Digital Forensics and Incident Response Analyst (Melbourne)

Digital Forensics and Incident Response Analyst (Melbourne)

05 Oct
|
Department of Education Victoria
|
Melbourne

05 Oct

Department of Education Victoria

Melbourne

About the role

The Digital Forensics and Incident Response Analyst role contributes to the overall success of the Security function by providing digital forensics capability and advanced investigations support to respond to incidents impacting the department and schools.

The role is responsible for conducting investigations into cybersecurity incidents, data breaches, insider threats, and other digital crimes. This role involves identification, acquisition, preservation, analysis, and presentation of digital evidence in a legally defensible manner.

The role also provides incident response support and technical advisory in a fast paced, high-volume and complex setting. Using enterprise Digital Forensics and Incident Response (DFIR) tools, methodologies, specialised capability and a sound understanding of legal and regulatory requirements related to digital evidence, the role will setup and maintain a digital forensics lab.

This role requires strong reporting, analytical and problem-solving skills along with technical expertise, and the ability to work collaboratively in teams and to clearly communicate findings to technical and non-technical stakeholders.

Key Responsibilities

- Conduct digital forensic analysis to reconstruct cyberattack timelines and identify attacker techniques.
- Respond to cybersecurity incidents across the full lifecycle: detection, containment, eradication, and recovery.
- Collect and preserve digital evidence while maintaining proper chain of custody.
- Maintain and improve the digital forensics lab and tools.
- Use security tools (e.g., SIEM) and host-based investigations to analyse incidents.
- Perform threat hunting, threat intelligence analysis, and trend forecasting.
- Provide technical remediation recommendations and communicate findings.
- Collaborate with external incident response teams during major incidents.
- Produce technical and executive reports on investigations and threats.
- Support in enhancing the organisation's overall cybersecurity posture.

Skills & Capabilities

Digital Forensics

- Perform forensic analysis across Windows, Linux, macOS, and cloud environments.
- Build attack timelines and investigate attack vectors, malware behaviour, lateral movement, and data exfiltration.




- Capture and analyse network traffic for investigation and decryption.
- Examine disk images, memory dumps, logs, and system artifacts to determine incident details.
- Set up, maintain, and enhance the digital forensics lab.
- Use specialised forensic tools such as EnCase, FTK, Autopsy, X-Ways, Volatility, and KAPE.

Evidence Collection & Preservation

- Acquire and preserve digital evidence (disk, memory, logs, network traffic, cloud artifacts) while maintaining chain of custody, evidence integrity such that the evidence is legally defensible.

- Ensure forensic soundness using proper chain‑of‑custody procedures.
- Capture volatile data (RAM, running processes, network connections) when needed.

Threat Analysis & Investigation

- Perform static and dynamic malware analysis to understand malicious behaviour.
- Investigate security events to assess severity, impact, and required response.
- Conduct threat intelligence, threat hunting, and investigative analysis.
- Correlate alerts and events to detect active or emerging threats.
- Develop detection signatures, automations, and response improvements.
- Identify and integrate Indicators of Compromise (IOCs) into detection systems.
- Track attacker Tactics, Techniques, and Procedures (TTPs) using frameworks such as MITRE ATT&CK.;

Incident Containment & Response

- Proven experience cyber incident response activities in a large, complex environment

- Work with security teams to isolate compromised systems.
- Recommend and implement containment strategies (e.g., blocking IPs, disabling accounts).
- Support eradication efforts such as malware removal or patching.

Documentation & Reporting

- Produce detailed forensic and incident reports for internal stakeholders, legal teams, and law enforcement when required.
- Document attack timelines, investigative findings, and evidence handling processes.




- Prepare situational and executive-level reports on cybersecurity incidents.
- Collaborate with SOC analysts, IT teams, threat intelligence, and management during investigations.
- Provide clear updates during active incidents and translate technical findings into business-friendly language.
- Demonstrate strong stakeholder engagement and communication skills to clearly explain technical issues.

Technical Expertise

- Strong knowledge of attacker tactics, techniques, and procedures (TTPs) using the MITRE ATT&CK; framework, along with familiarity with the NIST Cybersecurity Framework, incident response frameworks, and threat modelling.
- Hands-on experience with digital forensics tools such as EnCase, FTK, Autopsy/The Sleuth Kit, X-Ways, Magnet AXIOM, Volatility, Wireshark, and mobile forensics tools like Cellebrite, GreyKey, and Oxygen.
- Strong knowledge of Windows, Linux, macOS, file systems, network protocols, malware analysis, memory forensics and email forensics.
- Proven ability to monitor, analyse, and correlate security events, alerts, and threat intelligence to identify threats, assess impacts, support investigations, and recommend security improvements.
- Experience working with security platforms including SIEM (Microsoft Sentinel, Splunk), EDR (Microsoft Defender), and ServiceNow.
- Proficient in scripting and automation using Python, Bash, PowerShell, and query languages such as KQL and SPL.

Qualifications & Certifications

- Bachelor's degree or Diploma in Digital Forensics or Cyber Security or a related field
- Minimum 3-4 years demonstrated experience in cyber incident response, digital forensics, or cyber security investigations within a large and complex environment
- Robust knowledge of file systems and operating systems (Windows, macOS, Linux)
- One or more certifications from the "Desirable Certifications" section

Desirable Certifications

- GIAC Certified Forensic Analyst (GCFA)
- EC-Council Computer Hacking Forensic Investigator (CHFI)
- Forensics tools specific vendor certifications
- CEH
- CISSP
- Security+
- SANS Digital Forensics or Incident Response certifications

Applications close 11:59pm on Monday October 19th

📌 Digital Forensics and Incident Response Analyst (Melbourne)
🏢 Department of Education Victoria
📍 Melbourne

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: digital forensics and incident response analyst (melbourne) / melbourne

Subscribe to this job alert:

Get the latest job offers by email for: digital forensics and incident response analyst (melbourne) / melbourne