DFIR Analyst

SentinelOne

Singapore

On-site

SGD 90,000 - 150,000

Full time

16 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

RSUs
ESPP
Leave benefits
Parental leave
Medical benefits
EAP
Home office allowance
Internet allowance
Mobile allowance
Flexible benefits

Job summary

SentinelOne in Singapore is seeking a forensics-focused incident responder with 2+ years in digital forensics, IR, or threat hunting. You will analyze Windows artifacts, preserve evidence, and support ransomware and identity compromise investigations.

You will work with X-Ways Forensics, Axiom, FTK, SentinelOne EDR/XDR and SIEM tools, and contribute to reports, recommendations, and knowledge sharing while maintaining rigorous chain-of-custody standards.

Qualifications

  • Bachelor’s or Master’s degree in Digital Forensics, Cybersecurity, Computer Science, or related field, or equivalent practical self‑study.
  • 2+ years of hands‑on experience in digital forensics, incident response, or threat hunting, ideally in consulting/services.
  • Comfort analyzing Windows environments and forensic artifacts; understanding of forensic methodologies and evidence handling.

Responsibilities

  • Conduct EDR-driven incident response and forensic analysis across endpoints, networks, and cloud environments.
  • Preserve forensic evidence with chain-of-custody procedures; assist case intake with initial technical details.
  • Support malware and memory analysis under senior guidance.
  • Contribute to containment actions and security hardening recommendations; document investigations thoroughly.
  • Prepare customer-facing status updates and investigative reports; distill findings for stakeholders.
  • Follow SOPs and escalate questions to Technical Lead or Engagement Manager as needed.
  • Maintain awareness of threats and attacker techniques; contribute to knowledge base.

Skills

Digital forensics
Incident response
Threat hunting
Windows forensics
Network protocols
Scripting & automation
Strong communication
Under pressure
Cloud exposure

Education

Bachelor's or Master's in Digital Forensics, Cybersecurity, CS

Tools

X-Ways Forensics
Axiom
FTK
EDR/XDR platforms
SIEMs

Job description

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.

About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real‑time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.

Our teams are builders, problem‑solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission‑driven people, we invite you to help us build a safer future for humanity.

What Are We Looking For?

We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.

What Will You Do?
  • Conduct EDR‑driven incident response and vendor‑agnostic forensic analysis spanning endpoint, network, cloud, and SaaS environments, including ransomware, business email compromise, identity compromise, and other common incident types.
  • Acquire and preserve forensic evidence from endpoint, network, and cloud sources following standard chain‑of‑custody procedures; support case intake by gathering initial technical details to assess scope.
  • Support malware and memory analysis tasks under the guidance of senior team members.
  • Support incident containment actions and prepare security hardening recommendations; maintain thorough case documentation throughout each investigation.
  • Contribute to customer‑facing status updates and formal investigative reports, distilling complex technical findings for stakeholders.
  • Follow standard operating procedures and elevate technical or logistical questions to the assigned Technical Lead or Engagement Manager as needed.
  • Maintain awareness of emerging threats, attacker techniques, and evolving cybersecurity trends; contribute observed attacker techniques and indicators to the team’s shared knowledge base.
  • Be responsive to high‑pressure triage and analysis during large‑scale cybersecurity incidents, maintaining composure; participate in a rotating on‑call schedule for weekends and holidays.
  • Support handovers of investigations across regions as needed.
What Skills and Knowledge Will You Bring?
  • Bachelor’s or Master’s degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field, or equivalent practical self‑study.
  • 2 or more years of hands‑on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environment.
  • Comfort analyzing Windows environments and forensic artifacts; foundational understanding of forensic methodologies, evidence handling, acquisition techniques, and chain‑of‑custody procedures.
  • Experience with forensic tools such as X‑Ways Forensics, Axiom, and FTK.
  • Experience with EDR/XDR platforms (SentinelOne preferred) and SIEMs.
  • Working knowledge of network protocols and network‑based forensic analysis; scripting and automation capabilities.
  • Strong verbal and written communication—comfortable documenting and presenting technical findings clearly and precisely.
  • Ability to perform technical investigations under pressure in high‑stakes, time‑sensitive situations, while maintaining composure; an evident self‑starter with intellectual curiosity and the ability to adapt to change.
  • Knowledge of Linux and macOS forensic analysis is preferred.
  • Exposure to cloud environments (AWS, Azure, GCP) and memory analysis is preferred.
Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI‑native platform designed to operate at machine speed, not as an add‑on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards
  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
Time Off & Wellbeing
  • Competitive leave benefits
  • Gender‑neutral parental leave
Insurance & Financial Security
  • Medical and insurance benefits
  • Employee Assistance Program (EAP)
Work Perks & Flexibility
  • Global home office allowance
  • Internet and mobile phone allowance
  • Flexible benefits allowance

SentinelOne is proud to be an Equal Employment Opportunity and affirmative action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Technical Success Manager - Prompt
Staff Technical Success Manager - Prompt

SentinelOne • Singapore

Hybrid
SGD 140,000 - 190,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Competitive leave benefits
+6
Breach Readiness Consultant
Breach Readiness Consultant

SentinelOne • Singapore

On-site
SGD 120,000 - 180,000
RSUs
ESPP
Competitive leave benefits
+6
Commercial Solutions Engineering Intern
Commercial Solutions Engineering Intern

SentinelOne • Singapore

On-site
1:1 mentorship
Hands‑on projects
Training and development opportunities
+3
Senior Recruiter
Senior Recruiter

SentinelOne • Singapore

On-site
SGD 120,000 - 180,000
Equity & RSUs
Employee Stock Purchase Plan (ESPP)
Competitive leave benefits
+3
Senior Director, Channel Sales APJ
Senior Director, Channel Sales APJ

SentinelOne • Singapore

Hybrid
SGD 180,000 - 260,000
RSUs
ESPP
Competitive leave
+6
Senior Consultant, Incident Response and Threat Hunting
Senior Consultant, Incident Response and Threat Hunting

Ensign InfoSecurity • Singapore

On-site
SGD 120,000 - 190,000
Senior Specialist, Incident Response
Senior Specialist, Incident Response

SITA Group • Singapore

Hybrid
SGD 120,000 - 180,000
Flex Work Options
Wellbeing Programs
Professional Development
+2
Senior Cyber Security Consultant
Senior Cyber Security Consultant

Singtel • Singapore

On-site
Confidential
DFIR Analyst: Incident Response & Forensics
DFIR Analyst: Incident Response & Forensics

SentinelOne • Singapore

On-site
SGD 90,000 - 150,000
RSUs
ESPP
Leave benefits
+7
Senior Security Analyst
Senior Security Analyst

SITA Group • Singapore

Hybrid
SGD 60,000 - 90,000
Work from home flexibility
Professional development
Diversity & Inclusion
+1