JOB DESCRIPTION:
The Digital Forensic Specialist will work closely with internal investigative partners to support incident response, internal, and external investigations. Responsibilities include forensic collection and analysis and subject matter expertise in the advice, planning, and support for cyber investigations or internal or external fraud investigations.
You, as the Digital Forensics Specialist:
- Part of a team of highly skilled professionals who conduct complex and sensitive investigations, across North America
- Ability to manage assigned digital forensic efforts in support of eDiscovery requests, employee investigations, and IT security incident response, including but not limited, to internal and external intellectual property (IP) theft, attacks/intrusions, computer abuse, and insider threat investigations.
- Possess skills to collect, process, preserve and analyze data from electronic data sources, including laptop and desktop computers, servers, and mobile devices, per company policies and practices.
- Proficiency in investigations on the EnCase platform, industry-standard tools, and practices applying technical and functional skills.
- Works with Cyber Security Operations, Insider Threat Management Investigations, Legal, Human Resources, Privacy, Risk, and external law enforcement, as necessary, to forensically collect and analyze digital evidence and conduct cyber investigations.
- Researches, evaluates, develops, tests, and applies new methodologies for analyzing digital evidence to reduce the risk of exposure to TD Bank
- Supports / develops procedures and standards and delivers advice, direction and education to TD management and staff.
KEY ACCOUNTABILITIES
- Lead digital evidence / cybercrime investigations
- Collect evidence from computers, laptops, phones, iPads, databases and a variety of other devices/systems capable of storing valuable electronic data.
- Applies sound methodologies to collect, preserve, and analyze digital evidence.
- Maintain a digital forensic lab environment by ensuring all hardware and software are verified and validated as forensically sound.
- Focus on operational efficiency to ensure the Forensic Investigations & Digital Evidence team is leveraging tools and processes that reduce redundancy and improve capacity.
- Stays up to date on the emerging technology threat landscape.
- Respond to internal business units to investigate simple or complex, sensitive, or urgent matters, usually within minimal timeframes.
- Assist in managing the team’s computer forensic lab and network infrastructure.
- Prepares written professional reports.
- Testify and present evidence, as required.
REQUIRED QUALIFICATIONS
- Understanding of digital forensic principles, methodologies, and techniques; including experience using digital forensic tools (i.e., EnCase, Axiom, e-Discovery tools, Cellebrite, Intella, Crowdstrike, Splunk)
- Understanding of the principles of investigation, including reporting, evidence handling, chain of custody, and court or regulatory proceedings
- Ability to interpret digital evidence matters in a way understandable to business and non-technical people.
- Knowledge of Data Loss Prevention tools and conducting DLP related investigations.
- Knowledge of Microsoft Purview Mailbox collection and review.
- Excellent written and verbal communication, presentation, organization, leadership, and planning skills
- Demonstrated ability to manage crisis and emergency incidents.
- Self-starter, strategic thinker, negotiator and consensus builder, proven ability to satisfactorily manage competing priorities.
- Understanding of organizational priorities and relationships
- Solid understanding of governing plans and documents, procedures, and business administration
- Understanding of operating systems (Windows, Linux and OSX)
- Knowledge of malware triage and reverse engineering an asset
- Knowledge of network-based services and client/server applications
- Knowledge of enterprise systems and infrastructure
EDUCATION AND EXPERIENCE:
- University degree or college diploma from a recognized Institute of Technology or University program in an appropriate specialty such as Computer Science, or a related field
- Professional designation / certification in the following would be an asset: EnCE (Encase Certified Examiner); Certified Information Systems Security Professional (CISSP), Certified Cyber Forensics Professional (CCFP), Certified Information Security Manager (CISM), and SANS Global Information Assurance Certification (GIAC)
- Minimum of 5 years of relevant experience conducting computer forensic investigations to include investigations in a corporate network environment.
- Experience with programming/scripting languages an asset.
- Experience in identifying gaps in the existing process and proposing and implementing solutions.
- Background in operational information security disciplines (e.g., incident response, security infrastructure management or monitoring services)
- Familiarity with forensic lab network architecture and security infrastructure placement
- Familiarity with security tools such as Anti-Virus, Ironport systems and Data Loss Prevention tools
- 5 years experience in cyber forensics, incident response, digital forensic investigations, and/or information security role a plus.
- Handles conflict effectively, by overcoming differences of opinion and finding common ground.
- Ability to follow through on leads until all possible avenues in investigating a case have been exhausted.
- Ability to evaluate data and courses of action to reach logical, pragmatic decisions.
WHO WE ARE:
TD is one of the world’s leading global financial institutions and is the fifth largest bank in North America by branches/stores. Every day, we deliver legendary customer experiences to over 27 million households and businesses in Canada, the United States and around the world. More than 95,000 TD colleagues bring their skills, talent, and creativity to the Bank, those we serve, and the economies we support. We are guided by our vision to Be the Better Bank and our purpose to enrich the lives of our customers, communities and colleagues.
TD is deeply committed to being a leader in customer experience, that is why we believe that all colleagues, no matter where they work, are customer facing. As we build our business and deliver on our strategy, we are innovating to enhance the customer experience and build capabilities to shape the future of banking. Whether you’ve got years of banking experience or are just starting your career in financial services, we can help you realize your potential. Through regular leadership and development conversations to mentorship and training programs, we’re here to support you towards your goals. As an organization, we keep growing – and so will you.