Senior DFIR Analyst & Incident Response Lead

Socket.dev

United States

On-site

USD 108,000 - 130,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
Paid holidays and sick time
Parental leave

Job summary

SentinelOne is seeking a Senior DFIR Analyst to act as technical lead on breach response investigations for a 24x7x365 team. You will own case evidence and documentation, partnering with the Engagement Manager on scoping, strategy, and customer communications.

Bring depth across endpoint, network, and cloud forensics and threat hunting. Ideal candidates have 4+ years in digital forensics and incident response, proficiency with X-Ways, Axiom, FTK, and SIEMs, and strong scripting in Python.

Qualifications

  • Bachelor's or Master's in Digital Forensics, Cybersecurity, Computer Science, or related field.
  • 4+ years of hands-on DFIR, incident response, or threat hunting experience.
  • Proven lead or technical contributor on complex breach responses.
  • Comfort analyzing Windows, Linux, and macOS environments.
  • Expert-level with forensic tools: X-Ways, Axiom, FTK.

Responsibilities

  • Lead DFIR engagements and guide analytical focus with client expectations.
  • Gather initial technical details and assess scope during intake.
  • Perform EDR-driven IR and cloud/network forensics.
  • Develop containment and remediation guidance per attack pattern.
  • Prepare thorough, defensible investigative reports and documentation.

Skills

4+ years DFIR
Lead breach responses
Windows/Linux/macOS
Forensic tools
EDR/XDR experience
Cloud IR
Python scripting

Education

Bachelor's or Master's in Digital Forensics/Cybersecurity/CS

Tools

X-Ways Forensics
Axiom
FTK
SentinelOne EDR/XDR
SIEMs

Job description

SentinelOne is seeking a Senior DFIR Analyst to act as technical lead on breach response investigations for a 24x7x365 team. You will own case evidence and documentation, partnering with the Engagement Manager on scoping, strategy, and customer communications.

Bring depth across endpoint, network, and cloud forensics and threat hunting. Ideal candidates have 4+ years in digital forensics and incident response, proficiency with X-Ways, Axiom, FTK, and SIEMs, and strong scripting in Python.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DFIR Lead — Incident Response & Forensics
Senior DFIR Lead — Incident Response & Forensics

SentinelOne • United States

On-site
USD 108,000 - 130,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+2
Senior DFIR Lead — Incident Response & Forensics
Senior DFIR Lead — Incident Response & Forensics

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+3
Senior DFIR Analyst – Incident Response & Forensics
Senior DFIR Analyst – Incident Response & Forensics

SentinelOne • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+6
Lead DFIR Analyst – 24/7 Incident Response
Lead DFIR Analyst – 24/7 Incident Response

Socket.dev • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+4
Senior DFIR Incident Response Lead
Senior DFIR Incident Response Lead

Forensic Focus Limited • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Sr. DFIR Analyst
Sr. DFIR Analyst

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+3
Sr. DFIR Analyst
Sr. DFIR Analyst

Socket.dev • United States

On-site
USD 108,000 - 130,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+2
DFIR Analyst
DFIR Analyst

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 120,000
RSUs
Employee Stock Purchase Plan (ESPP)
Flexible time off
+6
Senior DFIR Lead – Incident Response & Forensics Expert
Senior DFIR Lead – Incident Response & Forensics Expert

Trustwave • United States

Hybrid
USD 110,000 - 160,000
Comprehensive medical, dental, and vis
401(k) with employer matching
Generous paid time off and holidays
+4
DFIR Analyst
DFIR Analyst

Socket.dev • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+4