About this role
Conduct in-depth digital forensic investigations across the the company, in adherence with the Group Digital Forensic Investigation Framework and standards, to identify, preserve, analyse and report on digital evidence relating to fraud, cybercrime, misconduct, insider threats and data breaches. Data Management and Analysis Gather, preserve, acquire, extract and analyse digital evidence from endpoints, servers, mobile devices, cloud environments, Microsoft 365, network infrastructure, and other digital sources. Recover deleted, hidden, encrypted, or damaged data using approved forensic methodologies and tools. Conduct forensic analysis of user activity, email communications, authentication records, cloud audit logs, browser activity, and application artefacts. Prepare detailed forensic reports, statistics, trends, findings, conclusions, and recommendations for stakeholders. Maintain chain of custody and ensure secure storage, management, and retention of digital evidence in accordance with organisational standards. Technology and Architecture Conduct endpoint, mobile, cloud, network, memory, and malware forensic investigations. Perform forensic investigations across Microsoft Azure, Microsoft 365, AWS, Google Cloud Platform, and SaaS environments. Utilise forensic, eDiscovery, and security technologies including EnCase, FTK, Magnet AXIOM, Cellebrite, MSAB XRY, Microsoft Sentinel, Microsoft Defender, Microsoft Purview, and other industry-standard tools. Risk, Regulatory and Compliance Conduct digital forensic investigations in accordance with legal, regulatory, and organisational requirements. Conduct root cause analysis to identify control weaknesses and recommend corrective actions to mitigate future incidents. Prepare affidavits, witness statements, and evidential reports for disciplinary, civil, regulatory, and criminal proceedings. Testify and present forensic findings in disciplinary hearings, tribunals, and court proceedings when required. Identify and escalate emerging digital crime trends, risks, and significant findings to appropriate stakeholders. Qualifications and Experience Minimum Qualifications Bachelor’s degree in digital Forensics, Cyber Security, Computer Science, Information Security, Information Systems, or a related field. Experience Minimum 5–7 years' experience in Digital Forensics, Incident Response, Cyber Investigations, or a related discipline. Experience preparing evidential reports and presenting findings to senior stakeholders, regulators, and legal representatives. Preferred Certifications GCFA, GCFE, GNFA, GCTI EnCE, CFCE, CCE, CHFI CISSP, CISM Microsoft Security Certifications AWS Security Specialty Google Professional Cloud Security Engineer