1

Digital Forensic Analyst Jobs in Quebec (NOW HIRING)

Cybersecurity Director

Quebec, QC · On-site +1

CA$138K - CA$173K/yr

  • Retirement

Incident Response and Digital Forensics: Lead investigations into security incidents, perform forensic analyses, and oversee incident response activities. Coordinate with legal counsel, law ...

Conduct forensic analysis and threat hunting using Microsoft Purview and Azure security tools. * Incident Response & Threat Mitigation: Lead incident response efforts by identifying, containing, and ...

GRC Lead/Security Analyst (Montreal - Canada) Founded in 2000, Ivalua is a leading global provider ... digital transformation revolutionizes supply chain sustainability and resiliency to unlock the ...

Security Analyst - CTEM Transformation

Quebec, QC · On-site

$90 - $130/hr

  • Retirement

  • PTO

As a Security Analyst - CTEM Transformation, you will play a key role in the implementation and evolution of iA's Cyber Threat Exposure Management (CTEM) program. You will help identify, prioritize ...

next page

Showing results 1-20

Digital Forensic Analyst information

See Quebec salary details

$31K

$88.1K

$196K

How much do digital forensic analyst jobs pay per year?

As of Aug 19, 2026, the average yearly pay for digital forensic analyst in Quebec is $88,079.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,500.00 and $105,500.00 per year, depending on experience, location, and employer.

What does a digital forensic analyst do?

A Digital Forensic Analyst is responsible for identifying, collecting, analyzing, and preserving digital evidence from computers, mobile devices, and other digital storage media. Their work is crucial in criminal investigations, cybersecurity incidents, and legal cases, as they help uncover evidence of cybercrimes, data breaches, or unauthorized data access. Digital Forensic Analysts use specialized tools and methodologies to ensure that digital evidence remains intact and admissible in court. They also prepare detailed reports and may testify as expert witnesses. Their role is vital in both law enforcement and the private sector.

What does a digital forensic analyst do?

A digital forensic analyst retrieves and analyzes evidence from computer data and digital devices. In this career, you work with law enforcement to establish facts and dates found in data from personal computers, company records, cell phones, and deleted files. Other duties include searching for clues, motives, and patterns within the dates that can become evidence. You may also work with equipment that can recover and back up memory files, while preventing original content from being altered. You analyze files, metadata, and networks with specialty software.

What are the key skills and qualifications needed to thrive as a digital forensic analyst?

To thrive as a Digital Forensic Analyst, you need a solid understanding of computer systems, networks, cybersecurity principles, and a relevant degree or certifications like GCFA or EnCE. Familiarity with forensic tools such as EnCase, FTK, X-Ways, and SIEM systems is typically required. Strong analytical thinking, attention to detail, and effective written communication set outstanding analysts apart. These skills are crucial for accurately investigating cyber incidents, preserving evidence integrity, and presenting findings clearly to stakeholders or in legal proceedings.

What are some common challenges digital forensic analysts face when handling evidence, and how are these addressed in the workplace?

Digital Forensic Analysts often encounter challenges such as maintaining the integrity of digital evidence, dealing with encrypted or damaged data, and keeping up with rapidly evolving technologies. To address these, analysts follow strict chain-of-custody protocols, use specialized forensic tools to recover and analyze data, and participate in ongoing training to stay current on new threats and techniques. Collaborative teamwork and clear communication with law enforcement, legal teams, and IT professionals are also essential to ensure thorough and legally sound investigations.

What is the difference between Digital Forensic Analyst vs Cybersecurity Analyst?

AspectDigital Forensic AnalystCybersecurity Analyst
CertificationsEnCE, GCFA, CISSP (optional)CISSP, CEH, Security+
Work EnvironmentInvestigations, law enforcement, legal settingsNetwork security, threat monitoring, incident response
Industry UsageLegal cases, criminal investigations, complianceCorporate security, IT departments, threat prevention

While both roles involve protecting digital assets, Digital Forensic Analysts focus on investigating cybercrimes and gathering digital evidence, often working in legal or law enforcement settings. Cybersecurity Analysts primarily work to prevent attacks, monitor networks, and respond to security incidents within organizations. Understanding these differences helps clarify career paths and employer expectations.

How do you become a digital forensic analyst?

To become a digital forensic analyst, individuals typically need a bachelor's degree in computer science, cybersecurity, or a related field. Gaining experience with digital investigation tools, such as EnCase or FTK, and obtaining certifications like the Certified Computer Forensics Examiner (CCFE) or GIAC Certified Forensic Analyst (GCFA) can enhance job prospects. Strong analytical skills, attention to detail, and knowledge of legal procedures are also important for success in this role.

How much money does a digital forensic analyst make?

A digital forensic analyst's salary varies based on experience, location, and certifications, but typically ranges from $60,000 to $120,000 annually. Entry-level analysts may earn around $60,000, while experienced professionals with specialized skills can earn over $100,000.

Is digital forensics well paid?

Digital Forensic Analysts typically earn competitive salaries that vary by experience, location, and employer. Entry-level positions may start around $50,000 annually, while experienced analysts with certifications and specialized skills can earn over $100,000 per year. The role often requires knowledge of forensic tools, cybersecurity, and legal procedures, which can influence compensation levels.

What are popular job titles related to Digital Forensic Analyst jobs in Quebec?

For Digital Forensic Analyst jobs in Quebec, the most frequently searched job titles are:

What job categories do people searching Digital Forensic Analyst jobs in Quebec look for?

The top searched job categories for Digital Forensic Analyst jobs in Quebec are:

What are popular job titles related to Digital Forensic Analyst jobs in QC?

For Digital Forensic Analyst jobs in QC, the most frequently searched job titles are:

Infographic showing various Digital Forensic Analyst job openings in Quebec as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $88,079 per year, or $42.3 per hour.

Senior Specialist, Incident Response | Specialiste principal, Reponse aux incidents

SITA Switzerland Sarl

Montreal, QC • On-site

Full-time

Posted 16 days ago


Job description

Overview

WELCOME TO SITA  

At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry.

You’ll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We don’t just move the world forward, we’re proud to be recognized as a Great Place to Work® by our employees and certified in most of our growing locations.

Here, we feel empowered, supported, and inspired to grow.

Are you ready to love your job? The adventure begins right here, with you, at SITA.

ABOUT THE ROLE & TEAM

 

As a Digital Forensics & Incident Response (DFIR) Specialist, you will play a key role in investigating cybersecurity incidents, performing digital forensic analysis, and supporting the containment and remediation of security threats across SITA's global environment. You will work closely with Security Operations, CSIRT Threat, Cloud & Infrastructure, Product Security, and Corporate IT teams to respond to threats, preserve evidence, and determine the root cause and impact of security incidents.

As part of SITA's Enterprise Information Security Office (EISO) and CSIRT Response Team, you will help strengthen the organization's incident response capabilities, forensic readiness, and cyber resilience while supporting the protection of SITA, its customers, and the broader air transport ecosystem.

This role is ideal for a proactive hands-on security professional with strong investigation and analytical skills who is passionate about incident response, digital forensics, and continuous improvement.

 

WHAT YOU WILL DO

  • Incident Response & Coordination
    • Investigate and manage cybersecurity incidents throughout the full incident response lifecycle, from analysis and containment to recovery and post-incident review.
    • Collaborate with SOC, CSIRT, IT, Cloud, Infrastructure, and Engineering teams to coordinate effective incident response activities and drive remediation efforts.
    • Produce incident reports and technical findings while continuously enhancing response processes, playbooks, and operational procedures.
  • Digital Forensics & Evidence Handling
    • Conduct digital forensic investigations across endpoints, servers, cloud, network, and SaaS environments, including evidence collection, preservation, analysis, and reporting.
    • Analyze forensic artifacts to identify attacker activity, determine root causes, assess business impact, and support investigations into malware, ransomware, account compromise, and data breaches.
    • Maintain robust evidence handling and documentation practices in alignment with legal, regulatory, and industry standards
  • Insider Threat & Risk
  • Support investigations involving insider threats, policy violations, privileged access misuse, and potential data loss incidents, while providing technical evidence and findings to Legal, Compliance, HR, and other stakeholders.
  • Identify and recommend security control improvements to mitigate insider threat risks and strengthen the organization's overall security posture.
  • operational processes across enterprise environments.
  • Tooling, Automation & Telemetry
    • Develop and maintain automation, scripts, and tools to enhance evidence collection, analysis, and incident response workflows.
    • Leverage AI-driven capabilities, security analytics, and telemetry to improve investigative efficiency and response effectiveness.
    • Enhance DFIR capabilities by improving logging, forensic readiness, tooling, and operational processes across enterprise environments.

Qualifications

ABOUT YOUR SKILLS

  • Proven experience in digital forensics, incident response, and cyber investigations within large enterprise environments.
  • Hands-on expertise with EDR/XDR platforms, SIEM solutions, forensic tools, and security monitoring technologies.
  • Strong ability to investigate and analyze security incidents across endpoints, servers, cloud environments, networks, and identity platforms.
  • Proficiency in Python and/or PowerShell, with working knowledge of KQL and other security-focused query languages.
  • Solid understanding of cyber threat actor tactics, techniques, and procedures (TTPs), including the MITRE ATT&CK framework.
  • Excellent analytical, problem-solving, and communication skills, with the ability to clearly document and present technical findings to diverse stakeholders.

Nice-to-Have:

  • Professional certifications such as GCFA, GNFA, GCIH, GREM, GCFE, CISSP, OSCP, or equivalent DFIR and cybersecurity credentials.
  • Hands-on experience in cloud security investigations and DFIR activities across Azure, AWS, and/or Google Cloud Platform (GCP) environments.
  • Strong proficiency with digital forensic methodologies and tools, including FTK, EnCase, Velociraptor, KAPE, Autopsy, Volatility, or similar platforms.
  • Experience in aviation, transportation, critical infrastructure, or operational technology (OT) environments, with knowledge of security automation, orchestration, and AI-assisted investigation techniques to enhance incident response effectiveness.

WHAT WE OFFER

We’re all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We’re really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever.

 Flex Week: Work from home up to 2 days/week (depending on your team’s needs)
 Flex Day: Make your workday suit your life and plans
 Flex Location: Take up to 30 days a year to work from any location in the world
 Employee Wellbeing: Access our 24/7 EAP and Champion Health platform for all-around wellbeing
 Professional Development: Build your skills with LinkedIn Learning and internal training programs
 Competitive Benefits: Designed to suit your country and contract type

Equal Employment Opportunity Employer / Veterans / Disabled.  SITA is an equal employment opportunity employer.  All qualified applicants will receive consideration for employment without regard of race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against based on disability.


Salary / Compensation Note
Hidden (-999)Qualifications:

ABOUT YOUR SKILLS

  • Proven experience in digital forensics, incident response, and cyber investigations within large enterprise environments.
  • Hands-on expertise with EDR/XDR platforms, SIEM solutions, forensic tools, and security monitoring technologies.
  • Strong ability to investigate and analyze security incidents across endpoints, servers, cloud environments, networks, and identity platforms.
  • Proficiency in Python and/or PowerShell, with working knowledge of KQL and other security-focused query languages.
  • Solid understanding of cyber threat actor tactics, techniques, and procedures (TTPs), including the MITRE ATT&CK framework.
  • Excellent analytical, problem-solving, and communication skills, with the ability to clearly document and present technical findings to diverse stakeholders.

Nice-to-Have:

  • Professional certifications such as GCFA, GNFA, GCIH, GREM, GCFE, CISSP, OSCP, or equivalent DFIR and cybersecurity credentials.
  • Hands-on experience in cloud security investigations and DFIR activities across Azure, AWS, and/or Google Cloud Platform (GCP) environments.
  • Strong proficiency with digital forensic methodologies and tools, including FTK, EnCase, Velociraptor, KAPE, Autopsy, Volatility, or similar platforms.
  • Experience in aviation, transportation, critical infrastructure, or operational technology (OT) environments, with knowledge of security automation, orchestration, and AI-assisted investigation techniques to enhance incident response effectiveness.

WHAT WE OFFER

We’re all about diversity. We operate in 200 countries and speak 60 different languages and cultures. We’re really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever.

 Flex Week: Work from home up to 2 days/week (depending on your team’s needs)
 Flex Day: Make your workday suit your life and plans
 Flex Location: Take up to 30 days a year to work from any location in the world
 Employee Wellbeing: Access our 24/7 EAP and Champion Health platform for all-around wellbeing
 Professional Development: Build your skills with LinkedIn Learning and internal training programs
 Competitive Benefits: Designed to suit your country and contract type

Equal Employment Opportunity Employer / Veterans / Disabled.  SITA is an equal employment opportunity employer.  All qualified applicants will receive consideration for employment without regard of race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against based on disability.

Education:UNAVAILABLEEmployment Type: FULL_TIME