DFIR Analyst
Core
Conduct EDR-driven incident response and vendor-agnostic forensic analysis across endpoint, network, cloud, and SaaS environments to investigate ransomware, business email compromise, and identity compromise.
Role type
Digital Forensics and Incident Response (DFIR) Analyst
Builds
Forensic evidence, investigative reports, and security hardening recommendations
Domain
Cybersecurity, Digital Forensics, Incident Response
Deliverable
client delivery
Required skills
Digital forensics, incident response, threat hunting, Windows forensic analysis, evidence acquisition, chain-of-custody procedures, malware analysis, memory analysis, EDR/XDR platforms, SIEMs, network protocols, scripting
Preferred skills
Linux and macOS forensic analysis, cloud environments (AWS, Azure, GCP)
Technologies
X-Ways Forensics, Axiom, FTK, SentinelOne, SIEMs
Responsibilities
Conduct forensic analysis and incident response; Acquire and preserve forensic evidence; Support malware and memory analysis; Prepare security hardening recommendations; Contribute to customer-facing status updates and formal reports; Maintain awareness of emerging threats and attacker techniques; Participate in rotating on-call schedule for high-pressure incidents
Seniority
Mid-level, hands-on IC