6+ YOE6+ years DFIR/incident response experience, 3+ years securing/investigating AWS/Azure/GCP, experience with cloud telemetry and forensic tools, strong client communication and consulting skills.
AWS, Azure, GCP, AWS CloudTrail, Azure Activity Logs, Microsoft Entra ID, Google Cloud Audit Logs, AWS Security Hub, GuardDuty, Microsoft Defender, Microsoft Sentinel, Google Security Command Center, Kubernetes, MITRE ATT&CK
8+ YOE8+ years DFIR, 10+ IT/security, lead role on high-severity engagements, strong written/verbal communication, mentoring junior staff, methodologies/tooling development.
Senior Investigator Digital Forensics, Incident Response (DFIR)
Chicago or Milwaukee or Dallas or Columbus or Kirkland or Cincinnati or New York or Cleveland or Oklahoma City or Austin or Albany or St. Petersburg or Hartford or Pittsburgh or St. Louis or Miami or Sacramento or Raleigh or Minneapolis or Mountain View or Scottsdale or San Francisco or Morristown or Denver or Boston or Philadelphia or Des Moines or Overland Park or Los Angeles or Charlotte or Walnut Creek or Carmel or Seattle or Houston or Arlington or Atlanta or Redmond or Bentonville or Beaverton or Nashville or Detroit or San Diego
$54k-$206k/yrHybridFull Time
AccentureNYSE: ACN: Global provider of management consulting and technology services.
4+ YOEBachelor's degree or equivalent, minimum 4 years DFIR experience, 3+ years with enterprise incident response and common DFIR toolsets; ability to obtain US security clearances; strong analytic and client-facing skills.
Volatility, X-Ways, FTK, EnCase, Autopsy, EDR, AWS, Azure, GCP, Microsoft Windows, GNU/Linux, MacOS, Active Directory, Python, PowerShell, Bash
Surefire Cyber: Provides rapid incident response and digital forensics services.
Proven DFIR and incident management experience, cloud and forensic tool knowledge, people management (3-5), client-facing communication, and willingness to provide after-hours on-call support.
Cyber Risk Defense Consultant VI – (DFIR) Principal
Greensboro, North Carolina, United States
HybridFull Time
Kaiser Permanente: Provides integrated medical care and health insurance plans.
10+ YOE10+ years IT experience including 4+ years in information security or network engineering; bachelor\u0002s degree (or equivalent experience); 4+ years informal leadership; incident response, forensics/DFIR, and executive communication skills.
Intercontinental ExchangeNYSE: ICE: Operates global financial exchanges, clearing houses, and mortgage technology.
3+ YOE3+ years relevant experience, university degree in a related discipline, hands-on Windows and Linux experience, strong networking knowledge, and skills in incident response, forensics, threat hunting, and security analytics.
Intercontinental ExchangeNYSE: ICE: Operates global financial exchanges, clearing houses, and mortgage platforms.
3+ YOE3+ years relevant experience; university degree in a related discipline; hands-on Windows and Linux experience; strong networking knowledge; experience in digital forensics, incident response, threat hunting, and security analytics.
OlympusTokyo Stock Exchange: 7733: Manufactures medical endoscopes and minimally invasive surgical tools.
7+ YOEBachelor's in computer science or equivalent, IT security certs preferred, minimum 7 years IT security experience, SIEM/EDR/DFIR experience, knowledge of threats/vulnerabilities and CVSS 3.0, strong analytical and communication skills.
Insider Threat Investigator - Cloud and AI Specialist
United States
$80k-$132k/yrRemoteFull Time
AllstateNYSE: ALL: Provides insurance products for vehicles, homes, and businesses.
3+ YOE3+ years cybersecurity/digital forensics/cloud security or risk analytics experience; experience with insider threat methodologies, SIEM/DFIR/UEBA, cloud security, and AI risks; strong analytical and communication skills.
Amazon Web Services (AWS), Microsoft Azure, SIEM Tools, DFIR, UEBA
Los Angeles or Sacramento or San Diego or San Francisco or Washington or Chicago or New York or Dallas or Houston
OnsiteFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
3+ YOE3+ years digital forensics/incident response experience, bachelor’s in CS/engineering/forensics, DFIR investigations across iOS/macOS/Windows, scripting/programming (Python,Rust,C++,C#,Java), relevant certifications, authorized to work in the U.S.
Incident Response Expert IV (Cyber Eviction Analysts)
Arlington, Virginia, United States
$125k-$145k/yrOnsiteFull Time
Argo Cyber Systems: Provides managed cybersecurity and incident response services to organizations.
5+ YOE8+ years in cyber incident management or DFIR; TS/SCI with DHS suitability; strong IR, SOC, or DFIR experience; able to work on 24x7/onsite; US citizenship.
Senior Director, Digital Forensics and Incident Response
New York City or Maryland or Tel Aviv or San Francisco or London or Budapest or United States or South America
RemoteFull Time
BlueVoyant: Managed detection, response, and threat intelligence security services.
3+ YOEExperience leading DFIR incidents as incident commander, 3+ years hands-on DFIR, 6+ years client-facing cyber/incident response experience, executive communication, mentoring, familiarity with endpoint/cloud/identity forensics and related tools, US citizenship required.
EnCase, FTK, Magnet AXIOM, Velociraptor, Splunk, Microsoft Sentinel, CrowdStrike, Microsoft 365, Microsoft Entra ID, Azure, AWS, Okta, Google Workspace, KQL, SPL, SQL, PowerShell, Python, Bash
Managing Director, Digital Investigations & Cyber Risk
New York, New York, United States
$250k/yrHybridFull Time
Nardello & Co.: Provides investigative services and litigation support to global clients.
12+ YOE12+ years in digital forensics/cyber response, proven book of business, expert testimony experience, ability to lead teams, and relevant DFIR certifications.
Berry Appleman & Leiden: Provide global corporate immigration legal and technology services.
3+ MgmtBachelor's degree or equivalent, 3+ years leading cybersecurity teams, experience in incident response, DFIR, threat hunting, security operations, and security engineering.
ECSNYSE: ASGN: Provides advanced technology and engineering services to government agencies.
5+ YOE5-8 years in cybersecurity/forensics, experience with industry/open-source DFIR tools, memory forensics, malware analysis, IOC development, and incident response.
Volatility, FTK, Wireshark, Windows Registry, Windows System Calls, Linux artifacts, Java de-obfuscation