23 dfir jobs at 15 companies in Laurel, MD

2w
Save
Mark Applied
Hide
DFIR Team Lead
McLean, Virginia, United States
$113k-$257k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
3+ YOE3+ years DFIR experience, Windows/Mac/Linux forensics, DFIR toolsets (FTK, EnCase, XWF, Axiom), Python/PowerShell scripting, log analysis, technical reporting, HS diploma/GED.
FTK, EnCase, XWF, Axiom, Python, PowerShell, IIS, AWS, Azure, GCP
1mo
Save
Mark Applied
Hide
Senior Investigator Digital Forensics, Incident Response (DFIR)
Chicago or Milwaukee or Dallas or Columbus or Kirkland or Cincinnati or New York or Cleveland or Oklahoma City or Austin or Albany or St. Petersburg or Hartford or Pittsburgh or St. Louis or Miami or Sacramento or Raleigh or Minneapolis or Mountain View or Scottsdale or San Francisco or Morristown or Denver or Boston or Philadelphia or Des Moines or Overland Park or Los Angeles or Charlotte or Walnut Creek or Carmel or Seattle or Houston or Arlington or Atlanta or Redmond or Bentonville or Beaverton or Nashville or Detroit or San Diego
$54k-$206k/yr HybridFull Time
Accenture
AccentureNYSE: ACN: Global provider of management consulting and technology services.
4+ YOEBachelor's degree or equivalent, minimum 4 years DFIR experience, 3+ years with enterprise incident response and common DFIR toolsets; ability to obtain US security clearances; strong analytic and client-facing skills.
Volatility, X-Ways, FTK, EnCase, Autopsy, EDR, AWS, Azure, GCP, Microsoft Windows, GNU/Linux, MacOS, Active Directory, Python, PowerShell, Bash
1w
Save
Mark Applied
Hide
DFIR Engagement Manager
McLean, Virginia, United States
$69k-$158k/yr RemoteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
3+ YOE3+ years progressive project management experience, cyber incident response or digital forensics experience, PMO skills, strong communication and crisis management, HS diploma required; bachelor\u0002s preferred.
3w
Save
Mark Applied
Hide
Senior Consultant, Digital Forensic and Incident Response (DFIR) (Remote)
Elkridge, Maryland, United States
RemoteFull Time
Surefire Cyber
Surefire Cyber: Provides rapid incident response and digital forensics services.
Experienced DFIR professional with forensic analysis, incident response, malware analysis, client-facing skills, and ability to provide after-hours on-call support.
ELK, Axiom, Encase, FTK
1d
Save
Mark Applied
Hide
Digital Forensics SME
Rockville, Maryland, United States
$140k-$184k/yr OnsiteFull Time
ActioNet
ActioNet: Provides IT modernization and cybersecurity services for government agencies.
8+ YOEBachelor's degree in a relevant technology field, 8+ years of specialized incident response experience, advanced DFIR expertise, enterprise forensic toolset experience, and evidentiary documentation experience.
DFIR, SOC, CMMI-DEV, CMMI-SVC, ISO 20000, ISO 27001, ISO 9001, HDI, Agile, DevSecOps, C4ISR, SIGINT, FSA
2mo
Save
Mark Applied
Hide
Senior Associate, Forensic Technology
Los Angeles or Sacramento or San Diego or San Francisco or Washington or Chicago or New York or Dallas or Houston
OnsiteFull Time
KPMG
KPMG: Global professional services network providing audit, tax, and advisory.
3+ YOE3+ years digital forensics/incident response experience, bachelor’s in CS/engineering/forensics, DFIR investigations across iOS/macOS/Windows, scripting/programming (Python,Rust,C++,C#,Java), relevant certifications, authorized to work in the U.S.
DFIR, Artificial Intelligence (AI), Python, Rust, C++, C#, Java, eDiscovery
2mo
Save
Mark Applied
Hide
Director, Cyber Security Incident Response Team (CSIRT)
Gaithersburg, Maryland, United States
$169k-$254k/yr HybridFull Time
AstraZeneca
AstraZenecaLondon Stock Exchange: AZN: Researches and develops medicines to treat major diseases globally.
5+ YOE5+ MgmtExtensive enterprise SOC/IR leadership, incident command, DFIR, OT/ICS, cloud governance, 24x7 operations, stakeholder management.
SIEM, SOAR, XDR, LLM, AI
3mo
Save
Mark Applied
Hide
Head of Insider Risk - USDS
Washington, District of Columbia, United States
$206k-$397k/yr OnsiteFull Time
TikTok USDS Joint Venture
TikTok USDS Joint Venture: Operates and secures TikTok services for U.S. users.
5+ YOE2+ Mgmt5+ years in insider risk/DFIR/IR with 2+ years leading teams; expertise in digital forensics, incident response, detection engineering, and cross-functional governance.
SIEM, EDR, DLP, UEBA, AWS CloudTrail, Azure Monitor, GCP Audit Logs, EnCase, FTK, Cellebrite, X-Ways, AXIOM, Python, Bash, PowerShell, CrowdStrike Falcon, Carbon Black, Splunk, QRadar, Sentinel, AWS, Azure, GCP, MITRE ATT&CK, NIST SP 800-53, CISA
1w
Save
Mark Applied
Hide
FedRamp Customer Success Manager
United States or Washington or Maryland or Virginia
$100k-$140k/yr HybridFull Time
Magnet Forensics
Magnet Forensics: Provides software for digital forensics and evidence recovery.
Strategic customer success experience with enterprise/public-sector accounts, executive engagement, strong technical aptitude in DFIR, experience with Salesforce and Gainsight, ability to manage FedRAMP requirements and travel ~20%.
Gainsight, Salesforce
2w
Save
Mark Applied
Hide
Host Based Cyber Systems Analyst IV
Arlington, Virginia, United States
$130k-$160k/yr OnsiteFull Time
Argo Cyber Systems
Argo Cyber Systems: Provides managed cybersecurity and incident response services to organizations.
8+ YOEU.S. citizen with active TS/SCI, DHS suitability, 8+ years DFIR experience, forensic acquisition skills, cloud and hybrid identity knowledge, strong reporting and analysis, and scripting/automation experience.
Entra ID/Azure AD, M365, AWS, GCP, SaaS, Azure Activity Logs, AWS CloudTrail, VPC Flow Logs, Microsoft Defender, Sentinel, AWS GuardDuty, GCP Chronicle, PowerShell, Python, Bash, JavaScript, Terraform, Kubernetes, CloudFormation, Azure Resource Manager, Docker, EnCase, FTK, SIFT, X-Ways, Volatility, WireShark, Sleuth Kit/Autopsy, Splunk, Snort, Crowdstrike, Carbon Black
1mo
Save
Mark Applied
Hide
Director, Cyber Security Incident Response Team (CSIRT)
Gaithersburg, Maryland, United States
$169k-$254k/yr HybridFull Time
AstraZeneca
AstraZenecaLondon Stock Exchange: AZN: Global biopharmaceutical developing and manufacturing prescription medicines.
5+ YOE5+ MgmtSenior leader to command enterprise incident response across cloud, on-premises and OT/ICS; requires 5+ years SOC/IR leadership, DFIR, MITRE ATT&CK, SIEM/SOAR/XDR, cloud/identity/endpoint expertise, and strong communication.
SIEM, SOAR, XDR, LLM, MITRE ATT&CK
2mo
Save
Mark Applied
Hide
Senior Cyber Lead
Linthicum Heights, Maryland, United States
$175k-$225k/yr OnsiteFull Time
Quantum Sky
Quantum Sky: Engineers mission-critical technology for federal government and defense sectors.
10+ YOE3+ MgmtBachelor's degree, 10+ years cybersecurity/DFIR experience, 3+ years technical leadership, DoD 8570/8140 baseline (Security+), Top Secret/SCI eligibility, experience with host/network/memory/malware forensics and SIEM/IDS/endpoint tools.
Splunk, ELK Stack, FTK, EnCase, X-Ways, Velociraptor, Volatility, Wireshark, SIEM, IDS/IPS
2mo
Save
Mark Applied
Hide
Senior Cyber Lead
Linthicum Heights, Maryland, United States
$175k-$225k/yr OnsiteFull Time
Tyto Athene
Tyto Athene: Provides IT modernization and cybersecurity services to government agencies.
10+ YOE3+ MgmtBachelor's degree, 10+ years cybersecurity/DFIR experience, 3+ years senior technical leadership, DoD RMF/STIG knowledge, experience with host/network/memory/malware forensics, SIEM/IDS/endpoint tech, and ISO/IEC 17025 evidence handling.
Splunk, ELK Stack, FTK, EnCase, X-Ways, Velociraptor, Volatility, Wireshark, SIEM, IDS/IPS
1w
Save
Mark Applied
Hide
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Baltimore, Maryland, United States
OnsiteFull Time
OneMain Financial
OneMain FinancialNYSE: OMF: Provides personal loans and credit cards to nonprime consumers.
8+ YOE8+ years cybersecurity experience with 6+ years SOC experience; bachelor\u0002s degree or equivalent; 2+ DFIR/forensics years; requires multiple certifications (e.g., GCFA, GCIH, CISSP); deep expertise in enterprise incident response, detection engineering, and threat hunting.
Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, Python, Bash, CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, Defender for Cloud Apps, Elastic, EDR/XDR, NDR, SIEM, SOAR, IDS/IPS, WAF, firewalls, VPN, DNS, DHCP, proxy, CASB, DLP, IAM, PAM, Kubernetes, Azure, AWS, Microsoft 365, Microsoft Entra ID, VMware, Hyper-V
1mo
Save
Mark Applied
Hide
Host Based Systems Analyst IV
Arlington, Virginia, United States
FieldFull Time
Solutions³
Solutions³: Provides cybersecurity consulting, IT management, and professional training services.
8+ YOEUS citizen with active TS/SCI clearance, able to obtain DHS suitability before start, 8+ years DFIR/host forensics experience, BS in CS/Cybersecurity/CE or HS + 10+ years, strong forensic imaging, analysis, reporting, and team leadership skills.
EnCase, FTK, SIFT, X-Ways, Volatility, Wireshark, Sleuth Kit, Autopsy, Snort, Splunk, CrowdStrike, Carbon Black
1mo
Save
Mark Applied
Hide
Cybersecurity Shift Lead
Linthicum, Maryland, United States
OnsiteFull Time
CyberMaxx
CyberMaxx: Provides managed detection and response cybersecurity services to organizations.
3+ YOE1+ MgmtMinimum 3 years SOC/cybersecurity operations experience, 1 year in a lead role; bachelor's degree or equivalent; certified (CompTIA Security+, CySA+, GCIH, GCIA, CEH); experience with SIEM/EDR/MDR; able to work rotating 24/7 shifts.
SIEM, EDR, MDR, DFIR, MITRE ATT&CK, NIST
4w
Save
Mark Applied
Hide
Security Analyst II
Alexandria, Virginia, United States
$155k-$165k/yr HybridFull Time
Public Broadcasting Service
Public Broadcasting Service: Non-profit organization distributing educational television and digital content.
5+ YOE5+ years cybersecurity experience with security analysis, incident response, threat hunting, system configuration, and cloud/on-prem defensive operations; relevant GIAC/ISC2/EC-Council/etc. certifications and a related bachelor’s degree preferred.
DFIR, IAM, PAM, DLP, NGFW, EDR, SIEM, IDS/IPS, MITRE ATT&CK, SOAR, CASB, DNS, Linux, Windows, PowerShell, Python, JavaScript, MacOS, WAF, CIS Benchmarks, Artificial Intelligence (AI)