Digital Forensics Expert
Il y a 2 jours
Brussels, Brussels-Capital, Belgique
AGAD Technology
Temps plein
Gratuit avec email ou Google
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
Gratuit avec email ou Google
We are looking for an experienced Digital Forensics & Incident Response professional to build and lead an enterprise-wide forensic readiness capability at out client in the Banking sector located in Brussels.
This is a strategic role focused on defining how digital evidence is acquired, managed and leveraged during cyber incidents. You will work across security, infrastructure, legal and business teams to ensure the organisation can respond effectively to major incidents and make informed containment and recovery decisions.
Key Responsibilities
Strategy and readiness. You will define forensic readiness standards, assess current maturity levels, identify evidence gaps and drive continuous improvement initiatives across the organisation. Operating model and partners. You will establish the target operating model, clarify roles and responsibilities, and manage relationships with external DFIR providers, including supplier selection, retainers, SLAs and mobilisation processes. Architecture and tooling. You will shape the tooling and architecture required for secure evidence acquisition, transfer, analysis and storage, covering forensic workstations, acquisition kits and software licensing. Runbooks and evidence handling. You will develop investigation playbooks and chain-of-custody procedures across identity, endpoint, network and cloud environments, ensuring investigations are conducted in a consistent and defensible manner. Exercises and assurance. You will lead tabletop exercises, acquisition testing and end-to-end incident simulations, while tracking KPIs and driving remediation actions to improve readiness. Requirements Enterprise DFIR experience. You have significant experience in cyber security with responsibilities spanning digital forensics, incident response or forensic readiness activities. Capability building. You have a proven track record of building, improving or governing DFIR capabilities, operating models, investigation processes or related security services. Technical foundation. You possess a solid understanding of Windows and Linux environments, endpoint, network, identity and cloud evidence sources, as well as familiarity with SIEM and EDR technologies. Forensic tooling. You are familiar with tools such as EnCase, FTK, Magnet AXIOM, Velociraptor, KAPE or Volatility. Partner and stakeholder leadership. You are comfortable working across security, infrastructure, legal, privacy and crisis management functions, while also managing external partners and forensic providers. You are fluent in Dutch. Certifications. Certifications such as GCFA, GCFE, GCIH, EnCE, CCE or CISSP are considered an asset. You have a solid foundation in digital forensics and are comfortable working independently while taking ownership of initiatives. You are a proactive self-starter who knows how to create structure, set direction and engage a broad range of stakeholders. This role is less focused on deep hands-on forensic investigations and more focused on strategy, governance, capability development and stakeholder alignment. You will define the vision, establish the right frameworks and ensure the organisation is prepared to respond effectively when incidents occur.
Key Responsibilities
Strategy and readiness. You will define forensic readiness standards, assess current maturity levels, identify evidence gaps and drive continuous improvement initiatives across the organisation. Operating model and partners. You will establish the target operating model, clarify roles and responsibilities, and manage relationships with external DFIR providers, including supplier selection, retainers, SLAs and mobilisation processes. Architecture and tooling. You will shape the tooling and architecture required for secure evidence acquisition, transfer, analysis and storage, covering forensic workstations, acquisition kits and software licensing. Runbooks and evidence handling. You will develop investigation playbooks and chain-of-custody procedures across identity, endpoint, network and cloud environments, ensuring investigations are conducted in a consistent and defensible manner. Exercises and assurance. You will lead tabletop exercises, acquisition testing and end-to-end incident simulations, while tracking KPIs and driving remediation actions to improve readiness. Requirements Enterprise DFIR experience. You have significant experience in cyber security with responsibilities spanning digital forensics, incident response or forensic readiness activities. Capability building. You have a proven track record of building, improving or governing DFIR capabilities, operating models, investigation processes or related security services. Technical foundation. You possess a solid understanding of Windows and Linux environments, endpoint, network, identity and cloud evidence sources, as well as familiarity with SIEM and EDR technologies. Forensic tooling. You are familiar with tools such as EnCase, FTK, Magnet AXIOM, Velociraptor, KAPE or Volatility. Partner and stakeholder leadership. You are comfortable working across security, infrastructure, legal, privacy and crisis management functions, while also managing external partners and forensic providers. You are fluent in Dutch. Certifications. Certifications such as GCFA, GCFE, GCIH, EnCE, CCE or CISSP are considered an asset. You have a solid foundation in digital forensics and are comfortable working independently while taking ownership of initiatives. You are a proactive self-starter who knows how to create structure, set direction and engage a broad range of stakeholders. This role is less focused on deep hands-on forensic investigations and more focused on strategy, governance, capability development and stakeholder alignment. You will define the vision, establish the right frameworks and ensure the organisation is prepared to respond effectively when incidents occur.