DFIR Analyst

USD 108,000-120,000 per year
SENIOR
✅ Remote

Tech Stack

AI AWS @ 4 Azure @ 4 GCP @ 4 Linux @ 4 Python @ 4 Security @ 7 macOS @ 4

Details

Role Overview

As a DFIR Analyst, you will serve as the technical lead on small- to medium-sized breach response investigations for SentinelOne's 24x7x365, follow-the-sun DFIR team. You will own case-level evidence and documentation quality end-to-end, partner closely with an Engagement Manager on scoping, case strategy, and customer communications, and apply technical expertise across threat hunting and endpoint, network, and cloud forensics.

Responsibilities

  • Serve as technical lead on DFIR engagements, directing analytical focus and partnering with the Engagement Manager to align technical work with scope and client expectations.
  • Support case intake by gathering initial technical details and assessing scope.
  • Conduct EDR-driven incident response and vendor-agnostic advanced forensic analysis across endpoint, network, cloud, and SaaS environments, including ransomware, business email compromise, identity compromise, and other common incident types.
  • Develop tactical containment guidance and remediation recommendations tailored to each engagement's attack pattern.
  • Contribute observed attacker techniques and indicators to the team's shared knowledge base.
  • Acquire and preserve forensic evidence from endpoint, network, and cloud sources using standard chain-of-custody procedures, with clear and thorough case documentation.
  • Support the preparation and delivery of interim status updates and deliverables.
  • Own evidence handling, documentation standards, and the accuracy and quality of formal investigative reports for assigned engagements.
  • Ensure findings are defensible, well-supported, and peer-reviewed before reaching customers, breach counsel, or other stakeholders.
  • Lead case handovers for assigned engagements, ensuring a complete and clear transfer of status across regions.
  • Mentor Analysts on technical methodology, evidence handling, and investigative best practices.
  • Manage triage and analysis during high-pressure, large-scale incidents while maintaining composure and clear decision-making.
  • Build or improve scripts, tooling, and internal processes, including AI-assisted approaches where useful, to streamline forensic, analysis, and reporting workflows.
  • Escalate scope, resourcing, or customer relationship concerns to the Engagement Manager promptly while owning technical escalations directly.
  • Track investigation hours accurately and in a timely manner.
  • Participate in a rotating on-call schedule for weekends and holidays to support active incident response.
  • Maintain awareness of emerging threats, attacker techniques, and evolving cybersecurity trends.

Requirements

  • Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field, or equivalent practical self-study.
  • 4+ years of hands-on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environment.
  • Experience serving as a lead or technical contributor on complex breach response engagements and working independently with minimal guidance.
  • Experience analyzing Windows, Linux, and macOS environments.
  • Expert-level experience with forensic investigative tools such as X-Ways Forensics, Axiom, and FTK.
  • Strong experience with EDR/XDR platforms, preferably SentinelOne, and SIEMs.
  • Strong understanding of network protocols, network security architecture, and network-based forensic analysis.
  • Working knowledge of cloud incident response methodology across at least one major provider: AWS, Azure, or GCP.
  • Experience conducting dynamic malware analysis and a solid understanding of the reverse engineering process.
  • Experience conducting endpoint-based threat hunting and compromise assessments.
  • Scripting ability, preferably Python, with experience automating investigative or analysis tasks.
  • Ability to write clear, evidence-backed findings and reason through ambiguous or incomplete data in writing.
  • Ability to communicate findings to customer technical teams, executives, and legal counsel.
  • Self-starter with intellectual curiosity and the ability to adapt to change.

On-Call Requirements

Participation in a rotating on-call schedule for weekends and holidays is required.

Benefits

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave and grandparent leave
  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary hospital, accident, and critical illness benefits
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance
  • Home office allowance
  • Mobile phone reimbursement
  • Wellness coach and wellness/gym reimbursement
  • Fertility coverage
  • Adoption and surrogacy reimbursement

Compensation

The U.S. base salary range is $108,000–$120,000 USD. The range may vary based on the candidate's location, and a different range may apply in some locations.

More jobs at SentinelOne

Similar jobs