Senior DFIR Analyst – Incident Response & Forensics

SentinelOne

United States

On-site

USD 108,000 - 120,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

RSUs
ESPP
Flexible time off
Paid holidays and sick time
Medical, dental, and vision coverage
401(k) with company match
Home office allowance
Mobile phone reimbursement
Wellness coaching

Job summary

SentinelOne is seeking a DFIR Analyst to serve as the technical lead on breach response investigations within our 24x7x365 DFIR team. You will own evidence handling, case documentation, and deliverables, collaborating with the Engagement Manager on scoping, strategy, and client communications.

The role requires 4+ years of hands-on digital forensics, incident response, or threat hunting, with strong expertise in Windows/Linux/macOS, X-Ways Forensics, Axiom, FTK, and SentinelOne/E DR platforms.

Qualifications

  • Lead or technical contributor on breach response engagements.
  • Comfort analyzing Windows, Linux, and macOS environments.
  • Expert-level experience with forensic tools (X-Ways, Axiom, FTK).
  • Strong experience with EDR/XDR platforms and SIEMs.
  • Knowledge of network protocols and network forensic analysis.
  • Cloud incident response across AWS/Azure/GCP.
  • Malware analysis and reverse engineering basics.
  • Endpoint-based threat hunting experience.
  • Scripting ability (Python).
  • Clear, evidence-backed reporting and written findings.
  • Ability to communicate findings to technical and non-technical stakeholders.
  • Self-starter with curiosity and adaptability.

Responsibilities

  • Serve as technical lead on DFIR engagements and align work with client expectations.
  • Assist with case intake and scoping.
  • Conduct incident response and forensic analysis across endpoints, network, cloud, and SaaS.
  • Provide containment guidance and remediation recommendations.
  • Contribute techniques and indicators to team knowledge base.
  • Preserve forensic evidence with proper chain of custody and thorough documentation.
  • Prepare interim updates and final investigative reports.
  • Lead case handovers and mentor junior analysts.
  • Improve tooling and processes with automation and AI-assisted approaches.
  • Escalate scope or resource concerns to the Engagement Manager.

Skills

Technical leadership
Cross-platform analysis
Forensic tools
EDR/XDR & SIEM
Network forensics
Cloud forensics
Malware analysis
Threat hunting
Python scripting
Reporting/written communication
Stakeholder communication
Self-motivation

Education

Bachelor's or Master's in Digital Forensics, Cybersecurity, CS

Tools

X-Ways Forensics
Axiom
FTK
SentinelOne
SIEMs

Job description

SentinelOne is seeking a DFIR Analyst to serve as the technical lead on breach response investigations within our 24x7x365 DFIR team. You will own evidence handling, case documentation, and deliverables, collaborating with the Engagement Manager on scoping, strategy, and client communications.

The role requires 4+ years of hands-on digital forensics, incident response, or threat hunting, with strong expertise in Windows/Linux/macOS, X-Ways Forensics, Axiom, FTK, and SentinelOne/E DR platforms.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead DFIR Analyst – 24/7 Incident Response
Lead DFIR Analyst – 24/7 Incident Response

Socket.dev • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+4
Senior DFIR Incident Response Lead
Senior DFIR Incident Response Lead

Forensic Focus Limited • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior DFIR Lead – Incident Response & Forensics Expert
Senior DFIR Lead – Incident Response & Forensics Expert

Trustwave • United States

Hybrid
USD 110,000 - 160,000
Comprehensive medical, dental, and vis
401(k) with employer matching
Generous paid time off and holidays
+4
Senior DFIR Lead: Incident Response & Forensics
Senior DFIR Lead: Incident Response & Forensics

LevelBlue • United States

Hybrid
USD 120,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+6
DFIR Analyst
DFIR Analyst

Socket.dev • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+4
DFIR Analyst
DFIR Analyst

SentinelOne • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+6
Senior DFIR Investigator & Incident Response Leader
Senior DFIR Investigator & Incident Response Leader

Prescient Comply • Chicago (IL)

On-site
USD 80,000 - 110,000
Senior DFIR Consultant: Remote Incident Response
Senior DFIR Consultant: Remote Incident Response

Surefire Cyber Inc. • United States

On-site
USD 140,000 - 180,000
Remote workforce
Generous paid time off
Parental leave
+1
Remote Director, Digital Forensics & Incident Response
Remote Director, Digital Forensics & Incident Response

Surefire Cyber Inc. • United States

On-site
USD 185,000 - 200,000
Remote work
Senior DFIR Consultant: Remote Incident Response
Senior DFIR Consultant: Remote Incident Response

Surefire Cyber Inc. • Northern (KY)

Hybrid
USD 110,000 - 160,000
Competitive compensation
Equity in company
Generous paid time off
+4