DFIR

Lever, Inc.

United States

Remote

USD 70,000 - 100,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Lever, Inc. is seeking a digital forensics and incident response (DFIR) professional to join the frontline of cybersecurity. You will participate in hands-on security research and investigations, helping clients detect and mitigate cyber threats.

The role emphasizes incident response lifecycle, cloud forensics, threat hunting, and close collaboration with in-house red team, CTI, and cyber architect teams across worldwide clients.

Qualifications

  • Must be based in the Central or Eastern regions of the US
  • 1-2 years of experience as a DFIR team member
  • Experience with performing digital forensics in a cloud environment
  • Experience with performing digital forensics of Windows-based and/or Linux-based platforms, network forensics, and analysis
  • Thorough understanding of threat hunting models, as well as cyber threat intelligence, including TTP and IoCs extraction and mapping
  • Experience with research and data analysis of large DBs via Splunk, Elasticsearch, SQL, or VQL
  • Strong understanding of targeted attacks; able to create customized tactical remediation plans
  • Good written and verbal English communication skills

Responsibilities

  • Perform incident response lifecycle and real-time activities, including detection and analysis, containment and eradication, and recovery
  • Perform incident response in a cloud environment (Azure, AWS etc.).
  • Perform digital forensics investigations
  • Research and analyze tactics, techniques, and procedures (TTPs) used by malicious actors
  • Perform hunt-evil and find-evil activities for proactively detecting attacks
  • Work closely with our in-house red team, CTI, and cyber architect teams
  • Work closely with worldwide companies, CISOs, and technology experts

Skills

DFIR
Cloud forensics
Threat hunting
Windows forensics
Linux forensics
English communication

Tools

Azure
AWS
Splunk
Elasticsearch
SQL
VQL

Job description

Cye's DFIR team is responsible for responding to our clients' cyber incidents and crises.

Our group is expanding. If you see yourself in the front line of the cybersecurity domain as a digital forensic and incident response (DFIR) talent, your place is with us. As a DFIR team member, you will participate in hands-on security research and investigations, helping our customers understand and mitigate cyber threats and attacks.

Responsibilities
  • Perform incident response lifecycle and real-time activities, including detection and analysis, containment and eradication, and recovery
  • Perform incident response in a cloud environment (Azure, AWS etc.).
  • Perform digital forensics investigations
  • Research and analyze tactics, techniques, and procedures (TTPs) used by malicious actors
  • Perform hunt-evil and find-evil activities for proactively detecting attacks
  • Work closely with our in-house red team, CTI, and cyber architect teams
  • Work closely with worldwide companies, CISOs, and technology experts
Qualifications
  • Must be based in the Central or Eastern regions of the US
  • 1-2 years of experience as a DFIR team member
  • Experience with performing digital forensics in a cloud environment
  • Experience with performing digital forensics of Windows-based and/or Linux-based platforms, network forensics, and analysis
  • Thorough understanding of threat hunting models, as well as cyber threat intelligence, including TTP and IoCs extraction and mapping
  • Experience with research and data analysis of large DBs via Splunk, Elasticsearch, SQL, or VQL
  • Strong understanding of targeted attacks; able to create customized tactical remediation plans
  • Good written and verbal English communication skills

Cye helps security and risk leaders gain a clear, defensible view of their cyber exposure, grounded in financial impact and real-world attack paths. By continuously quantifying exposure and validating it in context, organizations can establish a strong baseline, prioritize decisions with confidence, and track measurable reduction over time.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DFIR
DFIR

Cye • United States

On-site
USD 65,000 - 110,000
DFIR Investigator: Cloud Incident Response & Forensics
DFIR Investigator: Cloud Incident Response & Forensics

Cye • United States

On-site
USD 65,000 - 110,000
Senior Engineer, Cybersecurity DFIR
Senior Engineer, Cybersecurity DFIR

ICE • Jacksonville (FL)

On-site
USD 100,000 - 120,000
Senior Digital Forensics and Incident Response (DFIR) Consultant
Senior Digital Forensics and Incident Response (DFIR) Consultant

Forensic Focus • Miami (FL), Northern (KY)

Hybrid
USD 123,000 - 179,000
DFIR Investigator: Cloud Forensics & Threat Hunting
DFIR Investigator: Cloud Forensics & Threat Hunting

Lever, Inc. • United States

Remote
USD 70,000 - 100,000
Remote DFIR Lead: Incident Response & Forensics
Remote DFIR Lead: Incident Response & Forensics

Zoho • United States

Remote
USD 140,000 - 210,000
Sr. Cyber Consultant, DFIR
Sr. Cyber Consultant, DFIR

LevelBlue • United States

Hybrid
USD 110,000 - 150,000
Comprehensive health insurance
401(k) with employer matching
Generous PTO and holidays
+4
Senior DFIR Specialist: Incident Response & Forensics
Senior DFIR Specialist: Incident Response & Forensics

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 90,000 - 140,000
Comprehensive medical, dental, and视ion
401(k) with employer matching
Generous paid time off and holidays
+4
DFIR Cybersecurity Analyst - Incident Response & Forensics
DFIR Cybersecurity Analyst - Incident Response & Forensics

Columbia University Information Technology • New York (NY)

On-site
USD 80,000 - 110,000
DFIR Investigator: Cyber Incident Response & Forensics
DFIR Investigator: Cyber Incident Response & Forensics

Minerva Cyber Tech • Columbia (MD)

On-site
USD 85,000 - 120,000