Lead DFIR Analyst – 24/7 Incident Response

Socket.dev

United States

On-site

USD 108,000 - 120,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

RSUs
ESPP
Flexible time off
Paid holidays
Health insurance
401(k) match
Home office allowance

Job summary

SentinelOne is seeking a DFIR Analyst to lead breach response investigations for a 24x7x365 team. You will own evidence and documentation quality end-to-end, partner with the Engagement Manager on scoping and communications, and bring depth across endpoint, network, and cloud forensics.

Ideal candidates have 4+ years in digital forensics, incident response, or threat hunting, and strong scripting abilities.

Qualifications

  • Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science or equivalent.
  • 4+ years of hands-on experience in digital forensics, incident response or threat hunting.
  • Experience leading breach response engagements and working independently.
  • Comfort analyzing Windows, Linux, and macOS environments.
  • Expert-level with forensic tools such as X-Ways Forensics, Axiom, FTK.

Responsibilities

  • Serve as technical lead on DFIR engagements and align work with client expectations.
  • Support case intake, gather technical details, and assess scope.
  • Conduct EDR-driven incident response and cloud/network/endpoint forensics.
  • Develop containment guidance and remediation recommendations.
  • Acquire and preserve forensic evidence following chain-of-custody.
  • Prepare interim updates and final investigative reports for stakeholders.
  • Lead case handovers, mentor junior analysts, and manage high-pressure incidents.
  • Build scripts and tooling to streamline forensic workflows.

Skills

Digital forensics
Incident response
Threat hunting
Python scripting
Evidence handling

Education

Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science

Tools

X-Ways Forensics
Axiom
FTK
EDR/XDR platforms
SIEMs

Job description

SentinelOne is seeking a DFIR Analyst to lead breach response investigations for a 24x7x365 team. You will own evidence and documentation quality end-to-end, partner with the Engagement Manager on scoping and communications, and bring depth across endpoint, network, and cloud forensics.

Ideal candidates have 4+ years in digital forensics, incident response, or threat hunting, and strong scripting abilities.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DFIR Engagement Lead: Cybersecurity Incident Response
DFIR Engagement Lead: Cybersecurity Incident Response

Socket.dev • United States

On-site
USD 132,000 - 160,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Medical/dental/vision coverage
+1
Senior DFIR Incident Response Lead
Senior DFIR Incident Response Lead

Forensic Focus Limited • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior DFIR Lead – Incident Response & Forensics Expert
Senior DFIR Lead – Incident Response & Forensics Expert

Trustwave • United States

Hybrid
USD 110,000 - 160,000
Comprehensive medical, dental, and vis
401(k) with employer matching
Generous paid time off and holidays
+4
Senior DFIR Investigator & Incident Response Leader
Senior DFIR Investigator & Incident Response Leader

Prescient Comply • Chicago (IL)

On-site
USD 80,000 - 110,000
Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

Forensic Focus Limited • Indianapolis (IN)

Hybrid
USD 90,000 - 130,000
Senior DFIR Engineer: Threat Hunting, Forensics & IR Tools
Senior DFIR Engineer: Threat Hunting, Forensics & IR Tools

OpenTalent • United States

On-site
USD 120,000 - 190,000
Senior DFIR Consultant: Remote Incident Response
Senior DFIR Consultant: Remote Incident Response

Surefire Cyber Inc. • United States

On-site
USD 140,000 - 180,000
Remote workforce
Generous paid time off
Parental leave
+1
Senior DFIR Lead: Incident Response & Forensics
Senior DFIR Lead: Incident Response & Forensics

LevelBlue • United States

Hybrid
USD 120,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+6
Senior DFIR Lead: Incident Response & Digital Forensics
Senior DFIR Lead: Incident Response & Digital Forensics

LevelBlue, LLC. • Northern (KY)

Hybrid
USD 90,000 - 130,000
Medical, dental, vision insurance
401(k) with employer matching
Paid time off and holidays
+4
Remote Director, Digital Forensics & Incident Response
Remote Director, Digital Forensics & Incident Response

Surefire Cyber Inc. • United States

On-site
USD 185,000 - 200,000
Remote work