DFIR / Digital Forensics & Incident Response Analyst
Location: Remote
Duration: 1–2 Weeks
Position Overview
We are seeking a skilled DFIR / Digital Forensics & Incident Response Analyst to investigate and respond to cybersecurity incidents from initial detection through containment, eradication, and recovery.
The role combines digital forensic investigation, incident response, endpoint analysis, threat investigation, and root-cause analysis. The ideal candidate will have hands-on experience investigating compromised endpoints and servers, analyzing security telemetry, identifying attacker activity, and coordinating remediation efforts.
Key Responsibilities
Investigate cybersecurity incidents from initial detection through remediation.
Perform forensic analysis of endpoints, servers, and compromised systems.
Collect, preserve, and analyze digital evidence using established forensic procedures.
Analyze:
Security and system logs
Network traffic
Malware and malicious artifacts
Endpoint activity
Memory
Filesystem and system artifacts
Identify attack vectors, persistence mechanisms, indicators of compromise (IOCs), and attacker activity.
Develop detailed incident timelines to reconstruct security events.
Perform root-cause analysis and determine the scope and impact of incidents.
Support threat hunting and investigative activities.
Coordinate containment, eradication, and recovery activities with security and infrastructure teams.
Document investigative procedures, findings, timelines, and remediation recommendations.
Communicate technical findings and incident status to relevant stakeholders.
Required Technical Skills
SIEM & Security Analytics
Splunk
Microsoft Sentinel
IBM QRadar
Endpoint Detection & Response
CrowdStrike
Microsoft Defender
SentinelOne
Digital Forensics & Network Analysis
Wireshark
Volatility
FTK
EnCase
Magnet AXIOM
Security Frameworks & Scripting
MITRE ATT&CK
Python
PowerShell
Windows and Linux security/forensics
Required Qualifications
Proven experience in Digital Forensics and Incident Response (DFIR).
Hands-on experience investigating cybersecurity incidents and compromised systems.
Strong endpoint and server forensic analysis skills.
Experience collecting, preserving, and analyzing digital evidence.
Strong understanding of network traffic, endpoint telemetry, malware behavior, and attack techniques.
Experience identifying IOCs, attack vectors, and persistence mechanisms.
Ability to perform incident timeline development and root-cause analysis.
Experience supporting incident containment, eradication, and recovery.
Strong analytical, documentation, and communication skills.
Ability to work independently in a remote environment.
Numbers & Facts
Location
Philadelphia, PA (Remote)
Skills
Analysis Skillsunmatched
Communication Skillsunmatched
Computer Forensicsunmatched
Documentationunmatched
EnCaseunmatched
File Systemsunmatched
Forensic Scienceunmatched
Huntingunmatched
IBM Product Familyunmatched
Incident Responseunmatched
Internet Securityunmatched
Malwareunmatched
Memory Hardwareunmatched
Microsoft Product Familyunmatched
Procedure Developmentunmatched
Python Programming/Scripting Languageunmatched
Root Cause Analysisunmatched
Security Analysisunmatched
Security Attacksunmatched
Security Infrastructureunmatched
Splunkunmatched
Telemetryunmatched
Windows PowerShellunmatched
Wireshark (Ethereal)unmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.