Cyber Investigator [ insider threat, data loss prevention, digital forensics ] – Senior Analyst
AIGAbout the role
Cyber Investigator [ insider threat, data loss prevention, digital forensics ] – Senior Analyst
The Cyber Investigator provides expert-level contributions to AIG’s Information Security Office by protecting the company’s critical assets from internal threats and reducing overall risk. This senior level position will be looked upon as a subject matter expert (SME) in the fields of digital forensics, insider threat, and cyber investigations.
Position Responsibilities:
- Perform highly sensitive and confidential investigations, including digital forensic analysis, involving internal risks such as employee misconduct, intellectual property theft, embezzlement, misuse, harassment, and physical security threats.
- Lead proactive efforts to identify, disrupt, and protect AIG from any internal threats that may undermine the integrity and operations of the business.
- Conduct forensic analysis of physical devices and other electronic data sources in support of internal investigations and other legal requests using forensically sound processes.
- Provide subject matter guidance and work collaboratively with incident response and other cyber security teams in the event of a cross-functional investigation.
- Drive continuous improvement across the cyber investigations group and its processes.
- Utilize a range of data sources, systems, and tools to collect, search, recover, sort, and organize large volumes of digital evidence during all phases of the investigative process.
- Collect and preserve electronically stored evidence and digital media using repeatable and defensible procedures, ensuring chain of custody throughout the evidence lifecycle.
- Deliver clear and meaningful results and associated reporting to requestors of various levels across the organization.
- Maintain awareness of new forensic technology, techniques, and industry best practices.
- Mentor junior level security professionals and periodically perform quality review of their work.
- Assist team leadership with the development, collection, and publication of metrics that illustrate team performance and highlight obstacles thwarting team potential.
Requirements (Knowledge, Skills, and Abilities):
- Minimum of 7 years experience in computer forensics, investigations, or similar information security discipline leading digital investigations following legally sound practices (including chain of custody).
- Working knowledge and proven experience with current digital forensic best practices and methodologies.
- Demonstrated expertise in both working in and handling extremely confidential investigations.
- Experience with forensic technologies such as EnCase, AXIOM, and Cellebrite.
- Experience with emerging cloud technology services and their effect on digital investigations.
- Good understanding of possible methods of internal and external data movement.
- Ability to navigate a complex global network as part of the investigative research process.
- Familiarity with processes and technologies for collections from mobile device platforms.
- Strong understanding of enterprise email systems including Office 365 and MS Exchange.
- Experience with enterprise level SIEM and DLP tools such as Splunk, McAfee, and Symantec.
Personal Attributes:
- Self-starter with a sense of urgency who takes ownership and responsibility for service delivery.
- Works independently with minimal guidance while also working collaboratively with the team to achieve strategic goals.
- Professional, clear, and concise communication to both technical and non-technical audiences.
- Excellent analytical ability, sharp attention to detail, creative problem solving, and consultative skills.
- Proven organizational skills (time management and prioritization).
- Position requires access to highly sensitive confidential material; integrity and discretion are mandatory.
Formal Education & Certification
- Bachelor of Science in Computer Science, Information Systems, Software Engineering, Criminal Justice, or any combination of education and relevant experience.
Preferred Certifications:
- EnCase Certified Examiner – EnCE
- GIAC Certified Forensic Analyst – GCFA
- GIAC Certified Forensic Examiner – GCFE
- Certified Forensic Computer Examiner – CFCE
- Certified Information Systems Security Professional – CISSP
** NOTE: An equivalent combination of experience, education and/or training may be substituted for the listed minimum requirements.
Occasional travel may be required, but less than 10% of the time.
Enjoy benefits th
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s