Digital Forensics and Incident Response (DFIR) Senior Associate
Core
Manage security engagements, analyze forensic data, and investigate cyber incidents to improve client security posture and incident response programs.
Role type
Senior Digital Forensics and Incident Response (DFIR) Associate
Builds
Forensic evidence, incident reports, and improved security policies for enterprise clients
Domain
Cybersecurity, Digital Forensics, Incident Response
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Digital forensics investigation, incident response lifecycle management, network analysis, memory analysis, endpoint analysis, log analysis, threat hunting, packet capture analysis, scripting (Python, Perl, C/C++, C#, PowerShell, BASH, Batch)
Preferred skills
Cloud platform experience (AWS, GCP, Azure), Endpoint Detection & Response (EDR) tool usage
Technologies
EnCase, FTK, X-Ways, Sleuthkit, UFED, Cortex, Carbon Black, Crowdstrike, Wireshark, TCPdump, SIEM tools
Responsibilities
Manage security engagements from inception to completion, evaluate and improve incident response policies, examine client internal policies for gaps, recommend courses of action for security maturation, provide evidence and perform structured forensic analysis, perform triage and examine digital media, forensically analyze Windows and Unix systems, perform log analysis, hunt threat actors in enterprise networks and cloud environments, analyze packet captures
Seniority
Senior, hands-on IC