Senior Incident Response & Digital Forensics Analyst

USD 190,000-260,000 per year
SENIOR
✅ On-site

Tech Stack

AI @ 4 AWS Azure Communication @ 7 Compliance GCP Git Jira Linux @ 7 Mentoring @ 4 Networking @ 7 Python @ 6 Security @ 4 Splunk @ 7 macOS @ 7

Details

Bloomberg’s Cyber Security Operations Center (CSOC) protects the organization by identifying, investigating, and responding to cyber threats. The team works with Engineering, Legal, Compliance, and other groups to provide security monitoring, incident response, threat hunting, and forensic expertise across a complex global technology environment.

As part of the Threat Hunting, Intelligence & Incident Response (THIR) team, this role leads the technical investigation of complex security incidents and escalations. The analyst investigates ambiguous events by analyzing host, memory, network, and log evidence; acquiring and examining forensic images; investigating suspicious binaries; and reconstructing attacker activity to determine what happened, how it happened, and the extent of the impact.

During significant incidents, the analyst establishes ground truth, maintains technical ownership of investigations, and works with stakeholders across Bloomberg to support effective response. The role also includes mentoring team members, developing playbooks and procedures, sharing knowledge, and strengthening capabilities in malware analysis, memory forensics, and log-based threat hunting.

The analyst will contribute to forensic tooling, workflows, investigative standards, repeatable processes, and durable detection coverage based on lessons learned from incidents.

Responsibilities

  • Lead security incident investigations from initial signal through root-cause analysis and written conclusion.
  • Analyze host, memory, network, and log evidence.
  • Acquire and examine forensic images across Windows and Linux environments.
  • Investigate suspicious binaries using static and dynamic analysis, safe detonation, and extraction of observables for detection and threat hunting.
  • Reconstruct attacker activity and determine incident scope and impact.
  • Use endpoint and network telemetry to identify attacker behavior and locate additional evidence.
  • Investigate large datasets with Splunk or comparable enterprise search and log-analysis platforms.
  • Support significant incidents and maintain technical ownership of investigations.
  • Mentor colleagues through incident pairing, playbooks, procedures, documentation, and structured knowledge sharing.
  • Contribute to forensic tooling, workflows, investigative standards, and detection coverage.
  • Work with detection engineering teams to translate investigative findings into sustainable detection capabilities.
  • Collaborate with Engineering, Legal, Compliance, and other stakeholders.

Requirements

  • Substantial hands-on experience leading end-to-end security incident investigations.
  • Strong practical experience with disk and memory forensics across Windows and Linux, including evidence acquisition and analysis.
  • Demonstrated malware analysis experience, including static and dynamic analysis, safe detonation, and extraction of useful observables.
  • Strong knowledge of operating-system internals across Windows, Linux, and macOS.
  • Strong understanding of networking fundamentals, including TCP/IP, DNS, routing, and network evidence analysis.
  • Deep hands-on experience investigating large datasets with Splunk or a comparable enterprise search and log-analysis platform.
  • Experience using endpoint and network telemetry to determine attacker behavior.
  • Programming or scripting capability in any language; Python is commonly used within the team.
  • Ability to independently investigate difficult and unfamiliar problems and determine when to involve others.
  • Strong written and verbal communication skills.

Beneficial Experience

  • Memory-forensics frameworks such as Volatility and structured forensic acquisition tooling.
  • Reverse engineering beyond behavioral malware analysis.
  • Cloud forensics across AWS, Azure, or GCP, including snapshot-based acquisition and investigation.
  • Threat hunting and knowledge of attacker tools, techniques, and procedures used against enterprise environments.
  • CrowdStrike Falcon, particularly Real Time Response (RTR).
  • Humio, LogScale, or other large-scale log-analysis platforms.
  • Endpoint telemetry and EDR technologies such as osquery, Sysmon, Carbon Black, or Tanium.
  • Network security monitoring technologies such as Zeek, Suricata, Snort, NetWitness, packet capture, or network IDS.
  • Git, Jira, Jupyter notebooks, or similar development and collaboration tools.
  • Certifications such as GCFA, GCFE, GREM, or GNFA.
  • Experience applying mainstream commercial AI platforms to security or analytical workflows.

Collaboration and Work Environment

The team is globally distributed across New York, EMEA, and APAC and operates a follow-the-sun model, allowing investigations and operational work to transition between regions. The role is shift-oriented, and significant incidents may occasionally require support outside standard working hours. The team works together globally to manage incident response.

Bloomberg is an equal opportunities employer and values diversity, collaboration, curiosity, teamwork, and high standards.

Benefits

Benefits may include merit increases, incentive compensation for exempt roles, paid holidays, paid time off, medical, dental and vision coverage, short- and long-term disability benefits, a 401(k) match, life insurance, and wellness programs. Benefits are not provided directly to contingent workers, contractors, or interns.

More jobs at Bloomberg

Similar jobs