Just postedUrgently hiring Use left and right arrow keys to navigate

About this job

Job Description

Job Description
Memory Forensics Analyst

Location: Remote
Duration: 1–2 Weeks with potential extension

Position Overview

We are seeking an experienced Memory Forensics Analyst to investigate volatile memory and identify evidence of sophisticated cyberattacks, malware activity, and advanced persistence mechanisms.

The role will focus on RAM acquisition and analysis, malicious process identification, code injection detection, memory-resident malware, credential artifacts, and correlation of memory findings with endpoint and network evidence. The ideal candidate will have strong expertise in Windows and Linux memory structures, malware analysis, and incident response.

Key Responsibilities
  • Acquire and analyze RAM and volatile memory images from compromised systems.
  • Identify suspicious or malicious:
    • Processes
    • Threads
    • DLLs and loaded modules
    • Injected code
    • Network connections
    • Memory-resident artifacts
  • Investigate fileless malware and other memory-resident threats.
  • Identify advanced persistence mechanisms and indicators of compromise.
  • Analyze Windows memory structures and Linux memory artifacts.
  • Investigate credential-related artifacts and suspicious authentication activity within memory.
  • Correlate memory-forensic findings with endpoint and network evidence.
  • Perform malware analysis and support reverse-engineering activities when required.
  • Develop detailed incident timelines based on volatile-memory evidence and other investigative data.
  • Support incident response and threat-hunting activities.
  • Document forensic methodology, evidence, findings, and conclusions.
  • Prepare technical forensic reports and communicate findings to security and incident response teams.
Key Technical Skills Memory Forensics
  • Volatility
  • Rekall
  • Windows memory structures
  • Linux memory analysis
  • RAM acquisition and analysis
  • Process and thread analysis
  • DLL/module analysis
  • Code injection detection
  • Network connection analysis
  • Credential artifact analysis
Malware & Threat Analysis
  • Malware analysis
  • Fileless malware investigation
  • Reverse engineering
  • Persistence mechanism analysis
  • Indicators of Compromise (IOCs)
  • Advanced attack investigation
Scripting & Automation
  • Python
  • PowerShell
Incident Response
  • Incident response
  • Endpoint investigation
  • Network evidence correlation
  • Timeline development
  • Digital evidence analysis and documentation
Required Qualifications
  • Proven experience in memory forensics, digital forensics, malware analysis, or incident response.
  • Strong hands-on experience analyzing RAM and volatile memory images.
  • Proficiency with Volatility and/or Rekall.
  • Strong understanding of Windows memory structures and processes.
  • Experience with Linux memory analysis.
  • Ability to identify malicious processes, injected code, DLLs, network connections, and other suspicious memory artifacts.
  • Experience investigating fileless malware and advanced persistence techniques.
  • Understanding of malware analysis and reverse-engineering methodologies.
  • Strong Python and/or PowerShell scripting skills.
  • Experience correlating memory evidence with endpoint and network telemetry.
  • Strong analytical, investigative, and technical documentation skills.
  • Ability to work independently in a remote environment.

Nearby locations

Posting ID: 1297156909 Posted: 2026-09-16 Job Title: Memory Forensic Analyst