DFIR Analyst: Lead Incident Response & Forensics

Precision Labs

Northern (KY)

Hybrid

USD 108,000 - 120,000

Full time

12 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

RSUs
Employee Stock Purchase Plan (ESPP)
Flexible time off
Paid holidays & sick time
Parental leave
Health, dental, vision insurance
401(k) with company match
Life and disability insurance
FSA

Job summary

SentinelOne is seeking a DFIR Analyst to serve as technical lead on breach response investigations for our 24x7x365 DFIR team. You will own case evidence, documentation, and client communications, bringing depth across endpoint, network, and cloud forensics.

Ideal candidates have 4+ years in digital forensics, incident response, or threat hunting, and experience guiding engagements. The role requires scripting in Python and strong ability to communicate findings to diverse stakeholders.

Qualifications

  • Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related field (or equivalent practical self-study).
  • 4+ years of hands-on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environment.
  • Demonstrated experience serving as a lead or technical contributor on complex breach response engagements, capable of working independently with minimal guidance.

Responsibilities

  • Serve as technical lead on DFIR engagements, directing analytical focus and aligning work with scope and client expectations.
  • Support case intake by gathering initial technical details and assessing scope.
  • Conduct EDR-driven incident response and vendor-agnostic advanced forensic analysis spanning endpoint, network, cloud, and SaaS environments.
  • Develop tactical containment guidance and remediation recommendations tailored to each engagement's specific attack pattern.
  • Contribute observed attacker techniques and indicators to the team's shared knowledge base.
  • Acquire and preserve forensic evidence from endpoint, network, and cloud sources with clear case documentation.
  • Support the preparation and delivery of interim status updates and deliverables.
  • Own evidence handling, documentation standards, and the accuracy and quality of formal investigative reports.

Skills

Breach response
Threat hunting
Endpoint forensics
Communication with stakeholders
Self-starter / curiosity
Mentoring juniors
Cloud/incident response understanding
Scripting (Python)

Education

Bachelor's or Master's in Digital Forensics/Cybersecurity/CS

Tools

X-Ways Forensics
Axiom
FTK
EDR/XDR platforms
SIEMs
Python scripting

Job description

SentinelOne is seeking a DFIR Analyst to serve as technical lead on breach response investigations for our 24x7x365 DFIR team. You will own case evidence, documentation, and client communications, bringing depth across endpoint, network, and cloud forensics.

Ideal candidates have 4+ years in digital forensics, incident response, or threat hunting, and experience guiding engagements. The role requires scripting in Python and strong ability to communicate findings to diverse stakeholders.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DFIR Analyst & Incident Response Lead
Senior DFIR Analyst & Incident Response Lead

Socket.dev • United States

On-site
USD 108,000 - 130,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+2
Senior DFIR Lead — Incident Response & Forensics
Senior DFIR Lead — Incident Response & Forensics

SentinelOne • United States

On-site
USD 108,000 - 130,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+2
Senior DFIR Lead — Incident Response & Forensics
Senior DFIR Lead — Incident Response & Forensics

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+3
Senior DFIR Analyst – Incident Response & Forensics
Senior DFIR Analyst – Incident Response & Forensics

SentinelOne • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+6
Senior DFIR Incident Response Lead
Senior DFIR Incident Response Lead

Forensic Focus Limited • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Sr. DFIR Analyst
Sr. DFIR Analyst

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+3
Senior DFIR Consultant: Remote Incident Response
Senior DFIR Consultant: Remote Incident Response

Surefire Cyber Inc. • United States

On-site
USD 140,000 - 180,000
Remote workforce
Generous paid time off
Parental leave
+1
DFIR Analyst
DFIR Analyst

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 120,000
RSUs
Employee Stock Purchase Plan (ESPP)
Flexible time off
+6
Senior DFIR Investigator & Incident Response Leader
Senior DFIR Investigator & Incident Response Leader

Prescient Comply • Chicago (IL)

On-site
USD 80,000 - 110,000
DFIR Analyst
DFIR Analyst

SentinelOne • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+6