Digital Forensics & Incident Response Analyst
- 🇺🇸 United States
- On-site
- Staff / Principal
- 1 week ago
- Incident Response
- Windows
- Linux
- MacOS
- SQL
- Python
- Bash
- PowerShell
- OCI
- AWS
- Azure
- GCP
- ClickHouse
- RDS
- Redis
- GCIH
- GCIA
- GCFA
About the Team
The USDS JV Threat Detection and Response team is responsible for protecting TikTok’s people, data, and systems from threats that originate within the organization. We partner across Security, Legal, HR, IT, and Engineering to detect, investigate, and mitigate insider risks ranging from data exfiltration and policy violations to fraud and unauthorized access.
About the Role
As a Senior Analyst on the USJV Forensics & Response team, you will be at the forefront of our organization's digital investigations and incident response (DFIR) efforts. In this critical position, you will lead complex forensic investigations across a diverse technical landscape, including enterprise endpoints, servers, mobile devices, data platforms, and cloud infrastructure.
Responsibilities
- Incident Investigations & Response: Perform digital forensic investigations of endpoints, servers, mobile devices, data platforms, internal systems, and cloud infrastructure.
- Evidence Acquisition & Preservation: Identify, collect, image, and preserve physical and digital evidence in strict adherence to chain-of-custody protocols and legal standards.
- Data Analytics: Analyze complex data queries, trace data lineage, and assess outputs for data residency and compliance issues.
- Artifact & Malware Analysis: Analyze endpoints, file system artifacts, memory dumps, and network traffic to identify root cause, scope of incident, and TTPs.
- Reporting & Documentation: Author detailed forensic reports outlining technical findings, timeline of events, root cause analysis, and remediation recommendations.
- Legal & Compliance Support: Assist with internal investigations, eDiscovery requests, and coordinate with legal teams or law enforcement when necessary.
- Lab & Equipment Management: Maintain, configure, and upgrade the hardware, software, and network infrastructure of the digital forensics laboratory. Ensure go-kits and remote acquisition equipment is prepared for response scenarios.
Minimum Qualifications
- 1 year of experience in digital forensics & incident response, cybersecurity engineering, or data analytics experience.
- Strong understanding of Windows, Linux, and macOS file systems (NTFS, EXT4, APFS) and forensic artifacts.
- Moderate report writing skills, detailing analysis, procedures performed, and findings, capable of being consumed by executive-level stakeholders.
- Moderate hands-on experience with evidence handling, chain-of-custody, and contemporaneous note taking.
Preferred Qualifications
- Exposure to data analytics, analyzing complex SQL queries, data tasks, data lineage, and outputs.
- Exposure to scripting in Python, Bash, or PowerShell for automation and log parsing.
- Exposure to working with cloud platforms (OCI, AWS, Azure, or GCP).
- Hands-on technical experience investigating, responding to high-stakes incidents, including the ability to work effectively with engineers and technical operators.
- Experience analyzing varying data structures, including Apache Hive, ClickHouse, RDS, and Redis.
- Experience operating in regulated environments, with strict compliance requirements, supporting audits and evidence requests.
- Bachelor's in cybersecurity engineering, computer science, or digital forensics; OR have equivalent industry experience.
- Relevant Certifications: GCIH, GCIA, GIME, GCFE, GCFA, GREM, or equivalent.
Digital Forensics & Incident Response Analyst · TikTok USDS