الوصف الوظيفي
الأدوار والمسؤوليات
يتحمل محلل الأدلة الرقمية مسؤولية إجراء التحقيقات الجنائية الرقمية، واكتساب الأدلة، والحفظ، والتحليل، والتقارير في دعم حوادث الأمن السيبراني، وال التحقيقات القانونية، والمتطلبات التنظيمية، والمسائل الأمنية الداخلية. يلعب الدور دوراً حاسماً في تحديد المصدر والنطاق والتأثير للحوادث السيبرانية مع ضمان سلامة وقابلية قبول الأدلة الرقمية. يعمل الدور عن كثب مع فرق الاستجابة للحوادث، وعمليات الأمن، وأصحاب المصلحة القانونية، وممثلي العملاء للتحقيق في حوادث السيبرانية، وجمع الأدلة الجنائية، وتقديم النتائج الفنية التي تدعم اتخاذ القرار، والتخفيف، والإجراءات القانونية المحتملة.
المسؤوليات:
- اكتساب الأدلة الرقمية preserves الرقابة وحفظها
- إجراء اكتساب جنائي للأدلة الرقمية من محطات العمل، والخوادم، والأجهزة المحمولة، والبيئات الافتراضية، والمنصات السحابية ووسائط التخزين القابلة للإزالة
- التأكد من اتباع إجراءات سلسلة الحفظ الصحيحة طوال التحقيقات.
- الحفاظ على تكامل الأدلة باستخدام مناهج وأدوات أدلة معتمدة.
- إجراء اكتسابات جنائية حية وجامدة.
- الحفاظ على مستودعات الأدلة الجنائية والوثائق.
- التحقيق والتحليل الجنائي
- تحليل الأدلة الرقمية لتحديد الوصول غير المصرح به، سرقة البيانات، التهديدات من الداخل، نشاط البرمجيات الخبيثة، محاولات تدمير البيانات والامتثال للسياسات
- فحص أنظمة الملفات، آثار السجل، سجلات الأحداث، آثار المتصفح، سجلات نشاط المستخدم، وأدلة الشبكة
- إجراء تحليل الجدول الزمني وإعادة بناء الأحداث.
- دعم جهود التعقب وتحليل مسار الهجوم حيثما كان ذلك قابلاً للتطبيق.
- الإبلاغ والتوثيق
- إعداد تقارير جنائية تفصيلية توثق المنهجية والنتائج والأدلة المجمعة والاستنتاجات
- تقديم النتائج إلى أصحاب المصلحة الفنيين وغير الفنيين.
- الحفاظ على سجلات التحقيق وفقاً للمتطلبات التنظيمية والقانونية.
- دعم نشاطات إعداد الشاهد الخبير عند الطلب.
- البحث والتحسين المستمر
- الحفاظ على الوعي بتقنيات الهجوم الناشئة، ومنهجيات مكافحة الأدلة الرقمية، واتجاهات التحقيق الرقمي
- دعم تطوير إجراءات التحقيق، ومنهجيات الأدلة الرقمية والمعايير handling الأدلة
- المشاركة في التدريبات الفنية ومبادرات تطوير القدرات.
المُرشَّح المثالي
درجة البكالوريوس أو الدبلوم المتوسط (الحد الأدنى) من مؤسسة معترف بها. خبرة لا تقل عن سنتين في الأمن السيبراني، بما في ذلك ثماني التحقيقات الجنائية الرقمية المكتملة، على الأقل شهادة أدلة جنائية معتمدة من NCSC مثل (GCFE، GCFA، CHFI)، أو شهادة معادلة في نفس المجال معتمدة من NCSC. استخدام عملي لأدوات الأدلة الرقمية وممارسات التعامل مع الأدلة بشكل سليم. يُفضل التعرض للأدلة الرقمية في الأجهزة المحمولة والسحابة. يفضل الخبرة في بيئة MSSP أو مختبر أو بيئة جنائية قانونية.”
Job Description
Roles & Responsibilities
The Digital Forensics Analyst is responsible for conducting forensic investigations, evidence acquisition, preservation, analysis, and reporting activities in support of cybersecurity incidents, legal investigations, regulatory requirements, and internal security matters. The role plays a critical part in identifying the source, scope, and impact of cyber incidents while ensuring the integrity and admissibility of digital evidence. The role works closely with Incident Response teams, Security Operations, Legal stakeholders, and customer representatives to investigate cyber incidents, collect forensic evidence, and provide technical findings that support decision-making, remediation, and potential legal proceedings.
Responsibilities:
- Digital Evidence Acquisition & Preservation
- Perform forensic acquisition of digital evidence from Workstations, Servers, Mobile devices, Virtual environments, Cloud platforms and Removable media
- Ensure proper chain of custody procedures are followed throughout investigations.
- Preserve evidence integrity using approved forensic methodologies and tools.
- Conduct live and dead-box forensic acquisitions.
- Maintain forensic evidence repositories and documentation.
- Forensic Investigation & Analysis
- Analyze digital evidence to identify Unauthorized access ,Data theft , Insider threats ,Malware activity ,Data destruction attempts and Policy violations
- Examine File systems ,Registry artifacts ,Event logs ,Browser artifacts ,User activity records and Network evidence
- Conduct timeline analysis and event reconstruction activities.
- Support attribution efforts and attack path analysis where applicable.
- Reporting & Documentation
- Prepare detailed forensic reports documenting the Methodology, Findings, Evidence collected and Conclusions
- Present findings to technical and non-technical stakeholders.
- Maintain investigation records in accordance with regulatory and legal requirements.
- Support expert witness preparation activities where required.
- Research & Continuous Improvement
- Maintain awareness of Emerging attack techniques, Anti-forensics methodologies, Digital investigation trends and Digital investigation trends
- Support the development of Investigation procedures, Forensic methodologies and Evidence handling standards
- Participate in technical training and capability development initiatives.
Desired Candidate Profile
Bachelor's degree or intermediate diploma (minimum) from a recognised institution. Minimum 2 years experience in cybersecurity, including at least 2 completed digital forensic investigations. At least one valid NCSC-approved forensics certification like (GCFE, GCFA, CHFI), or another equivalent certification in the same field that is approved by the NCSC) Hands-on use of forensic tools and sound evidence-handling practice. Exposure to mobile and cloud forensics is preferable. Experience in an MSSP, lab, or law-enforcement forensic environment is preferable.