Job Summary:
Tesla's Security Intelligence team is responsible for protecting the company's intellectual property and infrastructure from insider threats. They are seeking a detail-oriented Sr. Digital Forensics & eDiscovery Engineer to lead complex investigations and collaborate with various teams to ensure evidence integrity and compliance with legal standards.
Responsibilities:
• Investigate insider threats and security incidents across endpoints, cloud platforms, and network infrastructure. Identify IoCs, unauthorized access, and data exfiltration activities to assess risk and support remediation efforts
• Conduct deep-dive analysis of system artifacts including file systems, memory dumps, registry hives, and logs from EDR/XDR platforms, SIEMs, DLP systems to reconstruct user activity and build comprehensive event timelines
• Perform forensically sound acquisition of digital evidence from laptops, mobile devices, servers, and cloud repositories while maintaining strict chain of custody, evidence integrity, and comprehensive collection documentation
• Execute targeted, defensible data collections from M365 (Exchange, SharePoint, OneDrive, Teams), enterprise endpoints, and cloud repositories using Microsoft Purview and other digital forensic tools
• Serve as the team's eDiscovery technical liaison, supporting Early Case Assessment (ECA) by advising Legal on data volume, custodian scope, and collection feasibility, while maintaining working knowledge of downstream phases (processing, review, and production) to ensure upstream decisions support downstream needs
• Collaborate with HR and Legal to conduct structured, compliant interviews - using digital evidence to guide questions, validate statements, and remediate security incidents
• Manage legal hold and preservation workflows in coordination with IT and Legal, ensuring accurate identification and preservation of relevant data and devices, and ongoing compliance with regulatory and legal obligations
• Produce clear, legally defensible documentation across all matters, including chain-of-custody records, collection logs, and executive-ready technical narratives for Legal, Compliance, HR, and leadership stakeholders
• Drive continuous improvement by refining DLP policies, access controls, detection rules, and eDiscovery intake runbooks based on patterns and lessons learned from past investigations and legal matters
Qualifications:
Required:
• Bachelor's degree in Cybersecurity or related, or equivalent experience
• 5+ years of combined experience in digital forensics, eDiscovery, or security investigations
• Proficiency with digital forensic tools: FTK, X-Ways, Cellebrite, Axiom, or equivalent
• Hands-on experience with Microsoft Purview for M365 preservation and collection across Exchange, SharePoint, OneDrive, and Teams
• Working knowledge of the EDRM framework, with deep expertise in identification, preservation, and collection, and functional understanding of processing, review, and production
• Solid understanding of network protocols (TCP/IP, HTTP/S, DNS) and log analysis via SIEM platforms
• In-depth knowledge of Windows, macOS, and Linux/Unix systems and their forensic artifacts
• Proven experience integrating AI tools to accelerate forensic or eDiscovery workflows
• Strong commitment to confidentiality, evidence integrity, and ethical conduct across all investigative and legal matters
Company:
Tesla is an electric vehicle and clean energy company that provides electric cars, solar, and renewable energy solutions. Founded in 2003, the company is headquartered in Austin, USA, with a team of 10001+ employees. The company is currently Late Stage.