An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Forensic Focus Limited in Sydney seeks a senior DFIR professional to lead high-priority investigations across endpoints, networks and cloud platforms, identifying root causes and attack methods.
You will partner with incident response, threat defence and security operations teams, while driving improvements to forensic tooling, automation and readiness processes.
A track record of five+ years in DFIR, malware analysis, memory forensics, and relevant certifications is required.
This senior hands-on position involves leading high-priority cyber investigations across endpoints, networks, and cloud environments, identifying root causes and attack methods. The specialist partners closely with incident response, threat defence, and security operations teams, while also driving improvements to forensic tooling, automation, and readiness processes.
Candidates need five or more years in DFIR or cyber investigations, with expertise in malware analysis, memory forensics, threat hunting, and evidence collection. Familiarity with SIEM, EDR, IDS/IPS, and DLP platforms is required. Relevant certifications such as GCFA, GCFE, EnCE, CFCE, or MCFE are strongly valued.
This role suits an experienced DFIR professional who thrives on technically complex investigations and is equally comfortable mentoring junior analysts and communicating findings to non-technical stakeholders. It is well suited to someone seeking long-term career progression within a large, strategically invested security function.