Senior DFIR Analyst

Gridware

Sydney

Remote

AUD 120,000 - 170,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Remote-friendly
Fully remote option
Sydney office option

Job summary

Gridware is seeking a Senior DFIR Analyst to lead investigations into BEC, ransomware and web application breaches, driving evidence collection, forensic analysis, and reporting with a top-notch team.

Experience with CrowdStrike Falcon, RTR containment, and Windows/Linux/macOS forensics is essential; remote-friendly role offering fully remote or Sydney office options in a flexible, fast-paced environment.

Qualifications

  • Hands-on with CrowdStrike Falcon for endpoint investigation, threat hunting, and incident containment.
  • Real-world experience in incident response, digital forensics, or a security operations centre.
  • Demonstrated technical capability with digital forensics tools, on Windows systems (plus Linux/macOS is a plus).
  • Autonomous, critical thinker with a team-first mindset.
  • General cyber security knowledge, threat landscape and playbooks.
  • Strong communication skills to convey technical concepts to varied audiences.
  • Certifications such as GCFE, GCFA, or GCIH are helpful but not essential.

Responsibilities

  • Collect and preserve evidence across incidents.
  • Conduct host-based and network-based forensics.
  • Perform malware analysis and log review.
  • Lead investigations and contribute to strategy across incident types.

Skills

CrowdStrike
RTR (Real Time Response)
Incident response
Forensics
Windows
Linux
macOS
Threat hunting
Communication
Teamwork

Tools

KAPE
AXIOM
SOF-ELK
Velociraptor
CrowdStrike
SentinelOne

Job description

About the role

Our Senior DFIR Analyst role is an exciting opportunity for those looking to go head-to-head with today's cyber criminals. We're looking for a Senior DFIR Analyst with at least 2 years' experience to lead and support investigations into Business Email Compromise (BEC), ransomware, and web application breaches. You'll drive evidence collection, containment, forensic analysis, reporting while working alongside some of the best in the field.

You'll contribute your expertise to strategy and methodology across various incident types, with a particular focus on forensic investigations into complex cyber incidents. You'll operate confidently both independently and as part of a team, working across the full operational flow and attack chain of security incidents to help our clients respond to cyber attacks and other investigations.

Gridware responds to a broad range of incidents, including Business Email Compromise, insider threat and employee misconduct, cloud and network compromise, ransomware, and data extortion.

What you'll do
  • Collect and preserve evidence
  • Conduct host-based and network-based forensics
  • Perform malware analysis
  • Review cloud and application logs
  • Use industry best-practice tools for log ingestion, threat hunting, and Endpoint Detection and Response, including KAPE, AXIOM, SOF-ELK, Velociraptor, CrowdStrike, and SentinelOne
What we're looking for
  • Hands-on experience with CrowdStrike Falcon for endpoint investigation, threat hunting, and incident containment, including using Real Time Response (RTR) to support forensic evidence collection and response activities
  • Real-world experience in incident response, digital forensics, or a security operations centre
  • Demonstrated technical capability with digital forensics tools, particularly on Windows systems (experience with Linux and macOS investigations is a plus)
  • An autonomous, critical thinker with a positive attitude and a team-first mindset
  • General cyber security knowledge, including an understanding of the threat landscape, threat actor groups, and playbooks
  • Strong communication skills, able to convey technical concepts to a broad range of audiences
  • Certifications such as GCFE, GCFA, or GCIH are helpful in demonstrating capability but not essential
Why Gridware
  • Flexible, remote-friendly environment, work fully remote, or from our A-grade office in Australia Square in the heart of Sydney's CBD
  • Great Place to Work certified and Top 10 Best Workplace in Australia 2024 & 2025
  • Exposure to high-impact, high-urgency incidents across industries
  • A flexible, remote-friendly environment — we're DFIR operators and we understand that work can be busy, but so can life
  • Variety of casework: Gridware responds to a high volume of incidents, so no two days are the same
  • Strong learning and development culture: a collaborative team of innovators with access to leading tooling, training, and thought leadership
  • Mental health days and flexible working arrangements
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DFIR Analyst - Remote Incident Response & Forensics
Senior DFIR Analyst - Remote Incident Response & Forensics

Gridware • Sydney

Remote
AUD 120,000 - 170,000
Remote-friendly
Fully remote option
Sydney office option
Senior DFIR Analyst
Senior DFIR Analyst

Forensic Focus • Sydney

Remote
AUD 108,000 - 138,000
Staff Incident Response Commander
Staff Incident Response Commander

Cox Purtell • Sydney

On-site
AUD 180,000 - 240,000
Senior DFIR Investigator & Incident Response Lead
Senior DFIR Investigator & Incident Response Lead

Forensic Focus • Sydney

Remote
AUD 108,000 - 138,000
Digital Forensics Analyst
Digital Forensics Analyst

Triskele Labs • City of Melbourne

On-site
AUD 80,000 - 120,000
Hybrid working environment
Salary packaging/novated leasing
Discounts & Benefits Platform access
+2
Level 1 Security Analyst
Level 1 Security Analyst

Triskele Labs • City of Melbourne

On-site
AUD 60,000 - 78,000
Digital Forensics (DFIR) / Incident Response Analyst
Digital Forensics (DFIR) / Incident Response Analyst

Forensic Focus • Sydney

Hybrid
AUD 95,000 - 129,000
Assistant Vice President, Security Detection & Response, Global Information Security, Sydney
Assistant Vice President, Security Detection & Response, Global Information Security, Sydney

Bank of America • Sydney

On-site
AUD 90,000 - 120,000
Senior DFIR Investigator & Incident Response Lead
Senior DFIR Investigator & Incident Response Lead

Forensic Focus Limited • Sydney

Hybrid
AUD 150,000 - 230,000
Security Forensics Engineer
Security Forensics Engineer

Pepperstone • City of Melbourne

On-site
AUD 120,000 - 180,000
Hybrid working
Remote work up to 4 weeks/year
15 weeks parental leave (primary carer
+3