Cyber Investigator [ insider threat, data loss prevention, digital forensics ] – Senior Analyst
AIGAbout the role
Cyber Investigator [ insider threat, data loss prevention, digital forensics ] – Senior Analyst
The Cyber Investigator provides expert-level contributions to AIG’s Information Security Office by protecting the company’s critical assets from internal threats and reducing overall risk. This senior level position will be looked upon as a subject matter expert (SME) in the fields of digital forensics, insider threat, and cyber investigations.
Position Responsibilities:
Perform highly sensitive and confidential investigations, including digital forensic analysis, involving internal risks such as employee misconduct, intellectual property theft, embezzlement, misuse, harassment, and physical security threats.
Lead proactive efforts to identify, disrupt, and protect AIG from any internal threats that may undermine the integrity and operations of the business.
Conduct forensic analysis of physical devices and other electronic data sources in support of internal investigations and other legal requests using forensically sound processes.
Provide subject matter guidance and work collaboratively with incident response and other cyber security teams in the event of a cross-functional investigation.
Drive continuous improvement across the cyber investigations group and its processes.
Utilize a range of data sources, systems, and tools to collect, search, recover, sort, and organize large volumes of digital evidence during all phases of the investigative process.
Collect and preserve electronically stored evidence and digital media using repeatable and defensible procedures, ensuring chain of custody throughout the evidence lifecycle.
Deliver clear and meaningful results and associated reporting to requestors of various levels across the organization.
Maintain awareness of new forensic technology, techniques, and industry best practices.
Mentor junior level security professionals and periodically perform quality review of their work.
Assist team leadership with the development, collection, and publication of metrics that illustrate team performance and highlight obstacles thwarting team potential.
Requirements (Knowledge, Skills, and Abilities):
Minimum of 7 years experience in computer forensics, investigations, or similar information security discipline leading digital investigations following legally sound practices (including chain of custody).
Working knowledge and proven experience with current digital forensic best practices and methodologies.
Demonstrated expertise in both working in and handling extremely confidential investigations.
Experience with forensic technologies such as EnCase, AXIOM, and Cellebrite.
Experience with emerging cloud technology services and their effect on digital investigations.
Good understanding of possible methods of internal and external data movement.
Ability to navigate a complex global network as part of the investigative research process.
Familiarity with processes and technologies for collections from mobile device platforms.
Strong understanding of enterprise email systems including Office 365 and MS Exchange.
Experience with enterprise level SIEM and DLP tools such as Splunk, McAfee, and Symantec.
Personal Attributes:
Self-starter with a sense of urgency who takes ownership and responsibility for service delivery.
Works independently with minimal guidance while also working collaboratively with the team to achieve strategic goals.
Professional, clear, and concise communication to both technical and non-technical audiences.
Excellent analytical ability, sharp attention to detail, creative problem solving, and consultative skills.
Proven organizational skills (time management and prioritization).
Position requires access to highly sensitive confidential material; integrity and discretion are mandatory.
Formal Education & Certification
Bachelor of Science in Computer Science, Information Systems, Software Engineering, Criminal Justice, or any combination of education and relevant experience.
Preferred Certifications:
EnCase Certified Examiner – EnCE
GIAC Certified Forensic Analyst – GCFA
GIAC Certified Forensic Examiner – GCFE
Certified Forensic Computer Examiner – CFCE
Certified Information Systems Security Professional – CISSP
** NOT
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s