Senior Digital Forensics and Incident Response Analyst

SentinelOne, Inc.

United States

On-site

USD 140,000 - 210,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision coverage
Employee assistance program
Gym reimbursement
Unlimited Time Off
Parental Leave 16 weeks
RSU program
401K

Job summary

SentinelOne, Inc. is seeking a Senior DFIR Analyst to lead breach investigations within our 24x7 DFIR team. You will own evidence handling, case documentation, and deliverables, coordinating with the Engagement Manager on scope and strategy.

You’ll apply threat hunting, endpoint, network, and cloud forensics skills to guide remediation, mentor analysts, and develop tooling to accelerate repeatable workflows. This role also involves on-call duties and client communication.

Qualifications

  • Bachelor's or Master's in Digital Forensics, Cybersecurity, Computer Science or related field.
  • 4+ years of hands-on experience in digital forensics, incident response, or threat hunting.
  • Strong experience with EDR/XDR platforms and SIEMs.
  • Comfort analyzing Windows, Linux, and macOS environments.
  • Experience leading breach response engagements.

Responsibilities

  • Serve as technical lead on DFIR engagements, directing analytical focus.
  • Own evidence handling, documentation standards, and investigative reports.
  • Lead case handovers and mentor Analysts on methodology.
  • Develop tactical containment guidance and remediation recommendations.
  • Build or improve scripts, tooling, and internal processes for repeatable workflows.

Skills

Network forensics
Threat hunting
EDR/XDR experience
Python scripting
Incident response
Forensic analysis

Education

Bachelor's or Master's in Digital Forensics/Cybersecurity/CS

Tools

X-Ways Forensics
Axiom
FTK
SentinelOne
SIEMs

Job description

  • We’re looking for people who are relentlessly curious and committed to continuous learning
  • AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts
  • Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes
  • As a Senior DFIR Analyst, you will be tasked with serving as technical lead on small to medium-sized breach response investigations for SentinelOne’s 24x7x365, follow-the-sun DFIR team
  • You’ll own case-level evidence and documentation quality end-to-end, partnering closely with an Engagement Manager on scoping, case strategy, and customer communications, and bringing strong, well-rounded technical depth across threat hunting and endpoint, network, and cloud forensics
  • Serve as technical lead on DFIR engagements, directing analytical focus and partnering with the Engagement Manager to align technical work with scope and client expectations
  • Support case intake by gathering initial technical details and assessing scope
  • Conduct EDR-driven incident response and vendor-agnostic advanced forensic analysis spanning endpoint, network, cloud, and SaaS environments (including ransomware, business email compromise, identity compromise, and other common incident types)
  • Develop tactical containment guidance and remediation recommendations tailored to each engagement’s specific attack pattern
  • Contribute observed attacker techniques and indicators to the team’s shared knowledge base
  • Acquire and preserve forensic evidence from endpoint, network, and cloud sources following standard chain-of-custody procedures, with clear, thorough case documentation throughout each investigation
  • Support the preparation and delivery of interim status updates and deliverables
  • Own evidence handling, documentation standards, and the accuracy and quality of formal investigative reports for assigned engagements, ensuring findings are defensible, well-supported, and peer-reviewed before reaching a customer, breach counsel, or other stakeholder
  • Lead case handovers for assigned engagements, ensuring a complete, clear transfer of status when work moves across regions
  • Mentor Analysts on technical methodology, evidence handling, and investigative best practices
  • Manage triage and analysis in high-pressure, large-scale incidents, maintaining composure and clear decision-making
  • Build or improve scripts, tooling, and internal processes — including AI-assisted approaches where useful — to streamline recurring forensic, analysis, and reporting workflows
  • Escalate scope, resourcing, or customer relationship concerns to the EM promptly, while owning technical escalations directly
  • Track hours for investigations accurately and in a timely fashion
  • Participate in a rotating on-call schedule for weekends and holidays, to support active incident response
  • Maintain awareness of emerging threats, attacker techniques, and evolving cybersecurity trends
Benefits
  • Medical, dental, and vision coverage
  • Employee assistance program
  • Gym reimbursement
  • Incentive-based challenges
  • Mental health and mindfulness
  • Unlimited Time Off
  • Grandparent Leave
  • Volunteer Time Off
  • Paid Sick Time
  • Paid Holidays
  • 16 weeks Gender-Neutral Parental Leave
  • Restricted Stock Unit Program
  • Flexible Spending Accounts
  • Life Insurance
  • Short and Long Term Disability Insurance
  • 401K
  • Team building activities
  • Celebrations and social gatherings
  • Community volunteering events
  • Global all hands and local town hall events

Strong understanding of network protocols, network security architecture, and network-based forensic analysisExperience conducting endpoint-based threat hunting (compromise assessments)Scripting ability (Python preferred), with experience automating investigative or analysis tasks4+ years of hands-on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environmentStrong experience with EDR/XDR platforms (SentinelOne preferred) and SIEMsComfort analyzing Windows, Linux, and macOS environmentsAn evident self-starter with intellectual curiosity and the ability to adapt to changeComfort communicating findings to a range of stakeholders, including customer technical teams, executives, and legal counselDemonstrated ability to write clear, evidence-backed findings and reason through ambiguous or incomplete data in writingExperience conducting dynamic malware analysis and solid understanding of the reverse engineering processDemonstrated experience serving as a lead or technical contributor on complex breach response engagements, capable of working independently with minimal guidanceBachelor’s or Master’s degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field (or equivalent practical self-study)Working knowledge of cloud incident response methodology across at least one major provider (AWS, Azure, or GCP)Expert-level experience with forensic investigative tools such as X-Ways Forensics, Axiom, and FTK

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. DFIR Analyst
Sr. DFIR Analyst

SentinelOne, Inc. • United States

Remote
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+2
DFIR Analyst
DFIR Analyst

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 120,000
RSUs
Employee Stock Purchase Plan (ESPP)
Flexible time off
+6
Sr. DFIR Analyst
Sr. DFIR Analyst

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+3
DFIR Analyst
DFIR Analyst

SentinelOne • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+6
Senior Threat Hunter
Senior Threat Hunter

SentinelOne • United States

On-site
USD 140,000 - 210,000
Medical cover
Assistance program
Gym reimbursement
+7
Senior DFIR Analyst – Incident Response & Forensics
Senior DFIR Analyst – Incident Response & Forensics

SentinelOne • United States

On-site
USD 108,000 - 120,000
RSUs
ESPP
Flexible time off
+6
Senior DFIR Lead — Incident Response & Forensics
Senior DFIR Lead — Incident Response & Forensics

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+3
DFIR Analyst: Lead Incident Response & Forensics
DFIR Analyst: Lead Incident Response & Forensics

Precision Labs • Northern (KY)

Hybrid
USD 108,000 - 120,000
RSUs
Employee Stock Purchase Plan (ESPP)
Flexible time off
+6
Senior DFIR Lead - Incident Response & Forensics
Senior DFIR Lead - Incident Response & Forensics

SentinelOne, Inc. • United States

Remote
USD 108,000 - 130,000
RSUs
ESPP
Flexible time off
+2
Senior DFIR Lead - AI-Driven Incident Response & Forensics
Senior DFIR Lead - AI-Driven Incident Response & Forensics

SentinelOne, Inc. • United States

On-site
USD 140,000 - 210,000
Medical, dental, and vision coverage
Employee assistance program
Gym reimbursement
+4