Job DescriptionJob Title: Digital Forensics AnalystWorking Pattern: Fulltime - hybridWorking location: Indianapolis, INRelocation assistance will be provided if applicableWhy Rolls-Royce?At Rolls-Royce we are proud to be a business that has truly helped to shape the modern world and are committed to always being a force for progress; powering, protecting and connecting people everywhere.By joining Rolls-Royce, you’ll have the opportunity to create world-class power and propulsion solutions, pushing your problem-solving and ingenuity, to deliver real impact that puts safety first.You’ll be given responsibility and the opportunity to grow in our high-performance culture. This is Infinite Potential. And it’s your chance to really shine and contribute to one of the world’s most recognized brands and a beacon for engineering excellence.Position Summary:We are seeking a highly motivated DFIR Specialist to join our Purple Team. This role bridges offensive and defensive security operations by combining incident response, threat hunting, digital forensics, adversary emulation, and detection engineering.The ideal candidate enjoys investigating real-world attacks, understanding adversary behavior, improving detection capabilities, and working collaboratively with red and blue teams to strengthen security posture.What you will be doing:Incident ResponseLead or support investigations involving malware, ransomware, insider threats, and advanced persistent threats.Perform endpoint, memory, disk, and cloud forensics.Conduct triage activities during security incidents.Coordinate containment, eradication, and recovery efforts.Develop incident response playbooks and procedures.Produce executive and technical incident reports.Threat HuntingConduct proactive hunts across endpoints, identity, cloud, and network telemetry.Develop hypotheses based on emerging adversary techniques.Analyze attack patterns using frameworks such as MITRE ATT&CK.Identify gaps in visibility and logging.Purple Team OperationsCollaborate with red team operators to emulate adversary tactics.Validate detections against simulated attacks.Assist in planning and executing purple team exercises.Measure and improve detection coverage.Map detections and hunting content to ATT&CK techniques.Detection EngineeringDevelop and tune detections within SIEM and EDR platforms.Reduce false positives while improving fidelity.Create custom analytics, dashboards, and monitoring content.Automate repetitive investigation tasks through scripting.ForensicsAcquire and analyze forensic artifacts from:Windows systemsLinux systemsCloud environmentsContainersIdentity providersPerform timeline reconstruction.Analyze persistence mechanisms.Basic Qualifications:Associate's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Mathematics and 2 + years of relevant experience OR;Master's degree in Cybersecurity, Computer Science, Information Technology, Mathematics OR;PhD in Cybersecurity, Computer Science, Information Technology, Mathematics OR;In lieu of a degree must have 6+ years' experience in Cyber Security or Information TechnologyMust be a US CitizenPreferred Qualifications:3+ years focused on incident response, threat hunting, or DFIR.6+ years' experience in Cyber Security or Information TechnologyExperience with various memory acquisition techniques/tools:FTK ImagerVolatility 3Velociraptor for remote memory dumpsExperience with enterprise SIEM platforms such as:Microsoft SentinelSplunk Enterprise SecurityElastic SecurityExperience with EDR technologies including:Microsoft Defender XDRCrowdStrike FalconSentinelOne SingularityFamiliarity with:Windows Event LogsSysmonKQLSigma rulesYARAPowerShellPythonMemory analysisMalware triageUnderstanding of:Attack chainsIdentity-based attacksCloud attack techniquesDetection engineering principlesExperience with adversary emulation frameworks.Familiarity with:CalderaPrelude OperatorVelociraptorTheHiveCloud security investigation experience in:Microsoft AzureAmazon AWSGoogle CloudCertifications:GIAC certifications such as GCFA, GCIH, GCFE, etc.Microsoft certifications such as SC-200, SC-400, AZ-500CISSP, CCSPOur vision is to ensure that the quality and dynamism that shaped our history continues into our future. It’s a bold pursuit, and we never stop striving to go further, faster, and better. We lead progress, creating the technologies that move us forward. If you’re driven to grow, to learn, and to make a lasting difference, this is where you belong.Rolls-Royce is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to any protected characteristics. We are committed to providing a respectful and non-discriminatory workplace where individuality is valued and everyone can thrive.Infinite Potential#CLOLI#CLOPROFJob CategoryInformation TechnologyJob Posting Date04 Sept 2026; 00:09Pay RangePay ranges for remote employees are based on the state where the employee resides and may vary from the posted range.$98,566-$160,169-AnnuallyLocation:Indianapolis, INBenefitsRolls-Royce provides a comprehensive and competitive Total Rewards package that includes base pay and a discretionary bonus plan. Eligible employees may have the opportunity to enroll in other benefits, including health, dental, vision, disability, life and accidental death & dismemberment insurance; a flexible spending account; a health savings account; a 401(k) retirement savings plan with a company match; Employee Assistance Program; Paid Time Off; certain paid holidays; paid parental and family care leave; tuition reimbursement; and a long-term incentive plan. The options available to an employee may vary depending on eligibility factors such as date of hire, employment type, and the applicability of collective bargaining agreements.SummaryLocation: IndianapolisType: Full time
...Rep-Lite in Salt Lake City, UT is seeking an Associate Sales Representative to kickstart a medical device sales career. You will partner with experienced Territory Managers, build physician relationships, support clinical customers, and grow business within your assigned...
...Description Job Summary We are seeking an experienced Neonatal Nurse Practitioner to join our Level III NICU team in Shreveport, LA . This position offers the opportunity to work alongside a highly collaborative group of neonatal providers dedicated to delivering...
...Roamarae Global Travel is looking for motivated individuals to join as Remote Travel Agents. In this role, you will assist clients in planning and booking vacations, including cruises and customized travel experiences.This flexible, work-from-home opportunity is ideal...
...Remote Travel Consultant Hotels & Resorts Specialist Location: Remote We are expanding! We're looking for a Remote Travel Consultant Hotels & Resorts Specialist who loves helping others plan incredible vacations. Work from home, set your hours, and build...
...GCP Cloud Architect Job Location: Edison NJ (Onsite) Duration: Full Time Required Technical Skill Set: Google Professional Cloud Architect Certified and/or Google Professional Data Engineer Certified. Good knowledge on Cloud foundation concepts Should have good...