Hiring.Camp

DFIR Analyst (Digital Forensics & Incident Response)

ACE Money Transfer

·

Yesterday

Location
Lahore, Punjab
Type
Full-time
Department
IT
Education
Bachelor
Closing date
Today
Source
ApplyToJob

Description

About Us

ACE Money Transfer is a UK-based multinational company headquartered in Manchester, United Kingdom. The company provides online remittance services to individuals across 29 countries in the UK, Europe, Canada, and Australia, enabling customers to send money securely to more than 100 countries worldwide.

Role Summary

The DFIR Analyst owns the Digital Forensics and Incident Response (DFIR) function at ACE Money Transfer.

This role is responsible for receiving and acknowledging security incidents reported through any channel, triaging and investigating them, performing forensically sound acquisition and analysis of digital evidence, identifying the root cause, attack vector, and business impact, delivering clear remediation recommendations, and defining preventive controls to reduce the likelihood of recurrence.

The role combines the rigor of digital forensics—including evidence preservation, forensic imaging, chain of custody, and deep host, network, and memory analysis—with the fast-paced demands of incident response, including containment, eradication, and recovery. The position operates within ACE's Information Security Management System (ISMS) and supports the organization's dual-jurisdiction regulatory obligations across the UK (FCA and UK GDPR) and Ireland (CBI, DORA, and EU GDPR), with PCI DSS v4.0.1 also within scope. Every investigation must produce a defensible, well-documented outcome capable of withstanding regulatory, legal, and audit scrutiny.

Key Responsibilities

Incident Intake & Triage

  • Monitor and respond to security incidents reported through any channel, including SIEM/SOAR alerts, email, ticketing systems, phishing reports, the service desk, direct escalations, or automated detection tools.
  • Acknowledge reported incidents within defined SLA timeframes and accurately record them in the incident or case management system.
  • Perform initial triage to classify severity, priority, and scope, and determine whether an event is a false positive, a security event, or a confirmed incident requiring a forensic response.

Digital Forensics

  • Perform forensically sound acquisition and preservation of digital evidence across endpoints, servers, mobile devices, cloud environments, network infrastructure, and email systems.
  • Create and verify forensic images (disk, memory, and logs) using write blockers and cryptographic hashing to ensure evidence integrity and admissibility.
  • Conduct host forensics, including file system, registry, event log, and artifact analysis, as well as memory forensics, network packet analysis, and log analysis to reconstruct attack timelines.
  • Perform malware triage and behavioral analysis in a controlled environment to determine malware capabilities, persistence mechanisms, and overall impact.
  • Maintain strict chain-of-custody procedures and evidence-handling practices to support forensic, regulatory, and legal requirements.

Investigation & Analysis

  • Conduct end-to-end investigations of confirmed security incidents by correlating forensic evidence across SIEM, endpoints, networks, identity platforms, email systems, and cloud telemetry.
  • Identify the root cause, initial access vector, affected assets and accounts, attack path, blast radius, lateral movement, data accessed or exfiltrated, and overall business impact.
  • Map observed adversary activity to the MITRE ATT&CK framework and enrich indicators of compromise (IOCs) using threat intelligence sources.
  • Determine the full scope of compromise and confirm whether personal data or cardholder data has been affected to support regulatory notification decisions.

Containment, Eradication & Recovery

  • Execute or coordinate containment activities (such as host isolation, session revocation, credential resets, and blocking actions) within the approved bounded-autonomy framework, escalating for human approval where required.
  • Lead or coordinate the eradication of attacker persistence mechanisms, malware, and unauthorized accounts, ensuring the environment is fully remediated.
  • Provide clear, practical, and actionable remediation guidance to asset owners, IT teams, and system administrators.
  • Verify the effectiveness of remediation efforts, support service restoration, and confirm the return to normal operations before formally closing incidents.

Prevention & Continuous Improvement

  • Recommend and support the implementation of preventive controls and detection improvements to reduce the likelihood of recurring incidents.
  • Propose new or optimized detection rules, forensic collection methods, incident response playbooks, and automation to strengthen DFIR capabilities.
  • Maintain and enhance DFIR runbooks, forensic toolkits, evidence-handling procedures, and the SOC knowledge base.
  • Contribute lessons learned during post-incident reviews and drive corrective and preventive actions through to completion.

Documentation, Reporting & Compliance

  • Produce accurate incident investigation and forensic reports detailing timelines, root causes, supporting evidence, business impact, actions taken, remediation activities, and preventive recommendations.
  • Support regulatory notification requirements (FCA, CBI, UK GDPR, EU GDPR, DORA, and PCI DSS) by providing timely and defensible forensic evidence to the Manager – Cybersecurity.
  • Ensure adherence to ACE's Incident Management Procedures, ISMS requirements, and recognized forensic best practices (such as ACPO and NIST SP 800-86) throughout the investigation lifecycle.

Required Qualifications & Experience

  • Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, Information Technology, or a related discipline (or equivalent practical experience).
  • 2–5 years of hands-on experience in Digital Forensics and Incident Response (DFIR), Digital Forensics, or a SOC/Blue Team incident response role.
  • Strong understanding of the incident response lifecycle, including preparation, detection, analysis, containment, eradication, recovery, and lessons learned.
  • Demonstrated experience with forensic imaging, host, disk, and memory forensics, log analysis, network forensics, and evidence handling.
  • Practical experience with SIEM, EDR/XDR platforms, forensic tools, and incident/case management systems.
  • Solid understanding of attacker techniques, malware behavior, phishing attacks, and identity-based threats, with familiarity with the MITRE ATT&CK framework.

Preferred Qualifications

  • Entry-level or foundational certifications such as CompTIA Security+, CySA+, BTL1, CHFI, or equivalent.
  • Basic understanding of digital forensic principles and evidence-handling procedures.
  • Familiarity with common SOC and forensic tools used for log analysis and incident investigations.
  • Working knowledge of cloud environments, including AWS and Microsoft Entra ID/Microsoft 365.
  • General awareness of DORA, FCA, PCI DSS, UK GDPR, and EU GDPR incident reporting and breach notification requirements.

Key Competencies

  • Meticulous and methodical approach to evidence handling while maintaining forensic integrity.
  • Calm, structured decision-making during high-pressure situations and active security incidents.
  • Strong analytical and investigative mindset with exceptional attention to detail.
  • Excellent written and verbal communication skills, with the ability to communicate technical findings to both technical and non-technical audiences.
  • Strong sense of ownership, accountability, and discipline in following processes, preserving evidence, and meeting service-level agreements.
  • Collaborative team player with the ability to work effectively across SOC, IT, Legal, Compliance, Risk, and business stakeholders.

Skills

AWSCybersecuritySIEMSOCComplianceGDPRCompTIA

Similar Jobs

2

Cyber - Digital Forensics & Incident Response Analyst (DFIR) - SDS

Santander Effect Our work touches · Encinar P02, Spain

1 month ago

Cyber - Digital Forensics & Incident Response Analyst (DFIR) - SDS

Santander · Encinar P02, Spain

1 month ago