Sr. DFIR Analyst
Core
Technical lead for small to medium-sized breach response investigations, owning evidence, documentation, and forensic analysis across endpoint, network, and cloud environments.
Role type
Senior DFIR Analyst (Technical Lead)
Builds
Defensible investigative reports, containment guidance, and forensic evidence packages for global enterprises.
Domain
Cybersecurity / Digital Forensics / Incident Response
Deliverable
client delivery
Required skills
Digital forensics, incident response, threat hunting, EDR/XDR platforms, SIEMs, network forensics, cloud incident response, malware analysis, reverse engineering, Python scripting, technical writing
Preferred skills
SentinelOne EDR experience, consulting or services delivery background, dynamic malware analysis, endpoint threat hunting
Technologies
X-Ways Forensics, Axiom, FTK, SentinelOne, AWS, Azure, GCP
Responsibilities
Lead DFIR engagements and direct analytical focus; conduct advanced forensic analysis on endpoint, network, cloud, and SaaS environments; develop containment and remediation guidance; acquire and preserve forensic evidence following chain-of-custody; mentor analysts on methodology and best practices; manage triage in large-scale incidents; build or improve scripts and tooling for forensic workflows.
Seniority
Senior, hands-on IC with mentorship responsibilities