DFIR Engineer - Vurke Inc

OpenTalent

United States

On-site

USD 120,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

OpenTalent is seeking a Senior DFIR Engineer to lead responses to advanced intrusions, perform forensic acquisition and analysis across disk, memory, cloud and mobile environments. You will reverse engineer malware, develop detections (YARA, signatures), hunt threats in SIEM/EDR (Splunk, Elastic, CrowdStrike), and build custom tooling in Python, PowerShell, Go.

The role requires 5+ years in DFIR with strong incident response and digital forensics, deep OS knowledge, and mentoring teammates while

Qualifications

  • 5+ years DFIR experience with strong incident response and digital forensics.
  • Deep OS internals knowledge across Windows, Linux and macOS.
  • Experience in malware reverse engineering and building detection rules.
  • Mentorship or team-lead responsibilities in security teams.

Responsibilities

  • Lead responses to advanced intrusions/APTs and insider threats.
  • Perform forensic acquisition & analysis across disk, memory, cloud and mobile.
  • Reverse engineer malware and develop detections (YARA, signatures).
  • Hunt threats and build detections in SIEM/EDR (Splunk, Elastic, CrowdStrike, etc.).
  • Develop custom tooling/scripts (Python, PowerShell, Go).
  • Mentor team and contribute to playbooks/runbooks.

Skills

DFIR expert
Windows OS internals
Linux OS internals
macOS OS internals
Mentorship
Python
PowerShell
Bash
Go

Tools

Volatility
X-Ways
Magnet AXIOM
GRR
IDA Pro
Ghidra
Zeek
Sysmon

Job description

Main responsibilities
  • Lead response to advanced intrusions/APTs, insider threats
  • Perform forensic acquisition & analysis (disk, memory, cloud, mobile)
  • Reverse engineer malware, develop detection rules (YARA, signatures)
  • Hunt threats, build detections in SIEM/EDR (Splunk, Elastic, CrowdStrike, etc.)
  • Develop custom tooling/scripts (Python, PowerShell, Go)
  • Mentor team, contribute playbooks/runbooks
Skills & Experience
  • 5+ years DFIR - Must be strong in BOTH Digital Forensice & Incident Response
  • Deep OS internals (Windows, Linux, macOS), network protocols, cloud security
  • Volatility, X-Ways, Magnet AXIOM, GRR, IDA Pro, Ghidra, Zeek, Sysmon
  • Strong scripting/programming (Python, PowerShell, Bash, Go)
  • Preferred certs: GCFA, GNFA, GREM, OSCP/OSEE

Originally posted on Himalayas

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DFIR Engineer: Threat Hunting, Forensics & IR Tools
Senior DFIR Engineer: Threat Hunting, Forensics & IR Tools

OpenTalent • United States

On-site
USD 120,000 - 190,000
Digital Forensics Analyst
Digital Forensics Analyst

Forensic Focus Limited • Indianapolis (IN)

Hybrid
USD 90,000 - 130,000
DFIR Engineer II - Incident Response - northwesternmutual
DFIR Engineer II - Incident Response - northwesternmutual

OpenTalent • Milwaukee (WI)

On-site
USD 110,000 - 140,000
Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

Forensic Focus Limited • Indianapolis (IN)

Hybrid
USD 90,000 - 130,000
Senior Cyber Incident Response and Digital Forensics Lead
Senior Cyber Incident Response and Digital Forensics Lead

Jobtailor • Colorado

On-site
USD 140,000 - 190,000
Digital Forensics and Incident Analyst
Digital Forensics and Incident Analyst

Jobtailor • Washington

On-site
USD 120,000 - 180,000
Digital Forensic Specialist
Digital Forensic Specialist

ALLTECH CONSULTING SVC INC • Troy (MI)

On-site
USD 60,000 - 110,000
Senior DFIR Engineer - Remote UK (Forensics & IR)
Senior DFIR Engineer - Remote UK (Forensics & IR)

OpenTalent • United States

On-site
USD 88,000 - 128,000
Detection Engineer - Threat Hunter
Detection Engineer - Threat Hunter

ECS Corporate Services • Arlington (VA)

Hybrid
USD 170,000 - 190,000
Top Secret Clearance
Digital Forensic / Incident Response - Lead
Digital Forensic / Incident Response - Lead

AntietamTechnologies • Maryland

Hybrid
USD 180,000 - 240,000