Search

Cloud Forensics Analyst - DT #9 - Remote

PublishedPublished: 6/14/2022
Technology

Job Description

Job DescriptionCloud Forensics Analyst

Location: Remote
Duration: 1–2 Weeks with potential extension

Position Overview

We are seeking an experienced Cloud Forensics Analyst to conduct forensic investigations across cloud environments, including AWS, Microsoft Azure, and Google Cloud Platform (GCP).

The role will focus on investigating compromised cloud accounts, unauthorized access, suspicious activity, and security incidents across cloud infrastructure. The ideal candidate will have hands-on experience with cloud logging, IAM analysis, workload forensics, container/Kubernetes environments, SIEM platforms, and cloud incident response.

Key Responsibilities

  • Conduct forensic investigations across AWS, Azure, and/or GCP environments.
  • Analyze cloud-based:
    • Audit and security logs
    • Identity and access activity
    • Storage resources
    • Compute instances
    • Network activity
  • Investigate compromised cloud accounts, unauthorized access, and suspicious identity activity.
  • Perform forensic collection from cloud workloads and virtual infrastructure.
  • Analyze cloud IAM activity and identify potential privilege escalation and attack paths.
  • Investigate cloud-native security events and indicators of compromise.
  • Perform forensic analysis of Kubernetes and containerized environments.
  • Correlate cloud telemetry with SIEM and other security data sources.
  • Support cloud incident response and threat hunting activities.
  • Develop incident timelines and document investigative findings.
  • Provide recommendations for containment, remediation, and improved cloud security controls.
  • Prepare clear technical reports and communicate findings to security and infrastructure teams.

Key Technical Skills Cloud Platforms

  • AWS
  • Microsoft Azure
  • Google Cloud Platform (GCP)

Cloud Security & Logging

  • AWS CloudTrail
  • AWS GuardDuty
  • Microsoft Defender for Cloud
  • Azure Activity Logs
  • Cloud IAM / Identity and Access Management
  • Cloud audit and security logging

Cloud & Container Forensics

  • Cloud workload forensic collection
  • Compute and storage forensics
  • Kubernetes forensics
  • Container forensics
  • Cloud attack-path analysis
  • Identity and privilege analysis

Security & Automation

  • SIEM platforms
  • Python
  • Terraform
  • Incident response
  • Threat hunting

Required Qualifications

  • Proven experience in cloud forensics, cloud security, or cloud incident response.
  • Hands-on experience investigating security incidents within AWS, Azure, and/or GCP.
  • Strong understanding of cloud logging, auditing, identity, access management, and network activity.
  • Experience investigating compromised cloud accounts and unauthorized access.
  • Experience collecting and analyzing forensic evidence from cloud workloads.
  • Strong understanding of cloud IAM and privilege escalation risks.
  • Experience with Kubernetes and/or container forensics.
  • Familiarity with SIEM platforms and security-event correlation.
  • Experience with Python or similar scripting languages for investigation and automation.
  • Working knowledge of Terraform and infrastructure-as-code concepts.
  • Strong understanding of incident response and threat-hunting methodologies.
  • Excellent analytical, documentation, and communication skills.
  • Ability to work independently in a remote environment.
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...