54 dfir jobs at 36 companies in United States

2mo
Save
Mark Applied
Hide
DFIR
United States
RemoteFull Time
CYE
CYE: Software platform for quantifying and managing organizational cyber exposure.
2+ YOEDFIR experience; cloud forensics in Windows/Linux; incident response lifecycle; threat hunting; English communication.
Splunk, Elasticsearch, SQL, VQL, Azure, AWS
1d
Save
Mark Applied
Hide
DFIR Team Lead
McLean, Virginia, United States
$113k-$257k/yr RemoteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
3+ YOE3+ years DFIR experience; Windows/Mac/Linux forensics; FTK, EnCase, XWF, Axiom; Python/PowerShell scripting; log analysis; timeline reconstruction; technical reporting; HS diploma/GED.
FTK, EnCase, XWF, Axiom, Python, PowerShell, AWS, Azure, GCP
1d
Save
Mark Applied
Hide
DFIR Team Lead
McLean, Virginia, United States
$113k-$257k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years DFIR experience, Windows/Mac/Linux forensics, DFIR toolsets (FTK, EnCase, XWF, Axiom), Python/PowerShell scripting, log analysis, technical reporting, HS diploma/GED.
FTK, EnCase, XWF, Axiom, Python, PowerShell, IIS, AWS, Azure, GCP
1mo
Save
Mark Applied
Hide
Principal Consultant, Cloud DFIR (Unit 42) - Remote
Harrisburg or Pennsylvania or United States
$151k-$208k/yr RemoteFull Time
Palo Alto Networks
Palo Alto NetworksNASDAQ: PANW: Provides enterprise-grade network, cloud, and endpoint security software.
6+ YOE6+ years DFIR/incident response experience, 3+ years securing/investigating AWS/Azure/GCP, experience with cloud telemetry and forensic tools, strong client communication and consulting skills.
AWS, Azure, GCP, AWS CloudTrail, Azure Activity Logs, Microsoft Entra ID, Google Cloud Audit Logs, AWS Security Hub, GuardDuty, Microsoft Defender, Microsoft Sentinel, Google Security Command Center, Kubernetes, MITRE ATT&CK
2mo
Save
Mark Applied
Hide
Principal DFIR Consultant - Remote (Anywhere in the U.S.)
United States
RemoteFull Time
GuidePoint Security
GuidePoint Security: Provides cybersecurity consulting, managed services, and integrated technology solutions.
8+ YOE8+ years DFIR, 10+ IT/security, lead role on high-severity engagements, strong written/verbal communication, mentoring junior staff, methodologies/tooling development.
PowerShell, Python, Bash, Go, Velociraptor, EDR, NDR, XDR, SIEM, cloud forensics tools
1mo
Save
Mark Applied
Hide
Senior Investigator Digital Forensics, Incident Response (DFIR)
Chicago or Milwaukee or Dallas or Columbus or Kirkland or Cincinnati or New York or Cleveland or Oklahoma City or Austin or Albany or St. Petersburg or Hartford or Pittsburgh or St. Louis or Miami or Sacramento or Raleigh or Minneapolis or Mountain View or Scottsdale or San Francisco or Morristown or Denver or Boston or Philadelphia or Des Moines or Overland Park or Los Angeles or Charlotte or Walnut Creek or Carmel or Seattle or Houston or Arlington or Atlanta or Redmond or Bentonville or Beaverton or Nashville or Detroit or San Diego
$54k-$206k/yr HybridFull Time
Accenture
AccentureNYSE: ACN: Global provider of management consulting and technology services.
4+ YOEBachelor's degree or equivalent, minimum 4 years DFIR experience, 3+ years with enterprise incident response and common DFIR toolsets; ability to obtain US security clearances; strong analytic and client-facing skills.
Volatility, X-Ways, FTK, EnCase, Autopsy, EDR, AWS, Azure, GCP, Microsoft Windows, GNU/Linux, MacOS, Active Directory, Python, PowerShell, Bash
1w
Save
Mark Applied
Hide
Director, DFIR (Remote)
United States
$185k-$200k/yr RemoteFull Time
Surefire Cyber
Surefire Cyber: Provides rapid incident response and digital forensics services.
Proven DFIR and incident management experience, cloud and forensic tool knowledge, people management (3-5), client-facing communication, and willingness to provide after-hours on-call support.
ELK, Axiom, EnCase, FTK, Volatility, AWS, Azure, GCP
1mo
Save
Mark Applied
Hide
Cyber Risk Defense Consultant VI – (DFIR) Principal
Greensboro, North Carolina, United States
HybridFull Time
Kaiser Permanente
Kaiser Permanente: Provides integrated medical care and health insurance plans.
10+ YOE10+ years IT experience including 4+ years in information security or network engineering; bachelor\u0002s degree (or equivalent experience); 4+ years informal leadership; incident response, forensics/DFIR, and executive communication skills.
1mo
Save
Mark Applied
Hide
Engineer, Cybersecurity DFIR
Jacksonville or Provo
OnsiteFull Time
Intercontinental Exchange
Intercontinental ExchangeNYSE: ICE: Operates global financial exchanges, clearing houses, and mortgage technology.
3+ YOE3+ years relevant experience, university degree in a related discipline, hands-on Windows and Linux experience, strong networking knowledge, and skills in incident response, forensics, threat hunting, and security analytics.
Windows, Linux
1mo
Save
Mark Applied
Hide
Engineer, Cybersecurity DFIR
Jacksonville, Florida, United States
OnsiteFull Time
Intercontinental Exchange
Intercontinental ExchangeNYSE: ICE: Operates global financial exchanges, clearing houses, and mortgage platforms.
3+ YOE3+ years relevant experience; university degree in a related discipline; hands-on Windows and Linux experience; strong networking knowledge; experience in digital forensics, incident response, threat hunting, and security analytics.
Windows, Linux
3mo
Save
Mark Applied
Hide
Cyber Incident Manager
West Nyack, New York, United States
$95k-$100k/yr HybridFull Time
The Salvation Army
The Salvation Army: Provides social services and humanitarian aid for communities.
3+ YOEBachelor's degree; 3-5 years related experience; strong DFIR, SIEM, IDS/IPS, EDR, threat intel, SOAR; leadership and communication skills.
DFIR, SIEM, IDS/IPS, EDR, Wireshark, EnCase, FTK, Autopsy, Volatility, Threat Intelligence, SOAR, Palo Alto XSOAR, Swimlane, ZenDesk, ServiceNow, Jira
2d
Save
Mark Applied
Hide
Threat Hunting Specialist, Global
Center Valley, Pennsylvania, United States
HybridFull Time
Olympus
OlympusTokyo Stock Exchange: 7733: Manufactures medical endoscopes and minimally invasive surgical tools.
7+ YOEBachelor's in computer science or equivalent, IT security certs preferred, minimum 7 years IT security experience, SIEM/EDR/DFIR experience, knowledge of threats/vulnerabilities and CVSS 3.0, strong analytical and communication skills.
SIEM, EDR, DFIR, CVSS 3.0
1w
Save
Mark Applied
Hide
Insider Threat Investigator - Cloud and AI Specialist
United States
$80k-$132k/yr RemoteFull Time
Allstate
AllstateNYSE: ALL: Provides insurance products for vehicles, homes, and businesses.
3+ YOE3+ years cybersecurity/digital forensics/cloud security or risk analytics experience; experience with insider threat methodologies, SIEM/DFIR/UEBA, cloud security, and AI risks; strong analytical and communication skills.
Amazon Web Services (AWS), Microsoft Azure, SIEM Tools, DFIR, UEBA
2mo
Save
Mark Applied
Hide
Senior Associate, Forensic Technology
Los Angeles or Sacramento or San Diego or San Francisco or Washington or Chicago or New York or Dallas or Houston
OnsiteFull Time
KPMG
KPMG: Global professional services network providing audit, tax, and advisory.
3+ YOE3+ years digital forensics/incident response experience, bachelor’s in CS/engineering/forensics, DFIR investigations across iOS/macOS/Windows, scripting/programming (Python,Rust,C++,C#,Java), relevant certifications, authorized to work in the U.S.
DFIR, Artificial Intelligence (AI), Python, Rust, C++, C#, Java, eDiscovery
3mo
Save
Mark Applied
Hide
Incident Response Expert IV (Cyber Eviction Analysts)
Arlington, Virginia, United States
$125k-$145k/yr OnsiteFull Time
Argo Cyber Systems
Argo Cyber Systems: Provides managed cybersecurity and incident response services to organizations.
5+ YOE8+ years in cyber incident management or DFIR; TS/SCI with DHS suitability; strong IR, SOC, or DFIR experience; able to work on 24x7/onsite; US citizenship.
SIEM, EDR, Splunk, SentinelOne, Elastic, Wireshark, ServiceNow, Jira, Remedy, Windows, Linux, Unix
1mo
Save
Mark Applied
Hide
Senior Director, Digital Forensics and Incident Response
New York City or Maryland or Tel Aviv or San Francisco or London or Budapest or United States or South America
RemoteFull Time
BlueVoyant
BlueVoyant: Managed detection, response, and threat intelligence security services.
3+ YOEExperience leading DFIR incidents as incident commander, 3+ years hands-on DFIR, 6+ years client-facing cyber/incident response experience, executive communication, mentoring, familiarity with endpoint/cloud/identity forensics and related tools, US citizenship required.
EnCase, FTK, Magnet AXIOM, Velociraptor, Splunk, Microsoft Sentinel, CrowdStrike, Microsoft 365, Microsoft Entra ID, Azure, AWS, Okta, Google Workspace, KQL, SPL, SQL, PowerShell, Python, Bash
4w
Save
Mark Applied
Hide
Senior Adversary Pursuit Engineer
Atlanta or Boston or Chicago or Denver or Los Angeles or New York City or San Francisco or Austin or United States
$140k-$175k/yr RemoteFull Time
Flock Safety
Flock Safety: Sells AI-powered cameras and software for public safety surveillance.
5+ YOE5+ years cybersecurity experience (≥3 years DFIR/threat hunting), DFIR on diverse environments including Android IoT, cloud (AWS/GCP/Azure), SIEM/EDR expertise, detection engineering (Splunk SPL, YARA, Sigma), automation (Torq, Tines), MITRE ATT&CK mapping, and mentoring skills.
AWS, GCP, Azure, Android, SIEM, EDR, Torq, Tines, LLMs, Splunk SPL, YARA, Sigma, MITRE ATT&CK
1w
Save
Mark Applied
Hide
Managing Director, Digital Investigations & Cyber Risk
New York, New York, United States
$250k/yr HybridFull Time
Nardello & Co.
Nardello & Co.: Provides investigative services and litigation support to global clients.
12+ YOE12+ years in digital forensics/cyber response, proven book of business, expert testimony experience, ability to lead teams, and relevant DFIR certifications.
4d
Save
Mark Applied
Hide
Manager-Cybersecurity
Richardson, Texas, United States
OnsiteFull Time
Berry Appleman & Leiden
Berry Appleman & Leiden: Provide global corporate immigration legal and technology services.
3+ MgmtBachelor's degree or equivalent, 3+ years leading cybersecurity teams, experience in incident response, DFIR, threat hunting, security operations, and security engineering.
XDR, SIEM, Threat Intelligence, SOAR, Vulnerability Management, Identity Security, Cloud Security
1mo
Save
Mark Applied
Hide
Cyber Forensics Analyst
Portland, Oregon, United States
OnsiteFull Time
ECS
ECSNYSE: ASGN: Provides advanced technology and engineering services to government agencies.
5+ YOE5-8 years in cybersecurity/forensics, experience with industry/open-source DFIR tools, memory forensics, malware analysis, IOC development, and incident response.
Volatility, FTK, Wireshark, Windows Registry, Windows System Calls, Linux artifacts, Java de-obfuscation