Digital Forensics Analyst

Forensic Focus Limited

Indianapolis (IN)

Hybrid

USD 90,000 - 130,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Forensic Focus Limited seeks an experienced DFIR analyst to lead and support incident response investigations across malware, ransomware, and APTs. The role covers endpoint, memory, disk, and cloud forensics, with proactive threat hunting and adversary emulation via purple team exercises.

You will develop and tune detections within SIEM and EDR platforms while collaborating across red and blue teams in a large, globally recognised organisation. US citizenship is required.

Qualifications

  • Experience with memory analysis and malware triage.
  • Familiarity with KQL, Sigma rules, YARA, PowerShell, Python.
  • Knowledge of the MITRE ATT&CK framework.

Responsibilities

  • Lead and support incident response investigations covering malware, ransomware, and APTs.
  • Perform endpoint, memory, disk, and cloud forensics.
  • Develop and tune detections within SIEM and EDR platforms.

Skills

Incident response
DFIR
Threat hunting
Purple team
Forensic analysis

Tools

Volatility 3
FTK Imager
Velociraptor
Microsoft Sentinel
Splunk
CrowdStrike Falcon
Microsoft Defender XDR

Job description

The Role

The analyst leads and supports incident response investigations covering malware, ransomware, and APTs, while conducting endpoint, memory, disk, and cloud forensics. Responsibilities also include proactive threat hunting, adversary emulation via purple team exercises, and developing and tuning detections within SIEM and EDR platforms.

Skills & Experience

Candidates should have experience with tools such as Volatility 3, FTK Imager, Velociraptor, Microsoft Sentinel, Splunk, CrowdStrike Falcon, and Microsoft Defender XDR. Familiarity with KQL, Sigma rules, YARA, PowerShell, Python, and the MITRE ATT&CK framework is strongly preferred alongside memory analysis and malware triage skills.

Who It Suits

This role suits an experienced DFIR professional who thrives working across red and blue team boundaries, enjoys investigating real-world attacks, and wants to build detection and forensic capabilities within a large, globally recognised engineering organisation. US citizenship is required.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

Forensic Focus Limited • Indianapolis (IN)

Hybrid
USD 90,000 - 130,000
Digital Forensics Analyst
Digital Forensics Analyst

Forensic Focus Limited • Alexandria (VA), Northern (KY)

Hybrid
USD 120,000 - 180,000
Digital Forensic Specialist
Digital Forensic Specialist

ALLTECH CONSULTING SVC INC • Troy (MI)

On-site
USD 60,000 - 110,000
Digital Forensics Analyst
Digital Forensics Analyst

Weiatech, LLC • Tysons (VA)

On-site
USD 70,000 - 90,000
Digital Forensics Analyst
Digital Forensics Analyst

SAIC • Chantilly (VA)

On-site
USD 100,000 - 130,000
Cyber Data Forensics Analyst
Cyber Data Forensics Analyst

Yugal Tech Academy • Town of Texas (WI)

On-site
USD 70,000 - 90,000
Cyber Data Forensics Analyst
Cyber Data Forensics Analyst

Yugal Tech Academy • South Carolina

On-site
USD 70,000 - 100,000
Cyber Forensic Specialist
Cyber Forensic Specialist

Accenture • Arlington (VA)

On-site
USD 90,000 - 120,000
Senior DFIR Lead – Incident Response & Forensics Expert
Senior DFIR Lead – Incident Response & Forensics Expert

Trustwave • United States

Hybrid
USD 110,000 - 160,000
Comprehensive medical, dental, and vis
401(k) with employer matching
Generous paid time off and holidays
+4
Digital Forensics & Incident Response Specialist
Digital Forensics & Incident Response Specialist

ALLTECH CONSULTING SVC INC • Troy (MI)

On-site
USD 60,000 - 110,000