position Group
  • About the Company
  • We are seeking a Senior Analyst, Investigations and Forensics on a contract-to-hire basis who will serve as the team’s deep technical specialist for endpoint, cloud, and identity forensics. This individual will independently lead and execute complex investigations across insider threat, employee misconduct, IP theft, fraud, ethics breaches, and security incidents, producing legally defensible findings that can support HR actions, litigation, regulatory response, and executive decision-making. Success in this role can lead to a permanent full-time position within the team. This is not a purely reactive role. The successful candidate will contribute to proactive detection capability development, forensic tooling, and the integration of AI into investigative workflows. They will be expected to exercise strong independent judgment, communicate with precision, and maintain the highest standards of evidentiary integrity.
  • About the Role
  • Forensic Investigations Lead and execute end-to-end digital forensic investigations across endpoint, cloud, email, identity, and SaaS environments.

Responsibilities

  • Conduct deep-dive analysis for insider threat, data exfiltration, IP theft, fraud, employee misconduct, and ethics matter investigations.
  • Support SIRT as the Advanced Forensic Tier on high-severity security incidents — establishing attribution, root cause, and precise forensic timelines.
  • Perform forensic imaging and acquisition of endpoints and storage media in accordance with established forensic standards and chain of custody protocols, ensuring evidence integrity from collection through analysis.
  • Conduct structured forensic analysis using industry-standard platforms including Magnet AXIOM Cyber, Cellebrite Endpoint Collector, Cellebrite Endpoint Investigator, and Sumuri Recon.
  • Collect, preserve, and analyze digital evidence in a forensically sound manner, maintaining chain of custody and evidentiary integrity throughout.
  • Produce executive-quality investigation reports suitable for HR proceedings, legal review, litigation support, and regulatory disclosure.

Qualifications

  • 5+ years of progressive experience in digital forensics, cybersecurity investigations, or a closely related discipline.
  • Demonstrated expertise conducting insider threat, data exfiltration, and employee misconduct investigations in enterprise environments.
  • Proficiency with enterprise forensic platforms: Magnet AXIOM Cyber, Cellebrite Endpoint Collector and Endpoint Investigator, and Sumuri Recon or comparable tooling.
  • Strong working knowledge of forensic imaging standards and acquisition methodologies — including write-blocking, hash verification, and documented chain of custody — consistent with industry frameworks such as ACPO, SWGDE, or equivalent.
  • Hands-on proficiency with EDR platforms — particularly CrowdStrike Falcon — for behavioral analysis, process telemetry, and forensic artifact review.
  • Strong working knowledge of Microsoft 365 forensics: Exchange Online mail flow and Recoverable Items, Azure AD sign-in and audit logs, Purview Compliance, and MDE.
  • Solid understanding of endpoint forensics across Windows and macOS: file system artifacts, registry analysis, prefetch/MRU data, browser forensics, and OS-level event logs.
  • Working knowledge of cloud and SaaS forensic investigation: OAuth and SAML authentication flows, conditional access logs, cloud storage access patterns, and admin audit trails.
  • Familiarity with network-layer investigation fundamentals: DNS, proxy, VPN, and firewall log analysis sufficient to reconstruct data movement and access patterns.
  • Proficiency in Google SecOps/Chronicle (YARA-L) for investigation and threat hunting.
  • Experience using device management platforms (JAMF, Intune, SCCM) for custodian device attribution and asset profiling in the context of investigations.
  • Proven ability to produce legally defensible, executive-quality investigation reports with precise evidentiary grounding.
  • Experience supporting eDiscovery processes, including ESI collection, legal hold execution, and custodian data scoping.
  • Required Skills
  • Experience working within or directly supporting corporate Legal, HR, or Ethics functions on sensitive employment or litigation matters.
  • Solid grounding in incident response methodology — including initial triage, scoping, containment sequencing, and post-incident analysis — with experience leading or co-leading high-impact security incidents.
  • Proficiency in Google SecOps/Chronicle and Splunk (SPL).
  • Familiarity with Zscaler proxy log analysis and cloud access security broker (CASB) telemetry.
  • Prior experience testifying or providing declarations in legal, arbitration, or regulatory proceedings.
  • Relevant certifications: GCFE, GCFA, EnCE, CFCE, CISSP, or equivalent.

Mention you found this on Data First Jobs — it helps us bring you more roles like this.

Analyst Investigations and Forensics (Google SecOps/Chronicle)

Central Business Solutions Inc.

Like this role? Get carefully selected jobs like it, twice a week, straight to your inbox.

Free, no spam. Unsubscribe anytime.