Description
The digital forensics analyst is responsible for conducting forensic investigations, evidence acquisition, preservation, analysis, and reporting activities in support of cybersecurity incidents, legal investigations, regulatory requirements, and internal security matters. The role plays a critical part in identifying the source, scope, and impact of cyber incidents while ensuring the integrity and admissibility of digital evidence.
The role works closely with incident response teams, security operations, legal stakeholders, and customer representatives to investigate cyber incidents, collect forensic evidence, and provide technical findings that support decision-making, remediation, and potential legal proceedings.
Responsibilities
Digital evidence acquisition & preservation
Perform forensic acquisition of digital evidence from workstations, servers, mobile devices, virtual environments, cloud platforms, and removable media.
Ensure proper chain of custody procedures are followed throughout investigations.
Preserve evidence integrity using approved forensic methodologies and tools.
Conduct live and dead-box forensic acquisitions.
Maintain forensic evidence repositories and documentation.
Forensic investigation & analysis
Analyze digital evidence to identify unauthorized access, data theft, insider threats, malware activity, data destruction attempts, and policy violations.
Examine file systems, registry artifacts, event logs, browser artifacts, user activity records, and network evidence.
Conduct timeline analysis and event reconstruction activities.
Support attribution efforts and attack path analysis where applicable.
Reporting & documentation
Prepare detailed forensic reports documenting the methodology, findings, evidence collected, and conclusions.
Present findings to technical and non-technical stakeholders.
Maintain investigation records in accordance with regulatory and legal requirements.
Support expert witness preparation activities where required.
Research & continuous improvement
Maintain awareness of emerging attack techniques, anti-forensics methodologies, and digital investigation trends.
Support the development of investigation procedures, forensic methodologies, and evidence handling standards.
Participate in technical training and capability development initiatives.
Our culture & code of conduct
At ZainTECH, we take pride in a culture built on collaboration, innovation, and uncompromising integrity. We are looking for individuals who share these values and are committed to customer-centricity and ethical excellence. All employees are expected to uphold our code of conduct, which serves as a guiding framework for responsible behavior across everything we do—from how we work with each other to how we engage with clients and partners globally.
Requirements
- Bachelor's degree or intermediate diploma (minimum) from a recognised institution.
- Minimum 2 years experience in cybersecurity, including at least 2 completed digital forensic investigations.
- At least one valid NCSC-approved forensics certification like GCFE, GCFA, CHFI, or another equivalent certification in the same field that is approved by the NCSC.
- Hands-on use of forensic tools and sound evidence-handling practice.
- Exposure to mobile and cloud forensics is preferable.
- Experience in an MSSP, lab, or law-enforcement forensic environment is preferable.
الوصف
المحلل التحري الرقمي مسؤول عن إجراء التحقيقات الجنائية واكتساب الأدلة والحفظ والتحليل والتقارير في دعم حوادث الأمن السيبراني والتحقيقات القانونية والمتطلبات التنظيمية ومسائل الأمن الداخلي. تلعب هذه الدور دورًا حاسمًا في تحديد المصدر والنطاق والتأثير لحوادث السيبرانية مع ضمان سلامة الأدلة الرقمية وقابلية قبولها كدليل.
يعمل الدور عن كثب مع فرق الاستجابة للحوادث وعمليات الأمن والجهات القانونية وممثلي العملاء للتحقيق في حوادث سيبرانية وجمع الأدلة الجنائية وتقديم النتائج الفنية التي تدعم اتخاذ القرار والتصحيح والإجراءات القانونية المحتملة.
المسؤوليات
اكتساب الأدلة الرقمية والحفظ
أداء اكتساب جنائي للأدلة الرقمية من أجهزة الكمبيوتر وأجهزة الخادم والأجهزة المحمولة والبيئات الافتراضية ومنصات السحابة والوسائط القابلة للإزالة.
التأكد من اتباع إجراءات سلسلة الحيازة بشكل صحيح طوال التحقيقات.
الحفاظ على سلامة الأدلة باستخدام منهجيات وأدوات جنائية معتمدة.
إجراء اكتسابات تشخيصية حية وميتة.
الحفاظ على مستودعات الأدلة الجنائية والوثائق اللازمة.
التحقيق والتحليل الجنائي
تحليل الأدلة الرقمية لتحديد الوصول غير المصرح به، وسرقة البيانات، والتهديدات الداخلية، ونشاط البرمجيات الخبيثة، ومحاولات تدمير البيانات، وانتهاكات السياسات.
فحص أنظمة الملفات، وآثار التسجيل، وسجلات الأحداث، وآثار المتصفح، وسجلات نشاط المستخدم، وأدلة الشبكة.
إجراء تحليل الجدول الزمني وإعادة بناء الأحداث.
دعم جهود التعريف ومسار الهجوم حيثما كان ذلك ممكنًا.
التقارير والتوثيق
إعداد تقارير جنائية مفصلة توثق المنهجية والنتائج والأدلة المجمعة والاستنتاجات.
عرض النتائج على الأطراف التقنية وغير التقنية.
الحفاظ على سجلات التحقيق وفق المتطلبات التنظيمية والقانونية.
دعم إجراءات تجهيز الشاهد الخبير حيثما كان مطلوبًا.
البحث والتحسين المستمر
الحفاظ على الوعي بأساليب الهجوم الناشئة، ومنهجيات مضادة للتحليل الجنائي، واتجاهات التحقيق الرقمي.
دعم تطوير إجراءات التحقيق، ومنهجيات التحري، ومعايير التعامل مع الأدلة.
المشاركة في التدريبات الفنية ومبادرات تطوير القدرات.
ثقافتنا ومدونة السلوك
في ZainTECH، نفخر بثقافة مبنية على التعاون والابتكار والنزاهة التي لا تتزعزع. نحن نبحث عن أفراد يشاركون هذه القيم ومكرسين للتركز على العميل والتفوق الأخلاقي. من المتوقع أن يلتزم جميع الموظفين بمدونة السلوك التي تعد إطارًا توجيهيًا للسلوك المسؤول في كل ما نقوم به—from كيفية العمل مع بعضنا البعض وإلى كيفية تعاملنا مع العملاء والشركاء حول العالم.
الـمتطلبات
- درجة البكالوريوس أو دبلوم متوسط (كحد أدنى) من مؤسسة معترف بها.
- خبرة لا تقل عن سنتين في الأمن السيبراني، بما في ذلك تنفيذ عمليتين أو أكثر من التحقيقات الجنائية الرقمية.
- على الأقل شهادة جنائية معتمدة من NCSC مثل GCFE أو GCFA أو CHFI أو شهادة مقبولة مماثلة في المجال نفسه معتمدة من NCSC.
- استخدام عملي للأدوات الجنائية وممارسة سليمة في التعامل مع الأدلة.
- يفضل التعرض للتحقيقات الخاصة بالهواتف المحمولة والسحابة.
- يفضل الخبرة في بيئة MSSP أو مختبر أو جهة إنفاذ القانون الجنائي.