DFIR Analyst
Core
Technical lead on small to medium-sized breach response investigations for a 24x7x365 DFIR team, owning evidence and documentation quality end-to-end.
Role type
Senior DFIR Analyst (Technical Lead)
Builds
Defensible forensic reports and tactical containment/remediation guidance for global enterprises.
Domain
Cybersecurity / Digital Forensics / Incident Response
Deliverable
client delivery
Required skills
Digital forensics, incident response, threat hunting, EDR/XDR analysis, network forensics, cloud incident response, malware analysis, reverse engineering, Python scripting, technical writing
Preferred skills
Experience with SentinelOne EDR, X-Ways Forensics, Axiom, FTK, dynamic malware analysis, endpoint threat hunting
Technologies
SentinelOne, X-Ways Forensics, Axiom, FTK, Python, AWS, Azure, GCP
Responsibilities
Lead DFIR engagements and direct analytical focus; conduct EDR-driven incident response and advanced forensic analysis across endpoint, network, cloud, and SaaS; develop containment guidance and remediation recommendations; acquire and preserve forensic evidence following chain-of-custody; mentor analysts on technical methodology; manage triage and analysis in high-pressure incidents; build or improve scripts and tooling to streamline workflows.
Seniority
Senior, hands-on IC