Memory Forensics Analyst - DT #11 - Remote

Compu-Vision - IT

  • Philadelphia, PA
  • 2 days ago
  • Remote

    Highlights

    The role will focus on RAM acquisition and analysis, malicious process identification, code injection detection, memory-resident malware, credential artifacts, and correlation of memory findings with endpoint and network evidence . We are seeking an experienced Memory Forensics Analyst to investigate volatile memory and identify evidence of sophisticated cyberattacks, malware activity, and advanced persistence mechanisms.

    Numbers & Facts

    LocationPhiladelphia, PA (
    Remote
    )

    Description

    Memory Forensics Analyst

    Location: Remote
    Duration: 1–2 Weeks with potential extension

    Position Overview

    We are seeking an experienced Memory Forensics Analyst to investigate volatile memory and identify evidence of sophisticated cyberattacks, malware activity, and advanced persistence mechanisms.

    The role will focus on RAM acquisition and analysis, malicious process identification, code injection detection, memory-resident malware, credential artifacts, and correlation of memory findings with endpoint and network evidence. The ideal candidate will have strong expertise in Windows and Linux memory structures, malware analysis, and incident response.

    Key Responsibilities

    • Acquire and analyze RAM and volatile memory images from compromised systems.
    • Identify suspicious or malicious:
      • Processes
      • Threads
      • DLLs and loaded modules
      • Injected code
      • Network connections
      • Memory-resident artifacts
    • Investigate fileless malware and other memory-resident threats.
    • Identify advanced persistence mechanisms and indicators of compromise.
    • Analyze Windows memory structures and Linux memory artifacts.
    • Investigate credential-related artifacts and suspicious authentication activity within memory.
    • Correlate memory-forensic findings with endpoint and network evidence.
    • Perform malware analysis and support reverse-engineering activities when required.
    • Develop detailed incident timelines based on volatile-memory evidence and other investigative data.
    • Support incident response and threat-hunting activities.
    • Document forensic methodology, evidence, findings, and conclusions.
    • Prepare technical forensic reports and communicate findings to security and incident response teams.

    Key Technical Skills

    Memory Forensics

    • Volatility
    • Rekall
    • Windows memory structures
    • Linux memory analysis
    • RAM acquisition and analysis
    • Process and thread analysis
    • DLL/module analysis
    • Code injection detection
    • Network connection analysis
    • Credential artifact analysis

    Malware & Threat Analysis

    • Malware analysis
    • Fileless malware investigation
    • Reverse engineering
    • Persistence mechanism analysis
    • Indicators of Compromise (IOCs)
    • Advanced attack investigation

    Scripting & Automation

    • Python
    • PowerShell

    Incident Response

    • Incident response
    • Endpoint investigation
    • Network evidence correlation
    • Timeline development
    • Digital evidence analysis and documentation

    Required Qualifications

    • Proven experience in memory forensics, digital forensics, malware analysis, or incident response.
    • Strong hands-on experience analyzing RAM and volatile memory images.
    • Proficiency with Volatility and/or Rekall.
    • Strong understanding of Windows memory structures and processes.
    • Experience with Linux memory analysis.
    • Ability to identify malicious processes, injected code, DLLs, network connections, and other suspicious memory artifacts.
    • Experience investigating fileless malware and advanced persistence techniques.
    • Understanding of malware analysis and reverse-engineering methodologies.
    • Strong Python and/or PowerShell scripting skills.
    • Experience correlating memory evidence with endpoint and network telemetry.
    • Strong analytical, investigative, and technical documentation skills.
    • Ability to work independently in a remote environment.

    Similar Jobs