We are seeking a motivated CSIRT Specialist with expertise in Digital Forensics and Incident Handling to join our team of cybersecurity professionals. In this role, you will assist organizations in responding to and mitigating security incidents through host forensics, log
Suivant analysis, and incident response preparation. Additionally, you will contribute to the development of detection use cases, improve our in-house CSIRT tools, and participate in workshops or training sessions to share knowledge and expertise.
Whether you are an experienced professional or at the early stages of your cybersecurity career, this position offers an excellent opportunity to grow within the field of incident response and cyber defense.
Key Responsibilities
Incident handling and response:
Conduct host forensics and analyze system logs to support incident response engagements.
Assist customers in preparing for potential security incidents by implementing effective processes.
Leverage Ttps (Tactics, Techniques, and Procedures) gained from engagements to improve detection mechanisms.
Occasionally participate in purple team engagements to validate detection use cases.
Tool development and maintenance: Develop and maintain in-house CSIRT tools and applications for more efficient incident handling.
Knowledge sharing and training:
Conduct training sessions or workshops with customers or peers to share knowledge about incident handling.
Present research or work at security conventions to contribute to the broader cybersecurity community.
Requirements
Extensive experience in Incident Response.
Deep understanding of networks (HTTP2/Quic, Dot/Doh, etc.) and operating system internals.
Proficient in tools like Volatility, Log2timeline, WireShark, Tshark, Snort, MISP, IntelMQ.
Skilled in debugging Python 3 code (and occasionally Python 2).
Experience with threat intelligence—understanding its capabilities and limitations.
Ability to work under pressure and maintain composure with stressed stakeholders.
Mentorship skills to support and share knowledge with less experienced team members.
Strong writing and reporting capabilities.
Languages: French and English mandatory