DFIR Specialist

Trilliuminfosec

Lahore

On-site

PKR 1,200,000 - 2,400,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Trillium Information Security Systems (TISS) is seeking a DFIR Analyst to join our Security Consultancy and Forensic team in Lahore. You will conduct compromise assessments, incident investigations, and forensic analysis across Windows and Linux environments, delivering clear technical reports.

The ideal candidate has hands-on DFIR tooling experience (Velociraptor, KAPE, Volatility), strong OS internals knowledge, and the ability to work under pressure on multiple cases with minimal supervision.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or related field (or equivalent).
  • 2 years of hands-on experience in digital forensics and/or incident response.
  • Strong understanding of Windows and Linux OS internals, networks, and artifacts.
  • Experience using DFIR tools such as Velociraptor, KAPE, EZ Tools, UAC, Log Analysis Tools, Volatility.

Responsibilities

  • Conduct compromise assessments to identify intrusions, persistence, lateral movement, privilege escalation, and data exfiltration.
  • Conduct digital forensic investigations across Windows and Linux systems.
  • Collect, preserve, and analyze digital evidence following forensic best practices.
  • Correlate findings with MITRE ATT&CK to identify adversary tactics, techniques, and procedures (TTPs).
  • Leverage Threat Intelligence platforms to enrich investigations and validate IOCs.
  • Respond to security incidents including ransomware attacks and data breaches.
  • Prepare comprehensive forensic and incident reports covering technical findings and remediation recommendations.
  • Collaborate with SOC, Threat Hunting, IT, and other teams to contain, eradicate, and recover from incidents.
  • Contribute to continuous improvement of DFIR processes, capabilities, methodologies, tools, and playbooks.

Skills

Windows internals
Linux internals
Network protocols
Memory artifacts
DFIR tooling

Education

Bachelor's degree in Computer Science / Cybersecurity / Information Security

Tools

Velociraptor
KAPE
EZ Tools
UAC
Log Analysis
Volatility

Job description

Trillium Information Security Systems (TISS) | Full time

Founded in 2005, Trillium Information Security Systems (TISS) is Pakistan’s first, and largest cybersecurity company. Today, Trillium has gained unrivaled expertise and experience; having delivered complex information assurance solutions to customers, performed specialized information security services, trained thousands of cyber security professionals across the country, and established a comprehensive network of resellers.

Job Description
About the Role

We are looking for a Digital Forensics and Incident Response (DFIR) Analyst to join our SecurityConsultancy and Forensic team. The DFIR Analyst will be responsible for conducting compromiseassessments, incident response investigations, and forensic analysis across Windows and Linuxenvironments. The ideal candidate will have hands-on experience with open-source and industrystandard DFIR tools, a strong understanding of operating system internals, and the ability todeliver detailed forensic and incident reports.

Key Responsibilities
  • Conduct compromise assessments to identify potential intrusions, persistencemechanisms, lateral movement, privilege escalation, and data exfiltration.
  • Conduct digital forensic investigations across Windows and Linux systems and environments.
  • Collect, preserve, and analyze digital evidence in accordance with established forensicbest practices
  • Correlate forensic findings with the MITRE ATT&CK framework to identify adversarytactics, techniques, and procedures (TTPs).
  • Leverage Threat Intelligence platforms to enrich investigations, validate Indicators ofCompromise (IOCs), and identify relevant threat actor activity.
  • Respond to security incidents, including ransomware attacks, data breaches,unauthorized access, and other cyber incidents.
  • Prepare comprehensive forensic and incident response reports covering technicalfindings, incident timelines, impact analysis, root-cause analysis, and remediationrecommendations.
  • Collaborate with SOC, Threat Hunting, IT, and other relevant teams to support the containment, eradication, and recovery of security incidents.
  • Contribute to the continuous improvement of DFIR processes, forensic capabilities, investigation methodologies, tools, and incident response playbooks.
Requirements
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or relatedfield (or equivalent experience)
  • 2 years of hands-on experience in digital forensics and/or incident response.
  • Strong understanding of:
    • o Windows and Linux OS internals and artifacts
    • o Network protocols, attack vectors, and adversary techniques
    • o File systems (NTFS, EXT4) and memory
  • Experience using and interpreting outputs from tools such as:
    • o Velociraptor, KAPE, EZ Tools (Eric Zimmerman), UAC, Log Analysis Tools, Volatility,etc.
  • Familiarity with threat intelligence, IOCs, and MITRE ATT&CK mapping.
  • Strong analytical and problem-solving skills with attention to detail.
  • Excellent written communication skills - ability to produce clear, technical investigationreports for both technical and non-technical audiences.
  • Ability to work under pressure and manage multiple cases in parallel.
Nice-to-Have
  • Certifications such as eCIR, CHFI, BTL1, etc.,
  • Experience with cloud forensics (AWS, Azure, GCP).
  • Familiarity with SIEM tools (Splunk, ELK, IBM QRadar) and endpoint telemetry.
  • Knowledge of PowerShell or Python scripting for automation.
  • Experience documenting and presenting case findings to clients or executive teams.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Investigator: Incident Response & Forensics
DFIR Investigator: Incident Response & Forensics

Trilliuminfosec • Lahore

On-site
PKR 1,200,000 - 2,400,000
Cybersecurity Support Engineer
Cybersecurity Support Engineer

Trilliuminfosec • Saddar

On-site
PKR 1,200,000 - 1,800,000
Cybersecurity Support Engineer
Cybersecurity Support Engineer

TISS • Saddar

On-site
PKR 1,339,000 - 2,009,000
Business Manager - Cybersecurity Solutions
Business Manager - Cybersecurity Solutions

Trilliuminfosec • Karachi Division

On-site
PKR 1,800,000 - 3,600,000
Cybersecurity Support Engineer - XDR/EDR & DLP Expert
Cybersecurity Support Engineer - XDR/EDR & DLP Expert

TISS • Saddar

On-site
PKR 1,339,000 - 2,009,000
Cyber Fusion Center Specialist
Cyber Fusion Center Specialist

HBL People • Pakistan

On-site
PKR 600,000 - 900,000
Cybersecurity Support Engineer: Endpoint & XDR
Cybersecurity Support Engineer: Endpoint & XDR

Trilliuminfosec • Saddar

On-site
PKR 1,200,000 - 1,800,000
Cyber Security Research Specialist
Cyber Security Research Specialist

HBL • Karachi Division

On-site
PKR 1,800,000 - 2,800,000
Cyber Security Research Specialist
Cyber Security Research Specialist

HBL People • Pakistan

On-site
PKR 2,500,000 - 6,500,000
Cybersecurity Support Engineer - Endpoint & XDR Specialist
Cybersecurity Support Engineer - Endpoint & XDR Specialist

Trillium Information Security Systems • Rawalpindi Cantonment

On-site
PKR 1,116,000 - 2,009,000