Dutch Digital Forensics and Incident Response (DFIR) Consultant

Ransomware Recovery

Utrecht

On-site

EUR 60,000 - 85,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical benefits
Bonus opportunities

Job summary

A leading cybersecurity organization is seeking an experienced incident response professional in Utrecht to engage in incident response tasks, collect forensic artifacts, and analyze IOCs. Candidates must be bilingual in English and Dutch with at least 2 years of experience in digital forensics. The role is remote with travel requirements of up to 50%. Competitive compensation and benefits are included.

Qualifications

  • 2+ years of experience in digital forensics or incident response.
  • Ability to analyze logs from various sources.
  • Understanding of business email compromise investigation techniques.

Responsibilities

  • Engage in incident response tasks with various stakeholders.
  • Collect forensic artifacts from affected systems.
  • Analyze files for indicators of compromise (IOCs).

Skills

Digital forensics
Incident response
Forensic analysis tools
Threat research
Customer service
Communication
Bilingual (English and Dutch)

Tools

EDR technologies
SIEM solutions
E-discovery tools

Job description

CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware events. Our team collaborates with prominent global insurance carriers, leading law firms, and Fortune 1000 businesses.

Core Responsibilities:

  • Engage on behalf of CYPFER in incident response tasks, interacting with various insurance partners, legal counsel, incident response units, client executives, and technical teams.
  • Utilize standard tools and methodologies to collect forensic artifacts and images from affected systems.
  • Assist with Windows forensics and triage to assess compromise and investigations.
  • Familiarity with malware analysis tools and methodologies.
  • Apply mitigation strategies and concepts to remediate identified threats.
  • Analyze triage collections/artifacts for indicators of compromise (IOCs) and potentially malicious activity.
  • Review logs from host systems and appliances to identify suspicious activities.
  • Collect forensic disk and memory images from physical and virtual endpoints and servers.
  • Understanding of an incident lifecycle and cyber-kill-chain.
  • Correlate events and build timelines of events.
  • Maintain current knowledge on emerging threats and vulnerabilities.
  • Analyze files for IOCs using various techniques.

Technical Requirements:

  • Bilingual English and Dutch
  • 2+ years of experience in digital forensics, incident response, or a similar role.
  • Knowledge of Windows and Unix/Linux operating systems.
  • Understanding of the functionality of EDR / EPP technologies.
  • Familiarity with forensic acquisition and analysis of physical and virtual systems.
  • Working knowledge of storage technologies such as RAID, NAS, SAN, Fiber Channel, iSCSI, and NFS.
  • Ability to analyze and interpret logs from various sources.
  • Ability to perform threat research and analyze current threats.
  • Understanding of business email compromise (BEC) cases and investigation techniques.
  • Participate in a rotating on-call schedule; ability to work on weekends and outside normal business hours as needed.
  • This role is remote but requires the ability to travel on short notice to a client site up to 50%. Must maintain flexibility to travel frequently within 24-48 hours' notice for deployments typically 1-2 weeks in duration.

Business Responsibilities:

  • Maintain current knowledge of information security, incident response techniques, emerging threats, and tools.
  • Work independently and produce high-quality deliverables with minimal supervision.
  • Exhibit strong customer service and consulting skills.
  • Adhere to client and internal policies, procedures, and security practices.
  • Maintain detailed notes and draft updates and reports as required.
  • Remain calm, composed, and articulate in tough customer situations.
  • Exhibit excellent relationship management and communication skills.

Preferred Skills:

  • Understand obfuscation techniques used to conceal malicious commands and traffic, and lateral movement strategies employed by threat actors.
  • Familiarity with exfiltration techniques used by threat actors.
  • Knowledge of SIEM and SOAR solutions.
  • Experience with e-discovery tools and methodologies.
  • Proficiency in collecting and analyzing data from mobile devices/cell phones.
  • Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar are a plus.

Compensation package includes a base salary, medical benefits and multiple bonus opportunities.

CYPFER is an equal opportunity employer. If you need accommodation during the interview process or beyond, please let us know. We celebrate our inclusive work environment and welcome applicants from all backgrounds and perspectives.

We thank you for your interest in joining the CYPFER team! While we welcome all applicants, only those selected for an interview will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

German Digital Forensics and Incident Response (DFIR) Consultant
German Digital Forensics and Incident Response (DFIR) Consultant

Ransomware Recovery • Utrecht

Remote
EUR 60,000 - 80,000
Medical benefits
Multiple bonus opportunities
German Senior Digital Forensics and Incident Response (DFIR) Consultant
German Senior Digital Forensics and Incident Response (DFIR) Consultant

Ransomware Recovery • Utrecht

Remote
EUR 60,000 - 80,000
Senior Consultant DFIR
Senior Consultant DFIR

Fox-IT • Rijswijk

On-site
EUR 50,000 - 75,000
German Senior Recovery Specialist
German Senior Recovery Specialist

Ransomware Recovery • Utrecht

Remote
EUR 70,000 - 90,000
Dutch Senior Recovery Specialist
Dutch Senior Recovery Specialist

Ransomware Recovery • Utrecht

On-site
EUR 60,000 - 80,000
Consultant
Consultant

FORCYD • Amsterdam

On-site
EUR 379,000 - 513,000
Full-time contract for two years
Competitive salary €3.300,00 per month
Mobility allowance
+6
Principal Consultant - DFIR
Principal Consultant - DFIR

Fox-IT • Rijswijk

On-site
EUR 120,000 - 170,000
Talent Pool Starters Academy 2027
Talent Pool Starters Academy 2027

Forcyd • Amsterdam

On-site
Mobility allowance
Bonus scheme based on performance
Strong pension plan
+3
Remote Digital Forensics & Incident Response Consultant
Remote Digital Forensics & Incident Response Consultant

Ransomware Recovery • Utrecht

Remote
EUR 60,000 - 85,000
Medical benefits
Bonus opportunities
Starters Academy 2027
Starters Academy 2027

Forcyd • Amsterdam

On-site
EUR 35,000 - 39,000
Mobility allowance
Bonus scheme
Pension plan
+4