Principal Consultant – DFIR

Jobtailor

Rijswijk

On-site

EUR 90,000 - 140,000

Full time

11 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

NCC Group is seeking a senior Digital Forensics and Incident Response lead to manage client engagements across security incidents and investigations in a fast-paced environment.

You will analyze complex data, mentor teams, and coordinate multi-disciplinary responses to protect clients. The role emphasizes clear communication with executives and delivering high-quality technical findings.

Qualifications

  • Ample experience in incident response, security operations or security consulting.
  • Strong knowledge supporting cyber incident response activities.
  • Understanding of network analysis, host investigation and forensics, and malware analysis.
  • Significant DF experience.
  • Experience using a case management system.
  • Advanced host, network and cloud forensics.
  • Log analysis and malware triage.
  • Experience evaluating client security controls, architecture and operations.
  • Experience crafting scripts using Perl, Python, PowerShell and Bash.
  • Experience triaging Windows and Linux hosts.
  • Experience with network traffic analysis.
  • Experience with log data analysis.
  • Ability to explain technical output to non-technical audiences, including executives.
  • Experience in 24x7 environments and turns.
  • Ability to lead large projects and reporting.
  • Strong interpersonal and communication skills including report-writing.
  • Identify attacker TTPs and develop indicators of compromise.
  • CREST/SANS certifications preferred.

Responsibilities

  • Manage and service NCC Group clients within Digital Forensics and Incident Response.
  • Participate in analysis and response to security incidents and events.
  • Support clients through deep technical, detail-oriented analysis.
  • Mentor and lead team members during engagements.
  • Coordinate cohesive teams during technical engagements.
  • Respond to emergency incidents including mitigation and remediation.
  • Maintain composure in client incident-management scenarios.
  • Provide clients with high-quality technical investigations.
  • Collaborate on identifying, resolving and documenting security incidents.
  • Conduct intelligence-driven investigative analysis.
  • Discuss broader technology and security posture with clients for Cyber Threat assessments.
  • Support internal cross-service collaboration, reviews and efficiency improvements.

Skills

Incident Response
Digital Forensics
Malware Analysis
Python Scripting
Cloud Forensics
Log Analysis
Windows Host Triage
Linux Host Triage
Network Analysis
PowerShell

Education

CREST CPIA
CREST CRIA
CREST CCNIA
CREST CCHIA
SANS GCFA
SANS GNFA
SANS GCIH

Tools

Perl
Python
PowerShell
Bash
Case Management System
Azure
M365
AWS
GCP

Job description

  • Manage and service NCC Group clients within the Digital Forensics and Incident Response space
  • Participate in the analysis and response to security incidents and events
  • Support clients through deep technical, detail-oriented analysis
  • Manage and mentor team members
  • Coordinate cohesive teams during technical engagements
  • Respond to emergency incidents, including mitigation and remediation activities
  • Maintain composure and effectiveness in client incident-management scenarios
  • Provide clients with high-quality technical investigations
  • Collaborate on the identification, resolution, and documentation of security incidents
  • Conduct intelligence-driven investigative analysis
  • Discuss broader technology and security posture with clients to perform Cyber Threat assessments
  • Support internal cross-service collaboration, reviews, and efficiency improvements
Requirements
  • Ample experience in incident response, security operations or strategic security consulting
  • Strong technical knowledge supporting cyber incident response activities
  • Understanding of network analysis, host investigation and forensics, and malware analysis
  • Significant experience in a Digital Forensics environment
  • Experience using a case management system
  • Advanced host, network, and cloud system forensics
  • Log analysis and malware triage
  • Experience evaluating client security controls, architecture, and operations
  • Experience crafting scripts and tools using Perl, Python, PowerShell, and Bash
  • Experience triaging Windows and Linux hosts
  • Experience with network traffic analysis
  • Experience with log data analysis
  • Ability to explain technical output to non-technical audiences, including executive and C-Suite levels
  • Experience working in 24x7 environments and turns
  • Ability to lead large-sized projects and take responsibility for analysis and reporting
  • Strong interpersonal and communication skills, including report-writing and presentation skills
  • Ability to identify attacker tactics, techniques and procedures (TTPs) and develop indicators of compromise
  • Relevant professional certification such as CREST CPIA/CRIA/CCNIA/CCHIA or SANS GCFA/GNFA/GCIH preferred
  • Strong understanding of common enterprise technologies and configurations, including Azure, M365, AWS, and GCP
Core Competencies

Demonstrates expertise in Digital Forensics and Incident Response, with a strong focus on technical analysis, incident management, and client communication. Capable of leading teams and projects while providing high-quality investigations and security assessments.

Highest-signal resume keywords
  • Incident Response
  • Digital Forensics
  • Malware Analysis
  • Python Scripting
  • Cloud System Forensics
ATS Optimization Keywords
Hard Skills
  • Incident Response
  • Digital Forensics
  • Network Analysis
  • Malware Analysis
  • Log Analysis
  • Windows Host Triage
  • Linux Host Triage
  • Cloud Forensics
  • Technical Investigations
  • Cyber Threat Assessment
Soft Skills
  • Interpersonal Skills
  • Communication Skills
  • Report Writing
  • Presentation Skills
  • Team Leadership
Certifications & Qualifications
  • CREST CPIA
  • CREST CRIA
  • CREST CCNIA
  • CREST CCHIA
  • SANS GCFA
  • SANS GNFA
  • SANS GCIH
Industry Keywords
  • Cybersecurity
  • Security Operations
  • Incident Management
  • Technical Engagements
  • Emergency Incident Response
Tools & Technologies
  • Perl
  • Python
  • PowerShell
  • Bash
  • Case Management System
  • Azure
  • M365
  • AWS
  • GCP
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Consultant - DFIR
Principal Consultant - DFIR

Fox-IT • Rijswijk

On-site
EUR 120,000 - 170,000
Crowdstrike Technical Consultant
Crowdstrike Technical Consultant

Accenture the Netherlands • Amsterdam

On-site
EUR 90,000 - 130,000
Senior DFIR Consultant: Incident Response & Forensics
Senior DFIR Consultant: Incident Response & Forensics

Jobtailor • Rijswijk

On-site
EUR 90,000 - 140,000
Staff AI Engineer
Staff AI Engineer

Jobtailor • Den Haag

On-site
EUR 90,000 - 130,000
Senior Consultant DFIR
Senior Consultant DFIR

Fox-IT • Rijswijk

On-site
EUR 50,000 - 75,000
Principal DFIR Consultant: Lead & Mentor Incident Response
Principal DFIR Consultant: Lead & Mentor Incident Response

nccgroup • Rijswijk

On-site
EUR 70,000 - 100,000
Solutions Engineer – Real-Time Intelligence Platforms
Solutions Engineer – Real-Time Intelligence Platforms

Jobtailor • Den Haag

On-site
EUR 120,000 - 180,000
Crowdstrike Pre-Sales Associate Director
Crowdstrike Pre-Sales Associate Director

Accenture the Netherlands • Amsterdam

On-site
EUR 90,000 - 130,000
Principal Consultant - DFIR
Principal Consultant - DFIR

nccgroup • Rijswijk

On-site
EUR 70,000 - 100,000
Senior Solutions Architect
Senior Solutions Architect

NCC Group • Rijswijk

On-site
EUR 70,000 - 90,000