Senior Digital Forensics & Incident Response Consultant (ID#5314)

New Value Solutions

Canada

Remote

CAD 80,000 - 120,000

Part time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

A cybersecurity solutions provider is seeking a highly skilled Senior DFIR Specialist to lead complex investigations and incident response activities. The ideal candidate will have over 5 years of experience in DFIR, handling major incidents, and be proficient in forensic analysis across various environments. This role includes responsibilities for delivering end-to-end incident response and ensuring compliance with evidentiary standards. Candidates with preferred certifications like GCFA or CISSP will have an advantage.

Qualifications

  • 5+ years in DFIR, cybersecurity operations, or threat investigation.
  • Demonstrated experience handling major incidents like ransomware or data breaches.
  • Strong hands-on experience with forensics in Windows and Linux environments.

Responsibilities

  • Conduct advanced forensic investigations across multiple environments.
  • Perform evidence acquisition and disk analysis.
  • Reconstruct attack timelines for incidents.

Skills

Cybersecurity operations
Forensic analysis
Incident response
Threat investigation
Memory forensics
Log analysis

Tools

SIEM platforms
Microsoft Azure
Oracle Linux

Job description

We are seeking a highly skilled Senior DFIR Specialist to lead and execute complex cybersecurity investigations and incident response activities across enterprise environments.

This a contract opportunity on an as needed basis.

This role is responsible for delivering end-to-end incident response, including forensic analysis, containment, eradication, recovery, and post-incident improvement.

This is a contract role.

Key Responsibilities
  • Conduct advanced forensic investigations across Windows environments, Oracle, and Linux systems, Enterprise platforms (Oracle applications, .NET, Microsoft 365 stack including Exchange, SharePoint, OneDrive)
  • Perform (1) Evidence acquisition (disk, memory, cloud artifacts), (2) Volatile memory and disk analysis, (3) Log and telemetry correlation across endpoints and cloud systems
  • Reconstruct attack timelines, including (1) Initial access vector, (2) Lateral movement, (3) Privilege escalation, and (4) Data exfiltration pathways
  • Maintain strict chain-of-custody procedures and evidentiary standards
  • Produce forensic reports suitable for legal, regulatory, and court proceedings
  • Lead or support end-to-end incident response activities, including (1) Triage and incident scoping, (2) Threat containment strategies, and (3) Root cause analysis
  • Respond to incidents such as Ransomware, Malware infections, Identity-based attacks, Cloud security incidents, and Business email compromise
  • Design and execute containment strategies for (1) Endpoint isolation, (2) Account compromise mitigation, and (3) Network segmentation
  • Lead eradication efforts for (1) Removal of persistence mechanisms, (2) Credential resets and hardening
  • Provide guidance on secure recovery practices and business continuity
  • Support engagement strategies for threat actors (e.g., ransomware scenarios), including (1) Advisory on negotiation approaches (if applicable), (2) Coordination with legal, privacy, and executive stakeholders and (3) Assist with regulatory and law enforcement coordination as required
  • Deliver after-action reports (AARs) wit (1) Root cause findings, (2) Gaps in detection and response, and (3) Prioritized remediation recommendations
  • Recommend improvements across (1) Security controls, (2) Logging and monitoring, and (3) Incident response processes
  • Contribute to development of (1) Playbooks and runbooks and (2) Detection rules and threat hunting hypotheses
Qualifications
  • 5+ years in DFIR, cybersecurity operations, or threat investigation
  • Demonstrated experience handling major incidents (e.g., ransomware, data breaches)
  • Experience producing legally defensible forensic documentation
  • Strong hands-on experience with:
  • Windows and Linux (Oracle Linux preferred) forensics
  • Enterprise cloud environments (Microsoft Azure / M365)
  • Proficiency in:
  • Memory forensics (e.g., Volatility)
  • Log analysis and SIEM platforms
Certifications (Preferred)
  • GCFA, GCIH, GNFA, CFCE, CISSP, OSCP, or equivalent
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DFIR Incident Response Lead
Senior DFIR Incident Response Lead

Forensic Focus Limited • Canada

Hybrid
CAD 95,000 - 158,000
Incident Response Commander/Forensic Analyst
Incident Response Commander/Forensic Analyst

Forensic Focus Limited • Montreal (administrative region)

Hybrid
CAD 83,000 - 193,000
Full-Cycle DFIR Specialist (Contract)
Full-Cycle DFIR Specialist (Contract)

New Value Solutions • Canada

Remote
CAD 80,000 - 120,000
Incident Response Senior Consultant
Incident Response Senior Consultant

Forensic Focus Limited • Canada

On-site
CAD 120,000 - 180,000
Incident Response Specialist
Incident Response Specialist

Integriti • Toronto

On-site
CAD 90,000 - 130,000
Consulting Associate/Recovery Services (Forensic Services practice)
Consulting Associate/Recovery Services (Forensic Services practice)

Forensic Focus Limited • Toronto

On-site
CAD 85,000 - 110,000
Sr. Cyber Consultant, DFIR
Sr. Cyber Consultant, DFIR

Forensic Focus Limited • Canada

Hybrid
CAD 95,000 - 158,000
Manager, Security Incident Response
Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development Corporation • Toronto

On-site
CAD 80,000 - 120,000
Incident Response Specialist
Incident Response Specialist

Integriti Group Inc. • Toronto

On-site
CAD 90,000 - 130,000
Senior Incident Response Consultant — Travel-Ready
Senior Incident Response Consultant — Travel-Ready

Forensic Focus Limited • Canada

On-site
CAD 120,000 - 180,000