Senior Investigator Digital Forensics, Incident Response (DFIR)
Chicago or Milwaukee or Dallas or Columbus or Kirkland or Cincinnati or New York or Cleveland or Oklahoma City or Austin or Albany or St. Petersburg or Hartford or Pittsburgh or St. Louis or Miami or Sacramento or Raleigh or Minneapolis or Mountain View or Scottsdale or San Francisco or Morristown or Denver or Boston or Philadelphia or Des Moines or Overland Park or Los Angeles or Charlotte or Walnut Creek or Carmel or Seattle or Houston or Arlington or Atlanta or Redmond or Bentonville or Beaverton or Nashville or Detroit or San Diego
$54k-$206k/yrHybridFull Time
AccentureNYSE: ACN: Global provider of management consulting and technology services.
4+ YOEBachelor's degree or equivalent, minimum 4 years DFIR experience, 3+ years with enterprise incident response and common DFIR toolsets; ability to obtain US security clearances; strong analytic and client-facing skills.
Volatility, X-Ways, FTK, EnCase, Autopsy, EDR, AWS, Azure, GCP, Microsoft Windows, GNU/Linux, MacOS, Active Directory, Python, PowerShell, Bash
Senior Consultant, Digital Forensic and Incident Response (DFIR) (Remote)
Elkridge, Maryland, United States
RemoteFull Time
Surefire Cyber: Provides rapid incident response and digital forensics services.
Experienced DFIR professional with forensic analysis, incident response, malware analysis, client-facing skills, and ability to provide after-hours on-call support.
Los Angeles or Sacramento or San Diego or San Francisco or Washington or Chicago or New York or Dallas or Houston
OnsiteFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
3+ YOE3+ years digital forensics/incident response experience, bachelor’s in CS/engineering/forensics, DFIR investigations across iOS/macOS/Windows, scripting/programming (Python,Rust,C++,C#,Java), relevant certifications, authorized to work in the U.S.
TikTok USDS Joint Venture: Operates and secures TikTok services for U.S. users.
5+ YOE2+ Mgmt5+ years in insider risk/DFIR/IR with 2+ years leading teams; expertise in digital forensics, incident response, detection engineering, and cross-functional governance.
United States or Washington or Maryland or Virginia
$100k-$140k/yrHybridFull Time
Magnet Forensics: Provides software for digital forensics and evidence recovery.
Strategic customer success experience with enterprise/public-sector accounts, executive engagement, strong technical aptitude in DFIR, experience with Salesforce and Gainsight, ability to manage FedRAMP requirements and travel ~20%.
Argo Cyber Systems: Provides managed cybersecurity and incident response services to organizations.
8+ YOEU.S. citizen with active TS/SCI, DHS suitability, 8+ years DFIR experience, forensic acquisition skills, cloud and hybrid identity knowledge, strong reporting and analysis, and scripting/automation experience.
Quantum Sky: Engineers mission-critical technology for federal government and defense sectors.
10+ YOE3+ MgmtBachelor's degree, 10+ years cybersecurity/DFIR experience, 3+ years technical leadership, DoD 8570/8140 baseline (Security+), Top Secret/SCI eligibility, experience with host/network/memory/malware forensics and SIEM/IDS/endpoint tools.
Tyto Athene: Provides IT modernization and cybersecurity services to government agencies.
10+ YOE3+ MgmtBachelor's degree, 10+ years cybersecurity/DFIR experience, 3+ years senior technical leadership, DoD RMF/STIG knowledge, experience with host/network/memory/malware forensics, SIEM/IDS/endpoint tech, and ISO/IEC 17025 evidence handling.
Security Operations Center (SOC) Tier 3 Analyst / Incident Responder
Baltimore, Maryland, United States
OnsiteFull Time
OneMain FinancialNYSE: OMF: Provides personal loans and credit cards to nonprime consumers.
8+ YOE8+ years cybersecurity experience with 6+ years SOC experience; bachelor\u0002s degree or equivalent; 2+ DFIR/forensics years; requires multiple certifications (e.g., GCFA, GCIH, CISSP); deep expertise in enterprise incident response, detection engineering, and threat hunting.
Elastic Security, KQL, ES|QL/EQL, SQL, PowerShell, Python, Bash, CrowdStrike Falcon, Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud, Defender for Cloud Apps, Elastic, EDR/XDR, NDR, SIEM, SOAR, IDS/IPS, WAF, firewalls, VPN, DNS, DHCP, proxy, CASB, DLP, IAM, PAM, Kubernetes, Azure, AWS, Microsoft 365, Microsoft Entra ID, VMware, Hyper-V
Solutions³: Provides cybersecurity consulting, IT management, and professional training services.
8+ YOEUS citizen with active TS/SCI clearance, able to obtain DHS suitability before start, 8+ years DFIR/host forensics experience, BS in CS/Cybersecurity/CE or HS + 10+ years, strong forensic imaging, analysis, reporting, and team leadership skills.
CyberMaxx: Provides managed detection and response cybersecurity services to organizations.
3+ YOE1+ MgmtMinimum 3 years SOC/cybersecurity operations experience, 1 year in a lead role; bachelor's degree or equivalent; certified (CompTIA Security+, CySA+, GCIH, GCIA, CEH); experience with SIEM/EDR/MDR; able to work rotating 24/7 shifts.
Public Broadcasting Service: Non-profit organization distributing educational television and digital content.
5+ YOE5+ years cybersecurity experience with security analysis, incident response, threat hunting, system configuration, and cloud/on-prem defensive operations; relevant GIAC/ISC2/EC-Council/etc. certifications and a related bachelor’s degree preferred.