Digital Forensics and Incident Response (DFIR) analyst

rgare

Ireland

Hybrid

EUR 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

RGA is seeking a senior incident response professional to lead complex cyber investigations and elevate the organization's resilience across global operations. The role combines hands-on DFIR, advisory leadership, and security program oversight in both remote and hybrid settings.

You will guide security teams, engage executives and legal stakeholders, and drive AI-assisted workflows to improve investigation speed and reporting quality.

Qualifications

  • 5+ years in incident response, DFIR, or security operations.
  • Experience leading major cyber incidents including ransomware or cloud compromise.
  • Demonstrated forensic tool proficiency (FTK/Encase/X-Ways/Magnet Axiom/SIFT).

Responsibilities

  • Lead enterprise incident response and cyber crisis engagements từ detection through recovery.
  • Direct investigations across Windows, Linux, macOS, Microsoft 365, AWS, Azure, and hybrid environments.
  • Perform advanced threat hunting using SIEM, EDR, and threat intel platforms.
  • Develop containment, eradication, and remediation strategies aligned to risk.
  • Produce executive briefings, technical reports, and post-incident reviews.
  • Collaborate with legal, compliance, privacy and external stakeholders as needed.
  • Drive adoption of AI-assisted workflows to speed investigations and reporting.

Skills

Digital forensics
Executive communication
Threat hunting
Log analytics
Incident response

Education

Bachelor's degree in Cybersecurity or related field
Industry certifications (GCFA/GCFE/GCIH/GCIA/CISSP/CISM/AWS/Azure security)

Tools

Splunk
Microsoft Defender
CrowdStrike Falcon
ServiceNow SIR
Cloud security tools
FTK
Encase
X-Ways
Magnet Axiom
SIFT

Job description

About the Role

We are seeking a senior incident response ("DFIR") professional to lead complex cyber investigations, strengthen RGA's enterprise resilience, and guide security teams through critical incidents. This role combines hands-on DFIR expertise, strategic advisory capabilities, stakeholder engagement, and security program leadership across global environments.


Who Thrives in This Role?

You are motivated by investigating sophisticated attacks, improving security operations, and turning lessons learned into measurable improvements. You want to leverage the latest tooling's and methods to "find evil". Always want to help improve tooling's with new ideas. You are comfortable with engaging executives, legal teams, technology leaders, and technical responders during high-pressure situations.


Key Responsibilities


  • Lead enterprise incident response and cyber crisis engagements from detection through recovery.

  • Direct host, network, cloud, identity, and SaaS investigations across Windows, Linux, macOS, Microsoft 365, AWS, Azure, and hybrid environments.

  • Perform advanced threat hunting and compromise assessments using SIEM, EDR, forensic, and threat intelligence platforms.

  • Develop containment, eradication, and remediation strategies aligned to business risk.

  • Produce executive briefings, technical reports, board-ready updates, and post-incident reviews.

  • Partner with legal, compliance, privacy, audit, and external stakeholders when required.

  • Drive adoption of AI-assisted workflows to improve investigation speed, reporting quality, and operational efficiency.

  • Support the 24/7 on-call rotation.


Required Experience and Expertise


  • 5+ years in incident response, DFIR, security operations, consulting, or related cybersecurity disciplines.

  • Experience leading major cyber incidents involving ransomware, business email compromise, insider threats, cloud compromise, supply chain attacks, or advanced persistent threats.

  • Strong digital forensics capability using industry-standard forensic and triage tools.

  • Experience with Splunk, Microsoft Defender, CrowdStrike Falcon, ServiceNow SIR, and cloud security technologies.

  • Knowledge of network protocols, detection engineering, log analytics, and threat hunting methodologies.

  • Excellent verbal and written communication skills for technical and executive audiences.

  • Demonstrated ability to manage multiple priorities in a global enterprise environment.

  • Forensic tools (FTK, Encase, X-Ways, Magnet Axiom, SIFT or other ) experience is mandatory.


Leadership Expectations

Provide technical leadership during investigations, influence strategic security decisions, contribute to capability development, and serve as a trusted advisor for cybersecurity risk management and response readiness.


Education and Certifications

Industry certifications such as GCFA, GCFE, GCIH, GCIA, CISSP, CISM, Azure Security Engineer, AWS Security Specialty, or comparable credentials are highly desirable (not mandatory). Bachelor's degree in Cybersecurity, Computer Science, Information Security, Engineering, Intelligence Studies, or a related discipline, or equivalent experience is desirable (not mandatory).


Work Environment

Remote or hybrid eligible. Participation in an on-call rotation. Travel is not required as part of the standard day-to-day duties. The role supports global operations and may engage with stakeholders across multiple regions and time zones.


#LI-DM1


What you can expect from RGA


  • Gain valuable knowledge from and experience with diverse, caring colleagues around the world.

  • Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought.

  • Join the bright and creative minds of RGA, and experience vast, endless career potential.


We're excited to get to know you and connect your unique skills with our global opportunities. To create a modern and seamless experience, we use artificial intelligence (AI) in parts of our preliminary screening process. This technology helps us personalize job recommendations, automate interview scheduling, evaluate candidates based solely on experience‑without considering name, gender, or other personal details-and provide real-time answers through our chatbot. AI is used only during early screening and never makes hiring decisions. Your RGA recruiter will work closely with you every step of the way to ensure the process feels personal, thoughtful, and focused on you.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DFIR Incident Response Lead — Remote
Senior DFIR Incident Response Lead — Remote

rgare • Ireland

Hybrid
EUR 120,000 - 180,000
Incident Response Manager - Security
Incident Response Manager - Security

United States Digital Space LLC • Dublin

On-site
EUR 90,000 - 120,000
Cyber Defense Incident Responder - Associate Director
Cyber Defense Incident Responder - Associate Director

EY • Dublin

On-site
EUR 120,000 - 180,000
International Contract Bench, Incident Response (DFIR)
International Contract Bench, Incident Response (DFIR)

Jobgether SRL • Ireland

On-site
EUR 90,000 - 130,000
Flexible contract
Live investigations
Exposure to ransomware
+2
Sr. Software Engineer, Threat Detection Incident Response (Hybrid, Dublin)
Sr. Software Engineer, Threat Detection Incident Response (Hybrid, Dublin)

CrowdStrike Holdings, Inc. • Ireland

On-site
EUR 120,000 - 150,000
Equity awards
Wellness programs
Vacation policy
+5
Senior DFIR Lead: Incident Response & Cyber Crisis (Hybrid)
Senior DFIR Lead: Incident Response & Cyber Crisis (Hybrid)

Forensic Focus • Ireland

Hybrid
EUR 65,000 - 111,000
Digital Forensics and Incident Response (DFIR) analyst
Digital Forensics and Incident Response (DFIR) analyst

Forensic Focus • Ireland

Hybrid
EUR 65,000 - 111,000
International Contract Bench, Incident Response (DFIR)
International Contract Bench, Incident Response (DFIR)

Lever, Inc. • Ireland

On-site
EUR 83,000 - 165,000
Flexible contract-based engagement
Live IR investigations exposure
Collaborative IR team
Cyber Defense Incident Responder - Assistant Director
Cyber Defense Incident Responder - Assistant Director

EY • Dublin

On-site
EUR 120,000 - 150,000
Sr. Software Engineer, Threat Detection Incident Response (Hybrid, Dublin/London)
Sr. Software Engineer, Threat Detection Incident Response (Hybrid, Dublin/London)

CrowdStrike Inc. • Dublin

Hybrid
EUR 120,000 - 180,000
Market compensation
Wellness programs
Vacation & holidays
+3