Triskele Labs Logo

Triskele Labs

Digital Forensics Analyst

Posted 20 Days Ago
Be an Early Applicant
In-Office
Melbourne, Victoria, AUS
Junior
In-Office
Melbourne, Victoria, AUS
Junior
Investigate cyber incidents including ransomware, business email compromise, insider threats, unauthorized access, data theft, and endpoint compromise. Acquire and analyze evidence forensically, maintain chain of custody, identify intrusion methods and threat actor activity, assess data access, and produce defensible reports for clients, insurers, and legal counsel. Support reactive investigations and proactive forensic readiness work, collaborate with incident response practitioners, and participate in out-of-hours work when required.
The summary above was generated by AI

Triskele Labs is an Australian cyber security firm delivering Managed Detection and Response, Governance Risk and Compliance, Penetration Testing, and Digital Forensics and Incident Response. We hold CREST Cyber Security Incident Response (CSIR) accreditation.

The Digital Forensics Team

We investigate cyber incidents for clients across Australia, remotely and on site. We establish how an intrusion occurred, what the Threat Actor did, and whether data was accessed or taken. Every matter is backed by a written report that stands up to review by the client, their insurer and their legal counsel.

Work arrives from two directions. Reactive matters are referred by cyber insurers, brokers and legal panel firms, and move at pace. Proactive work is delivered to retainer clients, covering forensic readiness and response planning.

We investigate ransomware and data extortion, business email compromise, insider threat, unauthorised access, data theft, funds redirection, website and endpoint compromise, and internal investigations.

You will work alongside a highly technical and seasoned group of digital forensics practitioners. Everyone carries live matters. Digital Forensics sits alongside Incident Response within the wider DFIR practice.


Requirements

Experience and Skills

  • Minimum one year of experience in a digital forensics role.
  • Understanding of the incident lifecycle.
  • Sound understanding of Windows and Linux forensic artefacts.
  • Exposure to Microsoft 365 investigation is advantageous.
  • Experience acquiring and handling evidence in a forensically sound manner, including chain of custody.
  • Familiarity with Threat Actor tactics, techniques and procedures.
  • Business-fluent written English.
  • Eligibility to work in Australia.

Tools

Experience with the following tools is relevant to the role:

  • Forensic suites such as Magnet Axiom, X-Ways Forensics, and Intella are advantageous.
  • Experience with acquisition, triage, and analysis tools such as KAPE, EZ Tools, Hayabusa, Velociraptor, Chainsaw, and Volatility.
  • Experience investigating Microsoft 365 and Entra ID environments, including the Unified Audit Log, sign-in and audit logs, mailbox rules, delegate access, and OAuth application grants, is advantageous.
  • Experience with EDR and SIEM tools such as SentinelOne, CrowdStrike, Microsoft Defender, Carbon Black, Microsoft Sentinel, Elastic, and Rapid7 is advantageous.

Training and Certifications

SANS and GIAC certifications are a significant bonus, in particular GCFE, GCFA, GCFR and GCIH. Vendor training in Magnet Axiom, X-Ways or Intella is also valued.

Two courses are mandatory for every member of the team: 13Cubed Investigating Windows Endpoints and 13Cubed Investigating Linux Endpoints. If you do not hold these, Triskele Labs will fund and enrol you.

Hours, On-Call and Overtime

Participation in the on-call rotation is voluntary.

You will work out of hours as matters require, particularly in the opening days of a ransomware or major incident matter. Out of hours work is paid as overtime.


Benefits
  • Join a supportive and driven team where each team member is valued.
  • Collaborative and growth-oriented culture with opportunities for career development.
  • Hybrid working environment, with some in-office presence expected
  • Salary packaging, novated leasing available
  • Access to Triskele Labs Discounts and Benefits Platform
  • Ongoing training opportunities

Why Triskele Labs?

Triskele Labs is a place where passion for cybersecurity and client success thrive. Our commitment to "Deliver Awesome" drives us to exceed expectations, making a tangible difference in our clients’ security journey.

Application Process

Applications without a cover letter will be immediately disqualified. Address your cover letter to Richard Grainger, Global Head of Digital Forensics. Tell us about why you are ideal for this role.

HQ

Triskele Labs Melbourne, Victoria, AUS Office

Melbourne, Australia

Similar Jobs

7 Minutes Ago
Remote or Hybrid
5 Locations
Mid level
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Provides technical support for CrowdStrike customers globally, with a focus on Korean-speaking enterprise customers in the Asia-Pacific region. Responsibilities include troubleshooting application and operating-system issues, identifying root causes, resolving escalations, collaborating with engineering and product teams, creating knowledge articles, and supporting customers across scheduled shifts and holidays. The role requires strong bilingual communication, technical debugging expertise, customer focus, and familiarity with cybersecurity, cloud, identity, SIEM, or related technologies.
Top Skills: Active DirectoryAi TechnologiesCassandraContainersCrowdstrike FalconDockerElasticsearchHttpsJSONKafkaKerberosKubernetesLdapLinuxmacOSMultifactor AuthenticationNtlmPcapRegular ExpressionsRest ApisSaaSSAMLSplunkTcp/IpWindowsWiresharkZero Trust
13 Hours Ago
In-Office
Junior
Junior
Food • Retail • Agriculture • Manufacturing
Provides hands-on, site-based HR support at McCain’s Ballarat plant across employee relations, labour relations, recruitment, onboarding, employee lifecycle activities, leave administration, engagement, wellbeing, retention, and HR systems adoption. Partners with leaders, employees, Talent Acquisition, HR Business Partners, and service delivery teams while supporting compliance, employee experience, and culture initiatives.
Top Skills: Hr Self-Service ToolsHr Systems
20 Hours Ago
Remote or Hybrid
Melbourne, Victoria, AUS
Entry level
Entry level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Support alliance managers, solution providers, and managed service partners across Australia by delivering cybersecurity enablement, technical training, demonstrations, proof-of-concept guidance, accreditation support, and opportunity assistance. Build trusted partner relationships, promote CrowdStrike’s cloud-native security platform, improve partner technical independence, support joint sales initiatives, and identify professional services opportunities. The role requires security architecture knowledge, strong communication, consulting or sales engineering capability, AI technology experience, and travel to partner locations.
Top Skills: Ai TechnologiesAnti-VirusAPIsAWSAzureBashCehCisspCloud Security ArchitectureComputer ForensicsCrowdstrikeData ProtectionEndpoint SecurityGCPIdentity ProtectionIncident ResponseMdr/XdrOscpPowershellPythonSansSIEMZero-Trust

What you need to know about the Melbourne Tech Scene

Home to 650 biotech companies, 10 major research institutes and nine universities, Melbourne is among one of the top cities for biotech. In fact, some of the greatest medical advancements were conceptualized and developed here, including Symex Lab's "lab-on-a-chip" solution that monitors hormones to predict ovulation for conception, and Denteric's vaccine for periodontal gum disease. Yet, the thousands of people working in the city's healthtech sector are just getting started, to say nothing of the tech advancements across all other sectors.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account