Senior DFIR Lead — Incident Response & Forensics

Precision Labs

Northern (KY)

Hybrid

USD 108,000 - 130,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

RSUs
ESPP
Flexible time off
Paid holidays and sick time
Parental leave
Medical, dental, vision

Job summary

SentinelOne seeks a Senior DFIR Analyst to act as the technical lead on breach response investigations for 24x7x365 operations. You will own case evidence, strategy, and customer communications while applying deep threat hunting and endpoint, network, and cloud forensics.

You will mentor analysts, improve workflows, and ensure high-quality, defensible findings with clear documentation. This role requires strong scripting and collaboration across regions.

Qualifications

  • Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or related field (or equivalent practical self-study).
  • 4+ years hands-on experience in digital forensics, incident response, or threat hunting.
  • Experience leading complex breach response engagements and independent work.
  • Comfort with Windows, Linux, and macOS environments.
  • Expert-level with forensic tools like X-Ways Forensics, Axiom, FTK.
  • Strong EDR/XDR and SIEM experience.
  • Cloud incident response knowledge (AWS/Azure/GCP).
  • Scripting ability (Python preferred) for automation.
  • Clear, evidence-backed investigative reporting.

Responsibilities

  • Serve as technical lead on DFIR engagements and align work with scope and client expectations.
  • Support case intake by gathering initial technical details and assessing scope.
  • Conduct EDR-driven incident response and forensic analysis across endpoints, networks, and cloud services.
  • Develop tactical containment guidance and remediation tailored to each engagement.
  • Contribute attacker techniques to the knowledge base.
  • Acquire and preserve forensic evidence with proper chain-of-custody and documentation.
  • Prepare interim status updates and deliverables.
  • Own evidence handling and quality of investigative reports.

Skills

Digital forensics
Incident response
Threat hunting
Windows/Linux/macOS
Python scripting
Evidence handling
Communication to stakeholders

Education

Bachelor's or Master's in Digital Forensics/C Cybersecurity/CS

Tools

X-Ways Forensics
Axiom
FTK
EDR/XDR (SentinelOne)
SIEM

Job description

SentinelOne seeks a Senior DFIR Analyst to act as the technical lead on breach response investigations for 24x7x365 operations. You will own case evidence, strategy, and customer communications while applying deep threat hunting and endpoint, network, and cloud forensics.

You will mentor analysts, improve workflows, and ensure high-quality, defensible findings with clear documentation. This role requires strong scripting and collaboration across regions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DFIR Lead — Incident Response & Forensics
Senior DFIR Lead — Incident Response & Forensics

SentinelOne • United States

On-site
USD 108,000 - 130,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+2
Senior DFIR Analyst & Incident Response Lead
Senior DFIR Analyst & Incident Response Lead

Socket.dev • United States

On-site
USD 108,000 - 130,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+2
Senior DFIR Analyst – Incident Response & Forensics
Senior DFIR Analyst – Incident Response & Forensics

SentinelOne • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+6
Lead DFIR Analyst – 24/7 Incident Response
Lead DFIR Analyst – 24/7 Incident Response

Socket.dev • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+4
Senior DFIR Incident Response Lead
Senior DFIR Incident Response Lead

Forensic Focus Limited • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior DFIR Lead – Incident Response & Forensics Expert
Senior DFIR Lead – Incident Response & Forensics Expert

Trustwave • United States

Hybrid
USD 110,000 - 160,000
Comprehensive medical, dental, and vis
401(k) with employer matching
Generous paid time off and holidays
+4
Sr. DFIR Analyst
Sr. DFIR Analyst

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+3
Senior DFIR Consultant: Remote Incident Response
Senior DFIR Consultant: Remote Incident Response

Surefire Cyber Inc. • United States

On-site
USD 140,000 - 180,000
Remote workforce
Generous paid time off
Parental leave
+1
Sr. DFIR Analyst
Sr. DFIR Analyst

Socket.dev • United States

On-site
USD 108,000 - 130,000
Restricted Stock Units (RSUs)
Employee Stock Purchase Plan (ESPP)
Flexible time off
+2
Senior DFIR Consultant: Remote Incident Response
Senior DFIR Consultant: Remote Incident Response

Surefire Cyber Inc. • Northern (KY)

Hybrid
USD 110,000 - 160,000
Competitive compensation
Equity in company
Generous paid time off
+4