Overview

Cyber Forensics and Incident Response | Senior Executive Jobs in Plaines Wilhems District, Mauritius at Deloitte

Title: Cyber Forensics and Incident Response | Senior Executive

Company: Deloitte

Location: Plaines Wilhems District, Mauritius

Summary

We're hunting for a Cyber Digital Forensics profile who can dive into compromised systems, reconstruct attack timelines, and turn raw artifacts into airtight evidence. You'll operate at the intersection of cybercrime investigation and incident response — tracing adversary footprints across endpoints, networks, and cloud infrastructure, and translating technical chaos into evidence that holds up under scrutiny.

What You'll Do

  • Acquire and analyze forensic evidence from compromised endpoints, servers, mobile devices, and cloud environments — without breaking the chain of custody
  • Reconstruct incident timelines from disk images, memory dumps, event logs, and network packet captures
  • Hunt for indicators of compromise (IOCs), lateral movement, persistence mechanisms, and data exfiltration paths
  • Lead investigations into breaches, insider threats, fraud, IP theft, ransomware attacks, and policy violations
  • Act as a core member of the Incident Response (IR) team — from initial detection through containment, eradication, and recovery
  • Perform root-cause analysis (RCA) and post-incident reviews to identify gaps in detection and response
  • Investigate phishing, business email compromise (BEC), and social engineering incidents end-to-end
  • Correlate forensic findings with SIEM alerts, EDR telemetry, and threat intelligence feeds to validate and scope incidents
  • Support threat hunting initiatives by identifying attacker TTPs (Tactics, Techniques, and Procedures) mapped to frameworks like MITRE ATT&CK
  • Develop and refine IR playbooks, forensic SOPs, and detection use cases based on lessons learned
  • Convert technical findings into clear, defensible reports for legal, executive, and law enforcement audiences
  • Reverse basic malware behavior to understand attacker tooling and command-and-control (C2) infrastructure
  • Coordinate with SOC, threat intel, and red/purple team functions to close detection gaps uncovered during investigations
  • Participate in tabletop exercises and IR simulations to stress-test organizational readiness
  • Keep pace with evolving anti-forensic techniques, attacker tradecraft, and next-gen forensic tooling
  • Maintain the integrity of the forensics lab — tools, hardware, and evidence handling protocols
  • Support on-call rotation for after-hours incident response as needed

What You Bring

  • 3–5 years in digital forensics, DFIR, SOC, or a related offensive/defensive security role
  • Battle-tested with forensic platforms: EnCase, FTK, Autopsy, X-Ways, Cellebrite, or Magnet AXIOM
  • Hands-on incident response experience — containment, eradication, recovery, and post-mortem documentation
  • Deep fluency in file systems (NTFS, FAT, HFS+, EXT) and internals of Windows, Linux, and macOS
  • Memory forensics chops (Volatility) and packet-level network analysis (Wireshark, Zeek/Bro)
  • Mobile forensics experience across iOS/Android ecosystems
  • Working knowledge of evidentiary standards — chain of custody, admissibility, legal hold
  • Baseline malware analysis and reverse engineering skills to ID threats without needing a full RE team
  • Familiarity with EDR/XDR platforms (CrowdStrike, SentinelOne, Microsoft Defender, Carbon Black)
  • Understanding of the MITRE ATT&CK framework and its application to threat detection and hunting
  • Solid grasp of ransomware kill chains, C2 infrastructure, and lateral movement techniques
  • Sharp analytical instincts and the discipline to document everything, every time
  • Comfortable being the calm voice in the room during a live incident — and, if needed, in a courtroom

Bonus Points

  • GCFA, GCFE, GCIH, CFCE, EnCE, CHFI, GNFA, or CCE certifications
  • Cloud forensics and incident response experience (AWS, Azure, GCP)
  • Scripting fluency (Python, PowerShell, Bash) to automate detection, triage, and forensic workflows
  • Experience with threat intelligence platforms (MISP, Recorded Future, Anomali)
  • Familiarity with SOAR platforms for automated response orchestration
  • Experience supporting law enforcement, regulatory reporting, or litigation
  • Prior exposure to red team/purple team engagements

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.