Profile of an IT Forensics Professional

A snapshot look at the IT forensics profession from the perspective of Rob Lee, an IT forensics expert at Mandiant.

By Julia King

Mon, October 19, 2009Computerworld A snapshot look at the IT forensics profession from the perspective of Rob Lee, an IT forensics expert at Mandiant.

Name: Rob Lee

Title: Director and IT forensics expert at Mandiant, a Washington-based information security software and services firm

Related work: Curriculum lead for digital forensics training at the SANS Institute.

30-second résumé: Before joining Mandiant, Lee served as the technical lead for a vulnerability discovery and exploit development team that worked for a variety of law enforcement, government and intelligence agencies.

He is a graduate of the U.S. Air Force Academy and a founding member of the USAF's Information Warfare Squadron, the first U.S. military operational unit focused on information operations.

Skills boost: To stay current, Lee does hands-on work in the field and is an avid reader of and contributor to information security journals and blogs.

A passion to learn and to continue learning -- rather than a formal computer science degree or security certification -- is the top requirement for an IT forensics expert, says Lee, who also teaches SANS certification classes. He also recommends specializing in a particular area of computer forensics.

"If you're choosing forensics, be a specialist in firewalls or hacking or mobile devices," Lee says. "Mobile devices alone are extremely complex and constantly changing.

"If you're just beginning, classes are the way to go," he advises. "After that, you can continue to learn online. The best thing you can do once you attain a certain level [of expertise] is give of yourself back to the community. Choose something you don't think anyone else has [expertise in] and research that. Always do research and publish it."

Next: Opinion: Web 2.0 security depends on users

Mandiant

Loading...
Security MarketSpace
A Hidden Benefit of Desktop Virtualization?
This IDG eZine explores the many user benefits of desktop virtualization. Learn more »
Controlling E-Discovery: What stays in? What goes out?
You want to hold the cards as far as information management, but keeping large in-house teams doesn't make sense. Learn more »
Get Ahead of Your Data in Early Case Assessment
Need tools that provide cost savings today and fit into a long-term e-discovery strategy? Learn more »
The Challenges of Working with Keyword Search
There is a dangerous assumption that keyword search alone can sufficiently manage e-discovery. Learn more »
How In-House Technology Delivers Savings
Learn how companies can gain control of the e-discovery process and reduce costs by bringing software in-house. Learn more »
Cloud Computing Security
Learn how enterprises and service providers can achieve cloud-ready security for a competitive edge. Learn more »
This eBook tells you what you need to know about securing virtualized datacenters.
This eBook tells you what you need to know about securing virtualized datacenters. Learn more »
Achieving Compliance for the Virtual Infrastructure
Read this white paper on key trends in virtualization security from Nemertes Research. Learn more »
 
SPONSORED LINKS
 

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

IDC White Paper: CCM for IT Compliance and Risk Management

White Paper: A Security Blueprint Delivered From within the Network

Maximizing efficiencies with unified communications.

Unified Communications: Thoughts, Strategies and Predictions. Join the discussion.

Cut Costs & Green Your IT Operations with PC Power Management

Webcast: Unleashing the Power of Customer Data

White Paper: Legacy Tools: Not Built for the Helpdesk

Taking a Seat at the Executive Table: The Reality of Virtualization

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Lower IT Costs with Oracle Database 11g Release 2

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

Five CIO challenges addressed by better change management

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Secure & simplify your data center w/Juniper Networks.

Gartner ITxpo Panel Webcast: Real-world Early Adoption of Windows 7.

Masters of Virtualization and Cloud Computing - Daily News

Stay informed with custom newsletters from Tech Dispenser

Trend Micro ranked #1 against real-world malware. Read more.

Streamline IT Costs. Boost Performance with WAN Optimization.

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Mobile Security: The Essential Ingredient for Today's Enterprise

Learn about the growing threat of insider data theft.

Efficiency goes up. Costs come down.

Verint Systems. Discover the Power of Intelligence in Action"

Upgrading to VMware vSphere with vWire

See how AT&T can help protect your network.

White Paper: 5 Best Practices for Smartphone Support

Global Research: CIOs Weigh In On Virtualization

White Paper: Next Generation Remote Infrastructure Management

Seven Design Requirements for Web 2.0 Threat Protection

Cloud-Based Email Management: Opinion Shifts In Favor

Achieving Business Agility with Application Grid

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Build your 1st app FREE with Force.com

Read about how to add efficiencies with Microsoft Virtualization.

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Forrester Webcast - Managing Desktop Support Costs

Be Prepared for Windows 7. Register for this Webcast Series.

Top Five CIO Challenges

AT&T Synaptic Storage as a Service. Expand on demand

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Read the RSA report: Security for Business Innovation

 
 
RESOURCE CENTER