Digital Forensics Analyst
Rolls-Royce
Indianapolis, IN
The Role
The analyst leads and supports incident response investigations covering malware, ransomware, and APTs, while conducting endpoint, memory, disk, and cloud forensics. Responsibilities also include proactive threat hunting, adversary emulation via purple team exercises, and developing and tuning detections within SIEM and EDR platforms.
Skills & Experience
Candidates should have experience with tools such as Volatility 3, FTK Imager, Velociraptor, Microsoft Sentinel, Splunk, CrowdStrike Falcon, and Microsoft Defender XDR. Familiarity with KQL, Sigma rules, YARA, PowerShell, Python, and the MITRE ATT&CK framework is strongly preferred alongside memory analysis and malware triage skills.
Who It Suits
This role suits an experienced DFIR professional who thrives working across red and blue team boundaries, enjoys investigating real-world attacks, and wants to build detection and forensic capabilities within a large, globally recognised engineering organisation. US citizenship is required.
Typical advertised salary for Incident Response roles in United States: $125,000–$180,000 (median $150,000 — from 154 recent listings analysed by Forensic Focus).
Learn More/Apply





