View All Jobs 127641

Digital Forensic Specialist - Forensics & Ediscovery Services, Insider Threat Management

Own and expand the digital forensics investigations program across the regional teams
Singapore
Senior
2 days ago
TD Bank

TD Bank

Provides a wide range of retail, commercial, and investment banking services across North America and internationally.

Digital Forensic Specialist

The Digital Forensic Specialist will work closely with internal investigative partners to support incident response, internal, and external investigations. Responsibilities include forensic collection and analysis and subject matter expertise in advice, planning, and support for cyber investigations or internal or external fraud investigations.

Part of a team of highly skilled professionals who conduct complex and sensitive investigations, across North America and Singapore.

Ability to manage assigned digital forensic efforts in support of eDiscovery requests, employee investigations, and security incident response, including but not limited, to internal and external intellectual property (IP) theft, attacks/intrusions, computer abuse, and insider threat investigations.

Possess skills to collect, process, preserve and analyze data from electronic data sources, including laptop and desktop computers, servers, and mobile devices, per company policies and practices.

Proficiency in investigations using a variety of Digital Forensic tools including EnCase, Magnet Axiom, Intella, MS Purview and practices applying technical and functional skills.

Works with Cyber Security Operations, Insider Threat Management Investigations, Legal, Human Resources, Privacy, Risk, and external law enforcement, as necessary, to forensically collect and analyze digital evidence and conduct cyber investigations.

Research, evaluates, develops, evaluates, and applies new methodologies for analyzing digital evidence to reduce the risk of exposure to TD Bank.

Supports / develops procedures and standards and delivers advice, direction and education to TD management and staff.

Lead digital evidence / cybercrime investigations by applying forensically sound methodologies to collect, preserve, and analyze digital evidence.

Collect evidence from computers, laptops, phones, iPads, databases, and a variety of other devices/systems capable of storing valuable electronic data.

Focus on operational efficiency to ensure the Forensic Investigations & Digital Evidence team is leveraging tools and processes that reduce redundancy and improve capacity.

Stays up to date on the emerging technology threat landscape.

Respond to internal business units including HR, Legal, Investigations and others to investigate simple or complex, sensitive, or urgent matters, usually within Operational Target Agreement.

Assist in managing the team's computer forensic lab and network infrastructure.

Prepare written professional reports including testifying and presenting evidence, as required.

Understanding of digital forensic principles, methodologies, and techniques; including experience using various tools i.e., EnCase, Magnet Axiom, Cellebrite, Intella, MS Purview, Crowdstrike, and Splunk.

Understanding of the principles of investigation, including reporting, evidence handling, chain of custody, and court or regulatory proceedings.

Minimum of 5 years of relevant experience conducting computer forensic investigations to include investigations in a corporate network environment.

Solid understanding of governing plans and documents, procedures, and business administration.

Ability to investigate and interpret digital evidence matters in a way understandable to business and non-technical people.

Conducting DLP related investigations including data collection and review from DLP tools.

Conducting data collection and investigation of Emails, MS Teams chat messages, and Sharepoint using Microsoft Purview.

Excellent written and verbal communication, presentation, organization, leadership, and planning skills.

Demonstrated ability to manage crisis and emergency incidents.

Self-starter, strategic thinker, negotiator and consensus builder, proven ability to satisfactorily manage competing priorities.

Understanding of organizational priorities and relationships.

Understanding of operating systems (Windows, Linux and OSX).

Knowledge of enterprise systems and infrastructure, malware triage, network-based services, client/server applications and reverse engineering an asset.

Experience with programming/scripting languages an asset.

Experience in identifying gaps in the existing process and proposing and implementing solutions.

Background in operational information security disciplines (e.g., incident response, security infrastructure management or monitoring services).

Familiarity with forensic lab network architecture and security infrastructure placement.

Familiarity with security tools such as Anti-Virus, Ironport systems and Data Loss Prevention tools.

Handles conflict effectively, by overcoming differences of opinion and finding common ground.

Ability to follow through on leads until all possible avenues in investigating a case have been exhausted.

Ability to evaluate data and courses of action to reach logical, pragmatic decisions.

University degree or college diploma from a recognized Institute of Technology or University program in an appropriate specialty such as Computer Science, or a related field.

Professional designation / certification in the following would be an asset: EnCE (Encase Certified Examiner); Certified Information Systems Security Professional (CISSP), Certified Cyber Forensics Professional (CCFP), Certified Information Security Manager (CISM), and SANS Global Information Assurance Certification (GIAC).

+ Show Original Job Post
























Digital Forensic Specialist - Forensics & Ediscovery Services, Insider Threat Management
Singapore
Human Resources
About TD Bank
Provides a wide range of retail, commercial, and investment banking services across North America and internationally.