Key Responsibilities:
Management
- Lead end-to-end DFIR investigations for major incidents, coordinating across internal and external stakeholders.
- Own and refine investigation playbooks, escalation paths, and response workflows aligned with industry frameworks (NIST, SANS).
- Coach and mentor other investigations staff, driving technical skill development and case quality.
- Lead post-incident reviews and tabletop exercises to improve response maturity.
- Ensure all investigative activities comply with legal, regulatory, and internal policy requirements.
Technical
- Conduct forensic acquisition and analysis across endpoints, servers, networks, and cloud (AWS, Azure, M365).
- Perform memory analysis, disk forensics, log correlation, and malware reverse engineering to support incident containment, eradication, and recovery.
- Reconstruct attack chains, identify root cause, and assess lateral movement by correlating SIEM, EDR/XDR, packet captures, and threat intelligence sources.
- Maintain chain-of-custody and evidentiary standards for legal and regulatory needs.
- Document investigations with clear timelines, evidence, and technical conclusions.
Organizational
- Act as the primary point of contact for high-severity investigations, providing timely updates to leadership.
- Work closely with Legal, HR, Compliance, and IT on internal and sensitive cases.
- Deliver investigation reports and briefings tailored to technical and executive audiences.
- Support audits, regulatory reviews, and law enforcement with evidence and documentation.
- Strengthen partnerships with MSSPs, threat intel vendors, and forensic service providers.
Your Skills and Expertise
To set you up for success in this role from day one, 3M requires (at a minimum) the following qualifications:
- Bachelor’s degree in Cybersecurity, Digital Forensics, Information Technology or Computer Science (completed and verified prior to start)
- Six (6) or more years of experience in cybersecurity investigations, digital forensics, or incident response in a private, public, government or military environment
- One or more certifications involving incident response, cyber security (GCIH, E CEH, E CIH), or network forensics (GIAC Network Forensic Analyst (GNFA), NICCS Certified Network Forensics Examiner (CNFE)
Additional qualifications that could help you succeed even further in this role include:
- Strong investigative mindset with experience leading complex cyber investigations
- Proficient in digital forensics tools and techniques across Windows, Linux, and cloud environments
- Familiar with legal and regulatory considerations related to evidence handling and privacy
- Effective communicator with the ability to present findings to executive and legal audiences
- Collaborative and discreet, with a high degree of integrity and professionalism
- Strong analytical and critical thinking skills with attention to detail
- Experience in manufacturing or industrial environments is a plus
- Drives continuous process improvement
- Demonstrates excellent analytical and problem-solving skills
- Demonstrates and encourages innovative thinking, continuous learning and sharing of best practices
- Demonstrated knowledge of Incident Response and Investigative Methodology.
- Prior experience serving as an expert witness in legal proceedings.
- Demonstrate advanced proficiency in utilizing common digital forensic artifacts and tools such as ELK, Axiom, Encase, FTK (Forensic Toolkit), Open-Source, or comparable industry-standard tools.
- Familiarity with compliance frameworks such as NIST, ISO 27001, and industry-specific regulations.
- Highest level of integrity and management of confidential information.
Please note: your application may not be considered if you do not provide your education and work history, either by: 1) uploading a resume, or 2) entering the information into the application fields directly.
Please access the linked document by clicking select the country where you are applying for employment, and review. Before submitting your application, you will be asked to confirm your agreement with the terms.