Job Description
Note: The job is a remote job and is open to candidates in USA. Ingram Micro is a leading technology company for the global information technology ecosystem. The Principal Digital Investigator will work within the Security Incident Response Team to assess, analyze, and respond to serious information security events and incidents, requiring expertise in digital forensics and incident response.
- Responsibilities
- Perform forensics on network, host, memory, and other artifacts originating from multiple operating systems, applications, or networks and extract IOCs (Indicators of Compromise) and TTP (Tactics, Techniques, and Procedures)
- Investigate incidents leveraging forensics tools including Encase, FTK, X-Ways, Axiom, SIFT, and the SIEM to determine source of compromises and malicious activity that occurred
- Collect, analyze, assess, and disseminate information about cyber threats and potential attacks
- Conduct human-driven, proactive, and iterative hunts through enterprise networks, endpoints, or datasets to detect malicious, suspicious, or risky activities that have evaded detection by existing tools
- Participate with Security Incident Response Team (SIRT) in responding to active and time-sensitive threats including communications and coordination across different teams
- Maintaining proper chain of custody of evidence and associated documentation
- Testifying in court, Grand Jury, or other legal proceedings through testimony, sworn affidavits, or other legal instruments
- Skills
- Bachelor's degree in computer science, Engineering, Science, Math or Cyber Security related field is required
- Minimum 8 - 10 years functional experience including a minimum of 5+ years directly related to this role in incident response and digital forensics
- 3+ years of strong hands-on experience in digital forensics examinations and/or investigations using the EnCase or AXIOM tools
- 3+ years of experience in law enforcement (deputized) investigations (fraud, counterintelligence, high-tech crimes, etc.)
- 3+ years of experience in interviewing after taking a Reid Technique class (or an equivalent)
- Advanced knowledge and understanding in various disciplines such as security engineering, system and network security, authentication and security protocols, cryptography, and application security
- Experience with cloud services
- Strong understanding of vulnerabilities, common attack vectors and has attacker mindset: ability to think about creative threats and attack vectors
- Strong communication (i.e., written and verbal), presentation, teamwork skills and resourcefulness
- Deep understanding of internals and constructs of modern operating systems. (Windows/MacOS/Linux/Unix)
- Experience with EnCase, FTK, X-Ways, Axiom, SIFT, Splunk, Elastic Stack, Redline, Volatility, WireShark, TCPDump, and open-source forensic tools
- Experience with eDiscovery processes and the Relativity One platform
- Relevant security certifications (EnCE, MCFE, CFCE, CCME, CCO, CCPA, GNFA, GCFA)
- Provide three current work references & pass a criminal background check
- Pass a proficiency exam related to the role
- Preference given for experience conducting MacOS examinations
- Benefits
- Healthcare benefits
- Paid time off
- Parental leave
- A 401(k) plan and company match
- Short-term and long-term disability coverage
- Basic life insurance
- Wellbeing benefits
- Company Overview
- Ingram Micro is a provider of technology products and supply chain management services. It was founded in 1979, and is headquartered in Irvine, California, USA, with a workforce of 10001+ employees. Its website is https://corp.ingrammicro.com.
- Company H1B Sponsorship
- Ingram Micro has a track record of offering H1B sponsorships, with 78 in 2025, 76 in 2024, 51 in 2023, 54 in 2022, 52 in 2021, 50 in 2020. Please note that this does not guarantee sponsorship for this specific role.
Apply tot his job
Apply To this Job