Stand out for this role — generate a tailored resume and cover letter in about a minute.
Forensic Focus Limited seeks an experienced DFIR contractor to lead incident response operations across triage, containment, eradication and recovery, and to conduct in-depth forensic analysis of Windows, Linux and macOS systems, memory images, and network traffic.
The role requires independence, strong communication with executive and legal stakeholders, and ability to manage multi-client engagements in regulated environments.
The RoleThis contractor position spans two disciplines: leading incident response operations — from initial triage and live endpoint collection through containment, eradication and recovery — and conducting in-depth digital forensic analysis of Windows, Linux and macOS systems, memory images and network traffic, while coordinating client communications and regulatory reporting.
Candidates should be proficient with forensic collection tools such as KAPE, Velociraptor, UAC and CyLR, and analysis platforms including Volatility and MemProcFS. Experience with EDR-based IR, Active Directory attack techniques (Kerberoasting, golden/silver tickets), IOC development (YARA, Sigma), and knowledge of NIS2 and relevant cybersecurity legislation is expected.
This role suits an experienced DFIR professional comfortable operating independently as a freelancer or contractor, who can lead war-room incidents, communicate with executive and legal stakeholders, and perform deep forensic analysis — ideally with exposure to regulated environments and multi-client consulting engagements.