[6324] DFIR Tool Engineer
Start date: Negotiable
Clearance: NATO Cosmic Top Secret or equivalent
Location: Mons, BE
Skill, Knowledge & Experience:
• At least 5 years of experience in deploying, managing and maintaining forensics and XDR tools in complex environments.
• At least 2 years of experience with remote acquisition tooling (Fidelis and/or F-Response) with demonstrated ability to configure, support deployment at scale including resolving failed collections and performance issues.
• At least 2 years of experience with collaboration tools such as Jira and Confluence;
• Strong understanding of forensically sound acquisition principles (integrity verification, repeatability, minimizing system impact).
• Windows Server/Desktop administration skills: services, drivers, certificates, event logs, permissions, remote management.
• Ability to diagnose host-level issues impacting forensic tools (resource contention, disk I/O, endpoint controls, OS patch impacts).
• Experience with Red Hat Linux and managing a fleet of servers with Ansible.
• Experience working with vendors (support tickets, log bundles, upgrades) and communicating impacts/ETAs to investigators/analysts.
• Experience implementing least-privilege access, credential handling, and audit logging for forensic systems.
• Knowledge and demonstrable experience with scripting languages and integration tools including PowerShell, Python, Bash, Batch and Ansible.
• Good understanding of cyber security concepts.
• Good understanding of network communication protocols.
• Have an in-depth understanding of infrastructure concepts related to Hosting, Networks, IP address Management, firewalls, certificates, Load balancing and Proxy.
• Ability to produce detailed technical documentation and follow change management processes.
• Relevant certifications in cyber security, GIAC (Global Information Assurance Certification) or equivalent.
Desirable Experience:
• Experience in working for or supporting a military or governmental organization.
• Experience in working for or supporting a large company with complex and heterogenous environments.
• Experience in delivering forensics tools support and finding innovative solutions.
• Professional experience in digital forensic analysis;
• Experience with Microsoft Azure, Microsoft Defender for Endpoint.
.png)

