DFIR

Cye

United States

On-site

USD 65,000 - 110,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Cye's DFIR team is expanding, inviting hands-on security researchers to join frontline investigations and incident response. You will be solving complex cyber incidents for clients, with emphasis on rapid detection, containment, and recovery across cloud and on-premises environments.

As a DFIR teammate, you will conduct cloud-focused forensics in Azure and AWS, investigate Windows and Linux systems, study TTPs and IoCs, and perform proactive threat hunting.

Qualifications

  • 1-2 years of experience as a DFIR team member.
  • Experience with digital forensics in cloud environments.
  • Forensics across Windows and/or Linux, plus network forensics.
  • Strong understanding of threat hunting models and cyber threat intelligence (TTPs & IoCs).
  • Experience researching large databases using Splunk, Elasticsearch, SQL, or VQL.
  • Excellent written and verbal English communication.

Responsibilities

  • Perform incident response lifecycle activities: detection, containment, eradication, and recovery.
  • Perform incident response in a cloud environment (Azure, AWS etc.).
  • Perform digital forensics investigations.
  • Research and analyze tactics, techniques, and procedures (TTPs) used by malicious actors.
  • Perform hunt-evil and find-evil activities for proactively detecting attacks.
  • Work closely with our in-house red team, CTI, and cyber architect teams.
  • Work closely with worldwide companies, CISOs, and technology experts.

Skills

Incident response
Digital forensics
Threat hunting
Cloud forensics
Windows/Linux forensics
English communication

Tools

Splunk
Elasticsearch
SQL
VQL

Job description

Cye's DFIR team is responsible for responding to our clients' cyber incidents and crises.

Our group is expanding. If you see yourself in the front line of the cybersecurity domain as a digital forensic and incident response (DFIR) talent, your place is with us.As a DFIR team member, you will participate in hands-on security research and investigations, helping our customers understand and mitigate cyber threats and attacks.

  • Perform incident response lifecycle and real-time activities, including detection and analysis, containment and eradication, and recovery
  • Perform incident response in a cloud environment (Azure, AWS etc.).
  • Perform digital forensics investigations
  • Research and analyze tactics, techniques, and procedures (TTPs) used by malicious actors
  • Perform hunt-evil and find-evil activities for proactively detecting attacks
  • Work closely with our in-house red team, CTI, and cyber architect teams
  • Work closely with worldwide companies, CISOs, and technology experts
  • Must be based in the Central or Eastern regions of the US
  • 1-2 years of experience as a DFIR team member
  • Experience with performing digital forensics in a cloud environment
  • Experience with performing digital forensics of Windows-based and/or Linux-based platforms, network forensics, and analysis
  • Thorough understanding of threat hunting models, as well as cyber threat intelligence, including TTP and IoCs extraction and mapping
  • Experience with research and data analysis of large DBs via Splunk, Elasticsearch, SQL, or VQL
  • Strong understanding of targeted attacks; able to create customized tactical remediation plans
  • Good written and verbal English communication skills

Cye helps security and risk leaders gain a clear, defensible view of their cyber exposure, grounded in financial impact and real-world attack paths. By continuously quantifying exposure and validating it in context, organizations can establish a strong baseline, prioritize decisions with confidence, and track measurable reduction over time.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DFIR
DFIR

Lever, Inc. • United States

Remote
USD 70,000 - 100,000
DFIR Investigator: Cloud Incident Response & Forensics
DFIR Investigator: Cloud Incident Response & Forensics

Cye • United States

On-site
USD 65,000 - 110,000
Senior Digital Forensics and Incident Response (DFIR) Consultant
Senior Digital Forensics and Incident Response (DFIR) Consultant

Forensic Focus • Miami (FL), Northern (KY)

Hybrid
USD 123,000 - 179,000
Remote DFIR Lead: Incident Response & Forensics
Remote DFIR Lead: Incident Response & Forensics

Zoho • United States

Remote
USD 140,000 - 210,000
DFIR Investigator: Cloud Forensics & Threat Hunting
DFIR Investigator: Cloud Forensics & Threat Hunting

Lever, Inc. • United States

Remote
USD 70,000 - 100,000
Digital Forensics and Incident Response (DFIR) Specialist
Digital Forensics and Incident Response (DFIR) Specialist

Zoho • United States

On-site
USD 140,000 - 210,000
DFIR Analyst: Lead Incident Response & Forensics
DFIR Analyst: Lead Incident Response & Forensics

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 120,000
RSUs
Employee Stock Purchase Plan (ESPP)
Flexible time off
+6
Senior DFIR Specialist: Incident Response & Forensics
Senior DFIR Specialist: Incident Response & Forensics

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 90,000 - 140,000
Comprehensive medical, dental, and视ion
401(k) with employer matching
Generous paid time off and holidays
+4
Senior Engineer, Cybersecurity DFIR
Senior Engineer, Cybersecurity DFIR

ICE • Jacksonville (FL)

On-site
USD 100,000 - 120,000
Senior DFIR Lead – Incident Response and Forensics
Senior DFIR Lead – Incident Response and Forensics

LevelBlue • United States

Hybrid
USD 110,000 - 150,000
Comprehensive health insurance
401(k) with employer matching
Generous PTO and holidays
+4