Digital Forensics and Incident Response (DFIR) Specialist

Zoho

United States

On-site

USD 140,000 - 210,000

Part time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Fyerx is seeking an experienced DFIR Specialist to lead post-breach investigations, containment lifecycles, and digital forensics operations. You will isolate compromised systems, perform disk and memory analyses, reconstruct attack timelines, and preserve legally admissible evidence to help the business recover from advanced cyber incidents.

Required: 5–8 years in cybersecurity with at least 4 years in post-breach assessments; strong command of EnCase, FTK, Volatility, and X-Ways Forensics;

Qualifications

  • 5–8 years of core cybersecurity experience, with 4+ dedicated years in post-breach digital forensics.
  • Strong mastery of advanced forensic software environments and memory/disk analysis.
  • Deep understanding of file systems, logs, and malware persistence mechanics.
  • Mandatory GCFA, GCIH, or CCE certifications.

Responsibilities

  • Lead high-severity incident response lifecycles across global networks.
  • Perform deep digital forensic investigations on live and image data.
  • Reconstruct complex threat timelines and C2 patterns.
  • Enforce strict chain-of-custody data preservation per standards.
  • Analyze malware behavior and translate findings into IOIs and reports.
  • Author runbooks and reports for legal and executive stakeholders.
  • Collaborate with GRC and legal teams on breach notifications.

Skills

Post-breach investigations
Threat hunting
Evidence preservation
Chain-of-custody
Forensic reporting

Education

GCFA
GCIH
CCE

Tools

EnCase
FTK
Volatility
X-Ways Forensics

Job description

Digital Forensics and Incident Response (DFIR) Specialist

Digital Forensics and Incident Response (DFIR) Specialist

  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 5 to 8 years
  • Relevant Experience Required: 4+ years of dedicated experience conducting digital forensics investigations and deep incident response execution
  • Mandatory Certification: GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), or Certified Computer Examiner (CCE)
Job Summary

We are seeking an experienced DFIR Specialist to lead our post-breach investigation pipelines, threat containment lifecycles, and digital forensics operations. The ideal candidate will isolate compromised systems, perform low-level disk and memory trace analyses, reconstruct complex attack timelines, and preserve legally admissible digital evidence to help the business understand and recover from advanced cyber incidents.

Key Responsibilities

  • Direct high-severity incident response lifecycles, spearheading rapid threat hunting sweeps, system isolations, and malicious compromise containment operations across the global network.
  • Perform deep digital forensic investigations, analyzing live volatile host memory dumps, master file tables (MFT), system registries, and volatile kernel memory layers.
  • Reconstruct chronological threat attack timelines, tracing advanced persistence methods, command-and-control (C2) callback patterns, lateral network movements, and data exfiltration markers.
  • Enforce rigid chain-of-custody data preservation parameters, collecting digital image snapshots of target drives and network captures in compliance with international legal and evidentiary standards.
  • Analyze complex malware behaviors and payload scripts, reverse engineering malicious scripts, unpacking obfuscated code loops, and translating findings into actionable local indicator blocks (IOCs).
  • Author detailed forensic investigation runbooks and expert reports, presenting clear summaries of breach roots, compromised asset matrices, data exposure volumes, and recovery steps to legal and executive stakeholders.
  • Collaborate with GRC and legal compliance teams, evaluating data breach notification requirements in accordance with corporate mandates and regional privacy laws (e.g., GDPR, HIPAA).
Requirements
  • 5 to 8 years of core cybersecurity systems engineering experience, with 4+ dedicated years actively running complex post-breach digital forensic track assessments.
  • Strong technical mastery of advanced forensic software environments (e.g., EnCase, FTK, Volatility, X-Ways Forensics), memory acquisition tools, and packet analysis suites.
  • Deep structural understanding of file system layout matrices (NTFS, EXT4, FAT), operating system log architectures, network layer packet capture parsing, and malware persistence mechanics.
  • Mandatory certification: GCFA, GCIH, or CCE.
Preferred Qualifications
  • Prior experience dealing with ransomware negotiations or navigating high-stakes ransomware containment events under tight timeline expectations.
  • Scripting background in Python or Perl used to build custom string searching queries or parse non-standard database application trace files.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Unix/Linux Infrastructure Forensics & Incident Engineer
Unix/Linux Infrastructure Forensics & Incident Engineer

Canvendor • San Jose (CA)

On-site
USD 120,000 - 180,000
Unix/Linux Infrastructure Forensics & Incident Engineer
Unix/Linux Infrastructure Forensics & Incident Engineer

Hallmark Global Technologies Limited • San Jose (CA)

On-site
USD 180,000 - 240,000
Digital Forensic Specialist
Digital Forensic Specialist

ALLTECH CONSULTING SVC INC • Troy (MI)

On-site
USD 60,000 - 110,000
Senior Digital Forensics and Incident Response (DFIR) Consultant
Senior Digital Forensics and Incident Response (DFIR) Consultant

Forensic Focus • Miami (FL), Northern (KY)

Hybrid
USD 123,000 - 179,000
Incident Responder
Incident Responder

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Incident Response & DFIR Lead
Incident Response & DFIR Lead

Greenhouse Software, Inc. • United States

Remote
USD 120,000 - 210,000
Vacation days
Sick leave
Public holidays
+5
Senior Cyber Forensic Analyst
Senior Cyber Forensic Analyst

ShorePoint • Albuquerque (NM)

On-site
USD 110,000 - 190,000
PTO 144 hours
11 holidays
Health insurance coverage (85% Premium
+2
Senior Digital Forensics and Incident Response Analyst
Senior Digital Forensics and Incident Response Analyst

SentinelOne, Inc. • United States

On-site
USD 140,000 - 210,000
Medical, dental, and vision coverage
Employee assistance program
Gym reimbursement
+4
Digital Forensics Analyst
Digital Forensics Analyst

Forensic Focus Limited • Alexandria (VA), Northern (KY)

On-site
USD 120,000 - 180,000
Digital Forensics Senior Analyst at Gulfstream Savannah, GA
Digital Forensics Senior Analyst at Gulfstream Savannah, GA

Gulfstream • Savannah (GA)

On-site
USD 90,000 - 120,000