Oh oh! Awesome! Info! {$ msg.text $} ({$ msg.count $})

Incident Response Investigator

  • Applications are considered on a rolling basis
  • Multiple locations
  • Hybrid
  • Monthly salary: €4,000 - €6,000
  • Applications are considered on a rolling basis
  • Multiple locations
  • Hybrid
  • Monthly salary: €4,000 - €6,000

WithSecure™ protects businesses all over the world from modern threats. We do this through a Co-security approach born from first-hand knowledge that no one can solve every cyber security problem alone. Every single day, our diverse, growing team fights against online extortion, threats to national infrastructure, the unlawful spread of sensitive information, and everything in-between. The best part about working for WithSecure is our people! We are a community of dedicated and passionate professionals that take workplace happiness seriously. If you’re looking for something that’s more than just a job – we’d love to hear from you.

We are looking for an Incident Response Investigator to join our team with the primary responsibility of this role is to work with WithSecure’s clients to deliver Investigations and Incident Response services. These services are aimed at responding to and containing security incidents for our clients, with a particular focus on advanced targeted attacks (known as Advanced Persistent Threat- APT). This can also cover a wide range of areas including forensic investigations, proactive compromise assessments and guiding our clients through the implementation of response procedures.

The role also requires the ability to clearly communicate to a range of audiences from technical practitioners through to executive boards. This requires the ability to identify technical issues and describe them in the language of the business leaders you are engaged with.

A successful candidate should have experience of both enterprise IT platforms and information security. They will be required to demonstrate an understand the motivations and methods adopted by a wide range of threat sources with a good understanding of how exploitation of systems occurs.

Key Responsibilities

  • Performing investigations, as part of a team, for WithSecure clients and producing high quality reports to present findings and guidance.
  • Maintaining target utilization on client chargeable projects whilst working as an Incident Response Investigator.
  • Producing output to highlight the technical competence of the company to a standard that can be published.
  • Supporting your practice area in successful delivery and growth.

What are we looking for?

  • Experience of one or more of the following
    • Client-server infrastructures,
    • Security architectures,
    • SIEM systems,
    • AV/EDR solutions
    • Cloud platforms
  • Experience of troubleshooting TCP/IP networking with the ability to perform network forensic analysis to a packet level.
  • Ability to perform file-system analysis including FAT, NTFS, HFS+ and/or EXT2/3/4 and ability to find and extract common disk-based indicators of compromise.
  • Familiarity with Windows, Linux and/or OS X internals together with the normal operation of these systems.
  • Knowledge of the phases of Incident Response as defined by NIST.
  • Familiarity with MITRE ATT&CK Matrix for Enterprise framework.
  • Knowledge of and experience in memory analysis.
  • Ability to report key findings in a clear and concise manner both at technical and senior management level.

Bonus points

  • Experience with a scripting language such as Python, Ruby, PowerShell or Bash is desirable.
  • Knowledge of common cloud technologies.
  • Vendor independent qualification in Incident Response and Forensics such as GIAC, IISFA,IACIS, ISFCE, ECCouncil or CREST certifications (e.g. CFCE, CCE, CIFI, CHFI, ECIH, GCIH, GCIA, GCFA, GCFE, GREM, GCED, Intrusion Analyst, Network or Host Intrusion Analyst or Malware Reverse Engineer).
  • Vendor specific qualification such as AccessData Certified Examiner (ACE), Encase Certified Examiner (EnCE) certification or X-Ways Professional in Evidence Recovery Techniques (X-PERT).

What will you get from us

  • Freedom – you will have the opportunity to define new ways of working how we engage with our customers, and how product value gets represented.
  • You will work together with experienced and enthusiastic colleagues, and within WithSecure you will find some of the best minds in the cyber security industry.
  • Your work will be clearly visible and recognized – all over the world and across our business unit.
  • You can rely on the support from the entire WithSecure leadership including our top executives.

Work with great people

Kinga Baran - Product Operations Lead
Kinga Baran
Product Operations Lead
"You can develop yourself in many contexts."
Joni Vatjus-Anttila - Director, Customer Success Management
Joni Vatjus-Anttila
Director, Customer Success Management
"Being able to say that our job is to keep our customers safe is everything to me. It creates a sense of purpose."
Łukasz Kwieciński - Senior Manager, R&D
Łukasz Kwieciński
Senior Manager, R&D
"Working here has been a transformative experience — the sophisticated challenges drive rapid growth, while the friendly, supportive team makes even the toughest problems easier to tackle."

Great Place to Work

  • Over 900 amazing colleagues in 18 offices

  • Possibility to protect the world

  • Work with best of class experts who care

  • Relaxed, open and fun working environment

  • 70+ nationalities

  • Global with the spirit of a small company

About the company

Purpose – Why we exist
We are here to build and sustain trust in a digital society
We are here to build and sustain trust in a digital society — trust that is threatened by uncertainty, fear and worry caused by cyber attacks and crime.

Vision – Where we are heading
No one should experience a serious loss because of a cyber attack
We envision a future where no one should experience a serious loss or be put out of business because of cyber attack or crime. At least no one who puts their trust in us.

Mission – What we do
Accelerate transition to outcome-based security
Our mission is to research, innovate and build technologies, human expertise and delivery-business models that will accelerate our customers’ and partners’ transition to outcome-based security.

Diversity & Inclusion:

WithSecure is an equal opportunity employer and believe that employing a diverse workforce is central to our success. We are committed to ensuring all qualified applicants will receive consideration for employment without regard to nationality, colour, race, ethnic or national origin, sex, gender (including gender reassignment), sexual orientation, religion or belief, age, marital status or physical or mental disability.
We will do everything we can to support you during your application. If you need us to make any adjustments to our recruitment process, speak to our recruitment team who will be happy to support you!

Ari Lappalainen | Contact Person

I'm interested
WithSecure

Multiple locations | Hybrid
Visit website