- We’re looking for people who are relentlessly curious and committed to continuous learning
- AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts
- Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes
- As a Senior DFIR Analyst, you will be tasked with serving as technical lead on small to medium-sized breach response investigations for SentinelOne’s 24x7x365, follow-the-sun DFIR team
- You’ll own case-level evidence and documentation quality end-to-end, partnering closely with an Engagement Manager on scoping, case strategy, and customer communications, and bringing strong, well-rounded technical depth across threat hunting and endpoint, network, and cloud forensics
- Serve as technical lead on DFIR engagements, directing analytical focus and partnering with the Engagement Manager to align technical work with scope and client expectations
- Support case intake by gathering initial technical details and assessing scope
- Conduct EDR-driven incident response and vendor-agnostic advanced forensic analysis spanning endpoint, network, cloud, and SaaS environments (including ransomware, business email compromise, identity compromise, and other common incident types)
- Develop tactical containment guidance and remediation recommendations tailored to each engagement’s specific attack pattern
- Contribute observed attacker techniques and indicators to the team’s shared knowledge base
- Acquire and preserve forensic evidence from endpoint, network, and cloud sources following standard chain-of-custody procedures, with clear, thorough case documentation throughout each investigation
- Support the preparation and delivery of interim status updates and deliverables
- Own evidence handling, documentation standards, and the accuracy and quality of formal investigative reports for assigned engagements, ensuring findings are defensible, well-supported, and peer-reviewed before reaching a customer, breach counsel, or other stakeholder
- Lead case handovers for assigned engagements, ensuring a complete, clear transfer of status when work moves across regions
- Mentor Analysts on technical methodology, evidence handling, and investigative best practices
- Manage triage and analysis in high-pressure, large-scale incidents, maintaining composure and clear decision-making
- Build or improve scripts, tooling, and internal processes — including AI-assisted approaches where useful — to streamline recurring forensic, analysis, and reporting workflows
- Escalate scope, resourcing, or customer relationship concerns to the EM promptly, while owning technical escalations directly
- Track hours for investigations accurately and in a timely fashion
- Participate in a rotating on-call schedule for weekends and holidays, to support active incident response
- Maintain awareness of emerging threats, attacker techniques, and evolving cybersecurity trends
Benefits
- Medical, dental, and vision coverage
- Employee assistance program
- Gym reimbursement
- Incentive-based challenges
- Mental health and mindfulness
- Unlimited Time Off
- Grandparent Leave
- Volunteer Time Off
- Paid Sick Time
- Paid Holidays
- 16 weeks Gender-Neutral Parental Leave
- Restricted Stock Unit Program
- Flexible Spending Accounts
- Life Insurance
- Short and Long Term Disability Insurance
- 401K
- Team building activities
- Celebrations and social gatherings
- Community volunteering events
- Global all hands and local town hall events
Strong understanding of network protocols, network security architecture, and network-based forensic analysisExperience conducting endpoint-based threat hunting (compromise assessments)Scripting ability (Python preferred), with experience automating investigative or analysis tasks4+ years of hands-on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environmentStrong experience with EDR/XDR platforms (SentinelOne preferred) and SIEMsComfort analyzing Windows, Linux, and macOS environmentsAn evident self-starter with intellectual curiosity and the ability to adapt to changeComfort communicating findings to a range of stakeholders, including customer technical teams, executives, and legal counselDemonstrated ability to write clear, evidence-backed findings and reason through ambiguous or incomplete data in writingExperience conducting dynamic malware analysis and solid understanding of the reverse engineering processDemonstrated experience serving as a lead or technical contributor on complex breach response engagements, capable of working independently with minimal guidanceBachelor’s or Master’s degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field (or equivalent practical self-study)Working knowledge of cloud incident response methodology across at least one major provider (AWS, Azure, or GCP)Expert-level experience with forensic investigative tools such as X-Ways Forensics, Axiom, and FTK