DFIR Analyst (Digital Forensics & Incident Response)

ACE Money Transfer


Date: 5 hours ago
City: Lahore
Contract type: Full time
About Us

ACE Money Transfer is a UK-based multinational company headquartered in Manchester, United Kingdom. The company provides online remittance services to individuals across 29 countries in the UK, Europe, Canada, and Australia, enabling customers to send money securely to more than 100 countries worldwide.

Role Summary

The DFIR Analyst owns the Digital Forensics and Incident Response (DFIR) function at ACE Money Transfer.

This role is responsible for receiving and acknowledging security incidents reported through any channel, triaging and investigating them, performing forensically sound acquisition and analysis of digital evidence, identifying the root cause, attack vector, and business impact, delivering clear remediation recommendations, and defining preventive controls to reduce the likelihood of recurrence.

The role combines the rigor of digital forensics—including evidence preservation, forensic imaging, chain of custody, and deep host, network, and memory analysis—with the fast-paced demands of incident response, including containment, eradication, and recovery. The position operates within ACE's Information Security Management System (ISMS) and supports the organization's dual-jurisdiction regulatory obligations across the UK (FCA and UK GDPR) and Ireland (CBI, DORA, and EU GDPR), with PCI DSS v4.0.1 also within scope. Every investigation must produce a defensible, well-documented outcome capable of withstanding regulatory, legal, and audit scrutiny.

Key Responsibilities

Incident Intake & Triage

  • Monitor and respond to security incidents reported through any channel, including SIEM/SOAR alerts, email, ticketing systems, phishing reports, the service desk, direct escalations, or automated detection tools
  • Acknowledge reported incidents within defined SLA timeframes and accurately record them in the incident or case management system
  • Perform initial triage to classify severity, priority, and scope, and determine whether an event is a false positive, a security event, or a confirmed incident requiring a forensic response

Digital Forensics

  • Perform forensically sound acquisition and preservation of digital evidence across endpoints, servers, mobile devices, cloud environments, network infrastructure, and email systems
  • Create and verify forensic images (disk, memory, and logs) using write blockers and cryptographic hashing to ensure evidence integrity and admissibility
  • Conduct host forensics, including file system, registry, event log, and artifact analysis, as well as memory forensics, network packet analysis, and log analysis to reconstruct attack timelines
  • Perform malware triage and behavioral analysis in a controlled environment to determine malware capabilities, persistence mechanisms, and overall impact
  • Maintain strict chain-of-custody procedures and evidence-handling practices to support forensic, regulatory, and legal requirements

Investigation & Analysis

  • Conduct end-to-end investigations of confirmed security incidents by correlating forensic evidence across SIEM, endpoints, networks, identity platforms, email systems, and cloud telemetry
  • Identify the root cause, initial access vector, affected assets and accounts, attack path, blast radius, lateral movement, data accessed or exfiltrated, and overall business impact
  • Map observed adversary activity to the MITRE ATT&CK framework and enrich indicators of compromise (IOCs) using threat intelligence sources
  • Determine the full scope of compromise and confirm whether personal data or cardholder data has been affected to support regulatory notification decisions

Containment, Eradication & Recovery

  • Execute or coordinate containment activities (such as host isolation, session revocation, credential resets, and blocking actions) within the approved bounded-autonomy framework, escalating for human approval where required
  • Lead or coordinate the eradication of attacker persistence mechanisms, malware, and unauthorized accounts, ensuring the environment is fully remediated
  • Provide clear, practical, and actionable remediation guidance to asset owners, IT teams, and system administrators
  • Verify the effectiveness of remediation efforts, support service restoration, and confirm the return to normal operations before formally closing incidents

Prevention & Continuous Improvement

  • Recommend and support the implementation of preventive controls and detection improvements to reduce the likelihood of recurring incidents
  • Propose new or optimized detection rules, forensic collection methods, incident response playbooks, and automation to strengthen DFIR capabilities
  • Maintain and enhance DFIR runbooks, forensic toolkits, evidence-handling procedures, and the SOC knowledge base
  • Contribute lessons learned during post-incident reviews and drive corrective and preventive actions through to completion

Documentation, Reporting & Compliance

  • Produce accurate incident investigation and forensic reports detailing timelines, root causes, supporting evidence, business impact, actions taken, remediation activities, and preventive recommendations
  • Support regulatory notification requirements (FCA, CBI, UK GDPR, EU GDPR, DORA, and PCI DSS) by providing timely and defensible forensic evidence to the Manager – Cybersecurity
  • Ensure adherence to ACE's Incident Management Procedures, ISMS requirements, and recognized forensic best practices (such as ACPO and NIST SP 800-86) throughout the investigation lifecycle

Required Qualifications & Experience

  • Bachelor's degree in Cybersecurity, Digital Forensics, Computer Science, Information Technology, or a related discipline (or equivalent practical experience)
  • 2–5 years of hands-on experience in Digital Forensics and Incident Response (DFIR), Digital Forensics, or a SOC/Blue Team incident response role
  • Strong understanding of the incident response lifecycle, including preparation, detection, analysis, containment, eradication, recovery, and lessons learned
  • Demonstrated experience with forensic imaging, host, disk, and memory forensics, log analysis, network forensics, and evidence handling
  • Practical experience with SIEM, EDR/XDR platforms, forensic tools, and incident/case management systems
  • Solid understanding of attacker techniques, malware behavior, phishing attacks, and identity-based threats, with familiarity with the MITRE ATT&CK framework

Preferred Qualifications

  • Entry-level or foundational certifications such as CompTIA Security+, CySA+, BTL1, CHFI, or equivalent
  • Basic understanding of digital forensic principles and evidence-handling procedures
  • Familiarity with common SOC and forensic tools used for log analysis and incident investigations
  • Working knowledge of cloud environments, including AWS and Microsoft Entra ID/Microsoft 365
  • General awareness of DORA, FCA, PCI DSS, UK GDPR, and EU GDPR incident reporting and breach notification requirements

Key Competencies

  • Meticulous and methodical approach to evidence handling while maintaining forensic integrity
  • Calm, structured decision-making during high-pressure situations and active security incidents
  • Strong analytical and investigative mindset with exceptional attention to detail
  • Excellent written and verbal communication skills, with the ability to communicate technical findings to both technical and non-technical audiences
  • Strong sense of ownership, accountability, and discipline in following processes, preserving evidence, and meeting service-level agreements
  • Collaborative team player with the ability to work effectively across SOC, IT, Legal, Compliance, Risk, and business stakeholders

Powered by JazzHR

zij1TAiuLG

How to apply

To apply for this job you need to authorize on our website. If you don't have an account yet, please register.

Post a resume

Similar jobs

BESS Design Engineer

Taltra (by KayJay Global Solutions), Lahore
5 hours ago
Role OverviewWe are seeking a talented and detail-oriented BESS Design Engineer to join our Engineering and Energy Storage Solutions team in Lahore. In this role, you will design technically reliable and commercially competitive Battery Energy Storage System solutions for commercial, industrial, utility-scale, renewable-energy, EV-charging, backup-power, and microgrid applications. You will work closely with sales, procurement, project management, and installation teams...

Associate Game Producer

Game District, Lahore
7 hours ago
Location: Lahore, PakistanJob Type: Full-TimeExperience: Fresh - 6 MonthsAbout The RoleWe're looking for a passionate Associate Game Producer who lives and breathes mobile games. This role is ideal for someone who may not have extensive industry experience but has a strong understanding of mobile games, excellent gaming instincts, and a genuine passion for creating great player experiences.If you're the type...

Business Development Manager

Buildmatiq, Lahore
1 day ago
Company DescriptionBuildmatiq is an AI development studio helping SMBs and startups across the US, UK, and Europe replace manual, repetitive work with robust, automated systems. We specialise in end-to-end AI solutions — from initial discovery through production deployment — ensuring tools and workflows are connected and decisions are made faster.Every project is fully custom, built to last, and owned by...