Digital Forensics Response Automation Analyst (DFIR Automation Analyst)

Requisition ID:  289405

  • Relocation Authorized:  None
  • Telework Type: Full-Time Telework 
  • Work Location: Glendale, AZ
  • Salary Range: $109,190 - $166,510 annually (Determined by function, education, experience, and qualifications of the applicant.)

 

Extraordinary teams building inspiring projects:

Since 1898, we have helped customers complete more than 25,000 projects in 160 countries on all seven continents that have created jobs, grown economies, improved the resiliency of the world's infrastructure, increased access to energy, resources, and vital services, and made the world a safer, cleaner place. 

Differentiated by the quality of our people and our relentless drive to deliver the most successful outcomes, we align our capabilities to our customers' objectives to create a lasting positive impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals, and the Manufacturing and Technology markets. Our services span from initial planning and investment, through start-up and operations. 

Core to Bechtel is our Vision, Values and Commitments. They are what we believe, what customers can expect, and how we deliver. Learn more about our extraordinary teams building inspiring projects in our Impact Report

Job Summary:

As a DFIR Automation Analyst, you will design and implement automation solutions that enhance core incident response capabilities. Leveraging both commercial and open-source forensic tools, you will streamline investigative workflows and improve response efficiency. You will also participate in our Incident Command pool and will lead incident response efforts as needed. This role requires close collaboration across technical and business teams to refine processes and foster a secure-by-design culture. Strong communication skills are essential, as you’ll engage with stakeholders at all levels—translating complex technical concepts into clear, actionable insights.

Major Responsibilities:

  • Design, implement, and continuously improve our incident response capabilities and modernize Bechtel’s computer forensics operations.
  • Assist efforts to modernize our digital forensics tooling and collection processes while leveraging SOAR, Cloud infrastructure, and CI/CD pipelines.
  • Develop and maintain scripts, playbooks, and integrations for forensic data collection, analysis, and reporting.
  • Conduct forensic investigations across cloud (e.g., AWS, Azure, GCP, SaaS, PaaS, and IaaS) and on-premise environments to identify, preserve, and analyze evidence
  • Collaborate with security operations, IT, and engineering teams to identify automation opportunities and implement scalable solutions.
  • Lead and prioritize incident response command staff efforts across the enterprise, including providing forensic analysis support and/or serving as incident commander.
  • Utilize your expert communication skills to produce greater awareness of goals, projects, and tasks amongst customers and stakeholders.
  • Participate in post-incident reviews and help implement lessons learned into automation strategies.

Education and Experience Requirements:

  • Bachelor's Degree in Information Technology, Computer Science, or a related field or 8 years equivalent experience (in lieu of degree).
  • Must be a United States citizen.

Required Knowledge and Skills:

  • 5 or more years of general information technology experience with at least 2 of those years in the area of digital forensics or incident response.
  • Familiarity with SOAR (Security Orchestration, Automation, and Response) software with an emphasis on building complex playbooks for automating routine incidents.
  • Familiarity with Incident Response in cloud/hybrid environments (AWS, Azure, GCP, etc).
  • Demonstrated experience with Gitops, CI/CD, and infrastructure as code (IaC) solutions.
  • Demonstrated knowledge of Windows, Mac, and Linux operating systems.
  • Strong working knowledge of Python, PowerShell, or similar scripting languages.
  • Skilled in SIEM/XDR/EDR platforms (e.g., Splunk, Sentinel, CrowdStrike) including log analysis, correlation, and detection tuning.
  • Solid experience applying all facets of digital forensics and incident response to on-prem and cloud environments.
  • Proven ability to manage yourself, prioritize tasks, and produce high-quality results in a fast-paced environment.
  • Able to work across team boundaries, reach consensus amongst disparate viewpoints, and graciously receive feedback.
  • Strong analytical, documentation, and communication skills.

Total Rewards/Benefits:

For decades, Bechtel has worked to inspire the next generation of employees and beyond! Because our teams face some of the world's toughest challenges, we offer robust benefits to ensure our people thrive.  Whether it is advancing careers, delivering programs to enhance our culture, or providing time to recharge, Bechtel has the benefits to build a legacy of sustainable growth. Learn more at Bechtel Total Rewards

Diverse teams build the extraordinary:

As a global company, Bechtel has long been home to a vibrant multitude of nationalities, cultures, ethnicities, and life experiences. This diversity has made us a more trusted partner, more effective problem solvers and innovators, and a more attractive destination for leading talent.

We are committed to being a company where every colleague feels that they belong-where colleagues feel part of "One Team," respected and rewarded for what they bring, supported in pursuing their goals, invested in our values and purpose, and treated equitably. Click here to learn more about the people who power our legacy.

 

At Bechtel, our employees enjoy a competitive total rewards package that includes comprehensive medical, dental, and vision plans, along with optional disability and supplemental insurance options, generous paid time off (160 hours annually, accrued 6.16 hours per pay period), nine paid holidays, paid parental leave, discretionary bonuses, and a well-designed 401K plan with matching and profit-sharing components

Bechtel is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity and expression, age, national origin, disability, citizenship status (except as authorized by law), protected veteran status, genetic information, and any other characteristic protected by federal, state or local law. Applicants with a disability, who require a reasonable accommodation for any part of the application or hiring process, may e-mail their request to acesstmt@bechtel.com