A complete application in a minute — tailored resume and cover letter, ready to send.
Forensic Focus Limited seeks an experienced DFIR analyst to lead and support incident response investigations across malware, ransomware, and APTs. The role covers endpoint, memory, disk, and cloud forensics, with proactive threat hunting and adversary emulation via purple team exercises.
You will develop and tune detections within SIEM and EDR platforms while collaborating across red and blue teams in a large, globally recognised organisation. US citizenship is required.
The analyst leads and supports incident response investigations covering malware, ransomware, and APTs, while conducting endpoint, memory, disk, and cloud forensics. Responsibilities also include proactive threat hunting, adversary emulation via purple team exercises, and developing and tuning detections within SIEM and EDR platforms.
Candidates should have experience with tools such as Volatility 3, FTK Imager, Velociraptor, Microsoft Sentinel, Splunk, CrowdStrike Falcon, and Microsoft Defender XDR. Familiarity with KQL, Sigma rules, YARA, PowerShell, Python, and the MITRE ATT&CK framework is strongly preferred alongside memory analysis and malware triage skills.
This role suits an experienced DFIR professional who thrives working across red and blue team boundaries, enjoys investigating real-world attacks, and wants to build detection and forensic capabilities within a large, globally recognised engineering organisation. US citizenship is required.