Senior Digital Forensics and Incident Response Specialist
Company TC Energy
Location Remote Houton, TX / Remote Calgary, AB / Various Remote Locations
Preferred GIAC Certifications GCIA, GCFA, GFXA
Travel 10%
Salary Not provided
Contact Name
Contact Email gabriela_chrisman/at/
Expires 2024-03-07

Job Description

The Opportunity

The Senior Digital Forensics and Incident Response (DFIR) Specialist position reports to the Manager of Cybersecurity Defense & Response. As a Senior DFIR Specialist, you will play a critical role in our cybersecurity team, helping to protect our organization against digital threats and responding to incidents with the highest level of expertise and precision. In collaboration with business partners and teams across Information Systems (IS), you will be responsible for identifying and responding to cyber security incidents, ensuring appropriate threat mitigation, and continuously improving our detection and response capabilities.

Key accountabilities for this role will include: leading and optimizing all aspects of security operations, mentoring other security analysts, and delivering best in class cyber protection for our organization.

This is a fully remote role and can be either Calgary or Houston based.

What You'll Do

Lead and coordinate the incident response team in handling cybersecurity incidents, including data breaches, malware infections, insider threats, and other security breaches.
Conduct comprehensive digital forensics investigations to identify the origin, extent, and impact of security incidents. Ensure all forensic procedures adhere to industry best practices and legal requirements.
Analyze and interpret log data, network traffic, and other sources of information to identify items that can be automated and signs of potential security threats or compromise.
Proactively monitor systems for suspicious activities and take necessary actions to mitigate threats.
Prepare detailed reports on incidents, investigations, and security risks, providing clear and actionable recommendations for improvements.
Collaborate closely with cross-functional teams, including IT, legal, and compliance, to ensure a cohesive approach to incident response and compliance with relevant regulations.
Remain up to date with the latest industry trends, threat landscapes, malware trends, attack techniques, and emerging technologies to continuously enhance your skills and knowledge.
Provide guidance and mentorship to members of the Defense and Response team.
Effectively communicate threat information and system status to leadership and stakeholders.
Participate in projects related to the deployment of IS Cybersecurity operations tools and practices.
Participate in Tabletop exercises related to Incident Response and Business Continuity.
Minimum Qualifications

Completion of a post-secondary educational program in IT Security or Computer Sciences from a recognized community college or university.
Demonstrated pursuit of knowledge through relevant certifications (GCIA, GCFA, GFXA, etc.)
5+ years of Cybersecurity experience.
​Preferred Qualifications

In-depth knowledge and experience in performing forensic investigations, both on-premises and in the cloud, utilizing a wide array of Cybersecurity tools.
Excellent communication and leadership abilities, enabling you to collaborate effectively with diverse teams and guide them through incident response processes.
Demonstrated ability to identify requirements/needs, assess solutions and provide recommendations.
Exceptional problem-solving skills, with the ability to analyze complex challenges and provide innovative solutions.
Experience in organizations that support SCADA networks, pipeline operations, and Industrial Plant Control systems is a plus.