Logo for Reinsurance Group of America, Incorporated

Digital Forensics and Incident Response (DFIR) analyst

Role overview

Qualifications

  • 5+ years in incident response, DFIR, security operations, consulting, or related cybersecurity disciplines.
  • Strong digital forensics capability using industry-standard forensic and triage tools.
  • Experience with Splunk, Microsoft Defender, CrowdStrike Falcon, ServiceNow SIR, and cloud security technologies.
  • Excellent verbal and written communication skills for technical and executive audiences.

Responsibilities

  • Lead enterprise incident response and cyber crisis engagements from detection through recovery.
  • Perform advanced threat hunting and compromise assessments using SIEM, EDR, forensic, and threat intelligence platforms.
  • Develop containment, eradication, and remediation strategies aligned to business risk.
  • Produce executive briefings, technical reports, board-ready updates, and post-incident reviews.

Key facts

Hard skills

Other skills

  • Communication
  • Team Leadership
  • Problem Solving

About the company

Reinsurance Group of America, Incorporated logo

Reinsurance Group of America, Incorporated

Insurance

Reinsurance Group of America, Incorporated (NYSE: RGA) is a global industry leader specializing in life and health reinsurance and financial solutions that help clients effectively manage risk and optimize capital. Founded in 1973, RGA celebrates its 50th anniversary in 2023. Over the past five decades, RGA has become one of the world’s largest and most respected reinsurers and is listed among Fortune's World's Most Admired Companies. The global organization is guided by a fundamental purpose: to make financial protection accessible to all. RGA is widely recognized for superior risk management and underwriting expertise, innovative product design, and dedicated client focus. RGA serves clients and partners in key markets around the world and has approximately $3.4 trillion of life reinsurance in force and assets of $89.1 billion as of March 31, 2023. To learn more about RGA and its businesses, visit www.rgare.com.

Company details

Company typeLarge
IndustryInsurance
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

You desire impactful work.
 

You’re RGA ready

RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all.

About the Role

We are seeking a senior incident response ("DFIR") professional to lead complex cyber investigations, strengthen RGA's enterprise resilience, and guide security teams through critical incidents. This role combines hands-on DFIR expertise, strategic advisory capabilities, stakeholder engagement, and security program leadership across global environments.


Who Thrives in This Role?

You are motivated by investigating sophisticated attacks, improving security operations, and turning lessons learned into measurable improvements. You want to leverage the latest tooling's and methods to "find evil". Always want to help improve tooling's with new ideas. You are comfortable with engaging executives, legal teams, technology leaders, and technical responders during high-pressure situations.


Key Responsibilities

  • Lead enterprise incident response and cyber crisis engagements from detection through recovery.
  • Direct host, network, cloud, identity, and SaaS investigations across Windows, Linux, macOS, Microsoft 365, AWS, Azure, and hybrid environments.
  • Perform advanced threat hunting and compromise assessments using SIEM, EDR, forensic, and threat intelligence platforms.
  • Develop containment, eradication, and remediation strategies aligned to business risk.
  • Produce executive briefings, technical reports, board-ready updates, and post-incident reviews.
  • Partner with legal, compliance, privacy, audit, and external stakeholders when required.
  • Drive adoption of AI-assisted workflows to improve investigation speed, reporting quality, and operational efficiency.
  • Support the 24/7 on-call rotation.

Required Experience and Expertise

  • 5+ years in incident response, DFIR, security operations, consulting, or related cybersecurity disciplines.
  • Experience leading major cyber incidents involving ransomware, business email compromise, insider threats, cloud compromise, supply chain attacks, or advanced persistent threats.
  • Strong digital forensics capability using industry-standard forensic and triage tools.
  • Experience with Splunk, Microsoft Defender, CrowdStrike Falcon, ServiceNow SIR, and cloud security technologies.
  • Knowledge of network protocols, detection engineering, log analytics, and threat hunting methodologies.
  • Excellent verbal and written communication skills for technical and executive audiences.
  • Demonstrated ability to manage multiple priorities in a global enterprise environment.
  • Forensic tools (FTK, Encase, X-Ways, Magnet Axiom, SIFT or other) experience is mandatory.

Leadership Expectations

Provide technical leadership during investigations, influence strategic security decisions, contribute to capability development, and serve as a trusted advisor for cybersecurity risk management and response readiness.


Education and Certifications

  • Industry certifications such as GCFA, GCFE, GCIH, GCIA, CISSP, CISM, Azure Security Engineer, AWS Security Specialty, or comparable credentials are highly desirable (not mandatory)
  • Bachelor's degree in Cybersecurity, Computer Science, Information Security, Engineering, Intelligence Studies, or a related discipline, or equivalent experience is desirable (not mandatory)

Work Environment

Remote or hybrid eligible. Participation in an on-call rotation. Travel is not required as part of the standard day-to-day duties. The role supports global operations and may engage with stakeholders across multiple regions and time zones.


#LI-DM1


What you can expect from RGA:

  • Gain valuable knowledge from and experience with diverse, caring colleagues around the world.

  • Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought.

  • Join the bright and creative minds of RGA, and experience vast, endless career potential.

We’re excited to get to know you and connect your unique skills with our global opportunities. To create a modern and seamless experience, we use artificial intelligence (AI) in parts of our preliminary screening process. This technology helps us personalize job recommendations, automate interview scheduling, evaluate candidates based solely on experience—without considering name, gender, or other personal details—and provide real-time answers through our chatbot. AI is used only during early screening and never makes hiring decisions. Your RGA recruiter will work closely with you every step of the way to ensure the process feels personal, thoughtful, and focused on you.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Incident Response Analyst Related jobs

Other jobs at Reinsurance Group of America, Incorporated

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.