Principal DFIR Consultant

Moxfive LLC
    • Autofill and Review
    6 days ago

    Job Description

    Who We Are

    If you feel like Incident Response and Recovery hasnt changed in the past 10 years, youre not alone. Business operations arent just on endpoints anymore. Its behind applications in Okta tiles, auto-scaling workloads, code repos, and sprawling data stores across one or many public clouds. At MOXFIVE, were focused on eradicating adversaries across our clients entire digital footprint, and that demands a faster, nimbler approach to DFIR, one where AI-driven tooling helps our consultants investigate faster without cutting corners on rigor.

    Were looking to expand our IR Consulting Team with individuals driven to protect clients, eliminate threat actors, and build the next era of digital forensics and incident response for the modern enterprise, including the LLM-based investigative platform were building to get them there.

    Who You Are

    You know that $I30 isnt referring to your local interstate, and that the easiest way to get on your bad side is to be handed a timestamp that isnt in UTC. Youve got a "Tools" folder sitting on your workstation somewhere with your favorite forensic scripts at the ready to tear into the next piece of suspicious activity you see. And speaking of suspicious activity, youve honed a keen sense for knowing the difference between legitimate users and threat actor activity because youve seen them in action. Hundreds of times.

    Windows environment investigations feel like the back of your hand at this point, and youve been starting to expand your knowledge on cloud-native forensics. Account takeovers are the new malware after all, and investigating the latest threats across Azure, GCP, AWS, and SaaS Apps is the growing frontier youve been looking to sink your teeth into. You know your way around CloudTrail and GuardDuty findings in AWS, Admin Activity and Data Access logs in GCP, and sign-in and audit logs in Entra ID, and youre just as comfortable chasing a rogue service principal or a suspicious Workload Identity Federation grant as you are pulling apart a $MFT.

    Youve also got an eye toward where the work is heading. Youre not afraid to put LLMs and AI tooling to work as part of the investigative process, whether thats rapidly triaging thousands of authentication logs for anomalous patterns, building timeline narratives faster without sacrificing accuracy, or using AI-assisted tooling to spot the needle in a haystack of cloud audit logs. You know these tools augment a sharp analyst, they dont replace one, and you hold the output to the same evidentiary standard youd hold your own analysis to. And you dont just want to be a consumer of that tooling. You want a hand in building it, translating what you know about how a real investigation actually unfolds into the logic, prompts, and guardrails of an LLM-based investigative platform that can eventually help the next analyst move faster than you did.

    Youre insatiably curious, addicted to threat intel, and a builder at heart. Ultimately, youre looking for the right opportunity that uses your technical chops to find and eliminate meaningful adversaries while putting your stamp on a better approach to traditional DFIR consulting.

    Why You Matter

    Youll be joining a seasoned team of high performing incident response consultants that are the tip of the spear for all forensic activity at MOXFIVE. From ransomware to nation-state threats, youll be supporting and leading meaningful cases across traditional enterprise and cloud-native environments, including multi-cloud intrusions spanning AWS, GCP, and Azure where the adversary is living off cloud-native identity and API abuse rather than dropping malware on disk. Your voice has significant weight in shaping our technology stack, investigative methodology, and service offerings as we continue to scale, including how we responsibly build LLM-driven capabilities into the investigative workflow itself. You wont just be a user of that platform. Your casework, your instincts for what matters in an investigation, and your judgment calls in the field will directly shape how its built, so that the methodology baked into the tooling reflects the same rigor you bring to a report.

    What Youll Bring

    • Experience responding to threat activity as an IR consultant or SOC analyst

    • Strong understanding of Windows/Mac/Linux fundamentals, forensic artifacts, and network analysis

    • Existing knowledge or passion to learn cloud-native investigations across AWS, GCP, and Azure, including familiarity with core log sources like CloudTrail, VPC Flow Logs, GCP Admin Activity/Data Access logs, and Entra ID/M365 audit logs

    • Curiosity about how LLMs and AI-assisted tooling can accelerate investigation and reporting without compromising forensic rigor, and interest in helping shape an internal LLM-based investigative platform built to accelerate future casework

    • An unwavering emphasis on investigation at the highest level of quality

    Numbers & Facts

    Location

    Skills

    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Apple Macsunmatched
    • Application Programming Interface (API)unmatched
    • Artificial Intelligence (AI)unmatched
    • Authenticationunmatched
    • Autoscalingunmatched
    • Business Operationsunmatched
    • Cloud Computingunmatched
    • Computer Forensicsunmatched
    • Computer Workstationsunmatched
    • Consultingunmatched
    • Core Loggingunmatched
    • Forensic Scienceunmatched
    • GCP (Good Clinical Practices)unmatched
    • IR (Infrared)unmatched
    • Identity Federationunmatched
    • Incident Responseunmatched
    • Intel Product Familyunmatched
    • Investigative Reportsunmatched
    • Linux Operating Systemunmatched
    • Machine Toolunmatched
    • Malwareunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Windows Operating Systemunmatched
    • Network Performance/Analysisunmatched
    • Public Cloudunmatched
    • Ransomwareunmatched
    • Scripting (Scripting Languages)unmatched
    • Software as a Service (SaaS)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder