Global DFIR Analyst — 24/7 Incident Response

SentinelOne

Poland

On-site

PLN 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

RSUs
ESPP
Competitive leave benefits
Gender-neutral parental leave
Medical and insurance benefits
Pension scheme
Global home office allowance
Mobile phone allowance
Wellness benefit

Job summary

SentinelOne is seeking a DFIR Analyst to deliver rapid breach response for global enterprises, conducting hands-on forensic analysis, threat hunting, and investigations across endpoint, network, and cloud environments on a follow-the-sun model.

The role emphasizes evidence-backed conclusions, thorough documentation, and the ability to distill findings for stakeholders, with weekend on-call rotation and opportunities to contribute to the knowledge base.

Qualifications

  • Bachelor's or master's in Digital Forensics, Cybersecurity, Computer Science, or related field, or equivalent practical self-study.
  • 2+ years hands-on experience in digital forensics, incident response, or threat hunting.
  • Experience with Windows forensic artifacts and chain-of-custody procedures.
  • Familiarity with memory analysis and cloud environments (AWS/Azure/GCP) is preferred.
  • Certifications such as GCFE/GCFA/GREM/CFCE/EnCE are a plus.

Responsibilities

  • Conduct EDR-driven incident response and forensic analysis across endpoint, network, cloud, and SaaS environments.
  • Support malware and memory analysis tasks.
  • Collect and preserve forensic evidence following chain-of-custody procedures.
  • Document case intake, scope, containment actions and hardening recommendations.
  • Maintain thorough case documentation and conduct clear investigative reporting.

Skills

Scripting and automation
Stress under pressure
Strong communication
Evidence-based analysis
Team collaboration

Education

Bachelor's or Master's in Digital Forensics/Cybersecurity/CS

Tools

X-Ways Forensics
Axiom
FTK
EDR/XDR platforms
SIEMs

Job description

SentinelOne is seeking a DFIR Analyst to deliver rapid breach response for global enterprises, conducting hands-on forensic analysis, threat hunting, and investigations across endpoint, network, and cloud environments on a follow-the-sun model.

The role emphasizes evidence-backed conclusions, thorough documentation, and the ability to distill findings for stakeholders, with weekend on-call rotation and opportunities to contribute to the knowledge base.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Analyst
DFIR Analyst

SentinelOne • Poland

On-site
PLN 120,000 - 180,000
RSUs
ESPP
Competitive leave benefits
+6
Senior Incident Response Leader — 24/7 Detection
Senior Incident Response Leader — 24/7 Detection

Linuxconfig • Warszawa

On-site
PLN 280,000 - 420,000
Senior Incident Response Lead - 24/7 Security Operations
Senior Incident Response Lead - 24/7 Security Operations

Dun & Bradstreet • Warszawa

On-site
PLN 280,000 - 420,000
Security Incident Response Analyst – Defender XDR Expert
Security Incident Response Analyst – Defender XDR Expert

DS Smith • Kraków

On-site
PLN 100,000 - 150,000
Hybrid Cyber Incident Response Lead
Hybrid Cyber Incident Response Lead

Accenture Poland • Warszawa

Hybrid
PLN 200,000 - 280,000
Remote MDR Sentinel Expert — Cloud Security & SIEM
Remote MDR Sentinel Expert — Cloud Security & SIEM

SoftwareONE Deutschland GmbH • Warszawa

Hybrid
PLN 190,000 - 270,000
Global culture
Mentor program
President's Club
+2
Remote MDR Analyst — Threat Hunting & Incident Response
Remote MDR Analyst — Threat Hunting & Incident Response

Jobs Paloaltonetworks • Warszawa

On-site
PLN 120,000 - 180,000
SOC Analyst L1/L2 - Frontline Security Investigator
SOC Analyst L1/L2 - Frontline Security Investigator

UnderDefense LLC • Warszawa

On-site
PLN 120,000 - 180,000
NOC & Incident Response Specialist — Remote, 24/7
NOC & Incident Response Specialist — Remote, 24/7

DEV • Wrocław

Hybrid
PLN 120,000 - 180,000
Security training
24/7 shift coverage
Remote-friendly Europe
Cyber Incident Response Lead
Cyber Incident Response Lead

Euroclear • Poland

Hybrid
PLN 180,000 - 260,000
Competitive benefits
Hybrid work model