Faster chat, better deals — Get the App

Digital Forensics & Incident Response Expert

Indeed

Company

Job typeFull-time
Workplace typeOnsite
Experience levelNo experience limit
Education levelNo degree limit

Description

Summary: Investigate, detect, respond to, and prevent cybersecurity incidents affecting digital advertising platforms, AdTech, and associated infrastructure. Highlights: 1. Lead complex investigations in digital forensics and incident response. 2. Specialize in AdTech security, fraud detection, and threat hunting. 3. Collaborate across teams to enhance cybersecurity and prevent attacks. The **Advertising Digital Forensics \& Incident Response Expert** is responsible for investigating, detecting, responding to, and preventing cybersecurity incidents affecting digital advertising platforms, advertising technology (AdTech), customer data, websites, mobile applications, advertising accounts, and associated technology infrastructure. The role combines **digital forensics, incident response, threat hunting, cybersecurity investigation, AdTech security, fraud detection, and evidence preservation** to identify the source, scope, impact, and root cause of security incidents and advertising\-related attacks. The successful candidate will work closely with Cybersecurity, SOC, IT, Digital Marketing, Ad Operations, Legal, Compliance, Privacy, and external security partners to ensure rapid containment and effective recovery from incidents. **Key Responsibilities** **1\. Digital Forensics \& Investigation** * Conduct forensic investigations involving compromised advertising platforms, websites, servers, endpoints, cloud environments, applications, and user accounts. * Collect, preserve, analyze, and document digital evidence in accordance with forensic best practices. * Analyze system logs, authentication records, network traffic, browser artifacts, endpoint data, cloud logs, application logs, and database activity. * Determine the attack vector, timeline, affected systems, attacker activities, and business impact. * Perform malware and suspicious\-code analysis when required. * Develop detailed forensic timelines and investigation reports. * Maintain proper chain of custody for evidence where required for legal, regulatory, or disciplinary proceedings. **2\. Incident Response** * Lead or support investigations into cybersecurity incidents involving advertising and digital media environments. * Detect, triage, contain, eradicate, and recover from security incidents. * Investigate account takeover, credential compromise, malicious advertising, website defacement, malware infection, data leakage, unauthorized campaign changes, and fraudulent advertising activity. * Coordinate incident response activities across technical and business teams. * Develop and execute incident response playbooks and procedures. * Conduct post\-incident reviews and identify corrective and preventive actions. **3\. Advertising \& AdTech Security** * Investigate attacks targeting advertising platforms, ad servers, DSPs, SSPs, DMPs, CDPs, analytics platforms, social media advertising accounts, and related technologies. * Analyze suspicious advertising campaigns, unauthorized account activity, malicious redirects, malvertising, click fraud, bot activity, and advertising\-platform abuse. * Investigate unauthorized modifications to campaigns, targeting, budgets, creatives, tracking codes, pixels, tags, and conversion mechanisms. * Identify security weaknesses within digital advertising workflows and third\-party integrations. * Work with advertising and marketing teams to improve security controls without unnecessarily disrupting campaign operations. **4\. Threat Hunting \& Detection** * Perform proactive threat hunting across endpoints, networks, cloud infrastructure, applications, and advertising environments. * Develop indicators of compromise (IOCs), indicators of attack (IOAs), detection rules, and threat\-hunting hypotheses. * Analyze threat intelligence relevant to AdTech, digital marketing, credential theft, account takeover, malware, phishing, and fraud. * Identify emerging attack techniques and recommend appropriate defensive measures. * Support the development and tuning of SIEM, EDR/XDR, SOAR, IDS/IPS, WAF, and other security detections. **5\. Security Monitoring \& Analysis** * Analyze security alerts and correlate information from multiple security and advertising systems. * Investigate anomalous login behavior, geographic anomalies, unusual campaign activity, privilege escalation, suspicious API calls, and abnormal traffic patterns. * Establish baselines for normal advertising\-platform behavior and identify deviations. * Support SOC analysts with advanced investigations and escalation handling. **6\. Cloud, Application \& Network Forensics** * Conduct forensic analysis across cloud environments such as AWS, Microsoft Azure, or Google Cloud. * Investigate compromised web applications, APIs, databases, containers, virtual machines, and cloud identities. * Analyze network traffic, DNS activity, proxy logs, firewall logs, VPN logs, and authentication events. * Investigate security incidents involving SaaS platforms and third\-party advertising technologies. **7\. Fraud \& Abuse Investigation** * Investigate advertising fraud, bot activity, click fraud, impression fraud, fake conversions, account abuse, and suspicious traffic. * Correlate cybersecurity indicators with advertising performance and campaign data. * Identify patterns associated with automated attacks, fraudulent accounts, botnets, and coordinated abuse. * Work with fraud, analytics, and advertising teams to distinguish legitimate activity from malicious activity. **8\. Reporting \& Stakeholder Management** * Prepare executive\-level and technical incident reports. * Present investigation findings, root causes, risks, and recommendations to management. * Provide evidence\-based recommendations for improving security controls. * Support Legal, Compliance, Privacy, Risk, and Audit teams during security investigations. * Communicate complex forensic findings clearly to both technical and non\-technical stakeholders. **Required QualificationsEducation** * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Digital Forensics, Information Security, or a related field. * Master's degree or specialized forensic/security education is an advantage. **Professional Experience** * **5\+ years of experience** in cybersecurity, digital forensics, incident response, SOC, threat hunting, or related disciplines. * Demonstrated experience conducting complex cybersecurity investigations. * Experience investigating compromised accounts, endpoints, servers, cloud environments, websites, or applications. * Experience with digital advertising, AdTech, marketing technology, or online fraud is highly desirable. Technical Skills strong knowledge of: * Digital forensics and incident response (DFIR) * Incident response lifecycle and forensic investigation methodologies * Windows and Linux forensics * Network and web application forensics * Cloud security and cloud forensics * Identity and access management * SIEM, SOAR, EDR/XDR, IDS/IPS, WAF, and security monitoring technologies * Threat intelligence and threat hunting * Malware and suspicious\-file analysis * Log analysis and event correlation * Network traffic analysis * DNS, HTTP/HTTPS, TCP/IP, VPN, proxy, and firewall technologies * Web applications, APIs, databases, and authentication mechanisms * Digital advertising platforms and AdTech ecosystems * Advertising fraud and bot detection * Python, PowerShell, Bash, or other scripting languages * Evidence collection and preservation * Security incident documentation and reporting **Key Competencies** * Strong analytical and investigative mindset * Excellent problem\-solving and critical\-thinking skills * Ability to work effectively under pressure during security incidents * Strong attention to detail * Ability to correlate large volumes of technical information * Excellent written and verbal communication * Strong documentation and report\-writing skills * Ability to work with confidential and sensitive information * Ability to collaborate with technical and business stakeholders * Strong understanding of cybersecurity risk and business impact * Ability to independently lead complex investigations Work Location: In person

Source: indeed

Posted by

Fatima Al-Kuwari

Indeed · HR

Location

Fatima Al-Kuwari

Indeed · HR

Similar jobs

Digital Forensics & Incident Response Expert job by Indeed in 2026 | ok.com