Forensic Team Lead
We are looking for a highly experienced Forensics Team Lead who has a proven track record of identifying and investigating sophisticated cyber threats in real-world environments. In this role, you will lead a specialized forensics function, operating at the core of our cloud-native infrastructure to proactively detect, investigate, and neutralize advanced adversaries. You will go beyond tools and predefined alerts—leveraging raw data, custom analysis, and forward-thinking strategies to stay ahead of attackers.
- Establish and lead the digital forensics function.
- Build and mentor a high-performing team of investigators, setting standards for excellence and rigor.
- Conduct advanced threat hunting activities across cloud environments to detect sophisticated attacks, including APTs and stealth intrusions.
- Perform deep historical investigations for newly discovered vulnerabilities, validating whether they were previously exploited and assessing potential impact.
- Analyze diverse data sources such as VPC flow logs, audit trails, and system artifacts.
- Adapt to new data formats and scenarios without relying solely on vendor tooling.
- Lead forensic investigations during active security incidents, transforming complex data into clear insights and actionable response plans.
- Develop and leverage automation (e.g., Python, AI-driven tooling) to streamline forensic workflows and enhance investigative capabilities.
- 5+ years in digital forensics, incident response, or threat hunting, with a demonstrated ability to uncover and investigate complex security incidents.
- Strong experience investigating security events in cloud environments, including working with audit logs, identity systems, and infrastructure telemetry.
- Proficiency in scripting or programming (e.g., Python) to build custom tools, automate analysis, and handle non-standard data formats.
- Ability to think critically and approach problems from an attacker’s perspective, identifying hidden patterns and potential attack paths.
- Treat vulnerabilities as potential incidents—conducting thorough historical analysis to confirm whether exploitation has occurred.
- Proven ability to lead teams during high-pressure situations, maintaining clarity, focus, and effective decision-making.



