Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
AWS @ 4
Azure @ 4
GCP @ 4
Linux @ 4
Python @ 4
Security @ 7
macOS @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Role Overview
As a DFIR Analyst, you will serve as the technical lead on small- to medium-sized breach response investigations for SentinelOne's 24x7x365, follow-the-sun DFIR team. You will own case-level evidence and documentation quality end-to-end, partner closely with an Engagement Manager on scoping, case strategy, and customer communications, and apply technical expertise across threat hunting and endpoint, network, and cloud forensics.
Responsibilities
- Serve as technical lead on DFIR engagements, directing analytical focus and partnering with the Engagement Manager to align technical work with scope and client expectations.
- Support case intake by gathering initial technical details and assessing scope.
- Conduct EDR-driven incident response and vendor-agnostic advanced forensic analysis across endpoint, network, cloud, and SaaS environments, including ransomware, business email compromise, identity compromise, and other common incident types.
- Develop tactical containment guidance and remediation recommendations tailored to each engagement's attack pattern.
- Contribute observed attacker techniques and indicators to the team's shared knowledge base.
- Acquire and preserve forensic evidence from endpoint, network, and cloud sources using standard chain-of-custody procedures, with clear and thorough case documentation.
- Support the preparation and delivery of interim status updates and deliverables.
- Own evidence handling, documentation standards, and the accuracy and quality of formal investigative reports for assigned engagements.
- Ensure findings are defensible, well-supported, and peer-reviewed before reaching customers, breach counsel, or other stakeholders.
- Lead case handovers for assigned engagements, ensuring a complete and clear transfer of status across regions.
- Mentor Analysts on technical methodology, evidence handling, and investigative best practices.
- Manage triage and analysis during high-pressure, large-scale incidents while maintaining composure and clear decision-making.
- Build or improve scripts, tooling, and internal processes, including AI-assisted approaches where useful, to streamline forensic, analysis, and reporting workflows.
- Escalate scope, resourcing, or customer relationship concerns to the Engagement Manager promptly while owning technical escalations directly.
- Track investigation hours accurately and in a timely manner.
- Participate in a rotating on-call schedule for weekends and holidays to support active incident response.
- Maintain awareness of emerging threats, attacker techniques, and evolving cybersecurity trends.
Requirements
- Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field, or equivalent practical self-study.
- 4+ years of hands-on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environment.
- Experience serving as a lead or technical contributor on complex breach response engagements and working independently with minimal guidance.
- Experience analyzing Windows, Linux, and macOS environments.
- Expert-level experience with forensic investigative tools such as X-Ways Forensics, Axiom, and FTK.
- Strong experience with EDR/XDR platforms, preferably SentinelOne, and SIEMs.
- Strong understanding of network protocols, network security architecture, and network-based forensic analysis.
- Working knowledge of cloud incident response methodology across at least one major provider: AWS, Azure, or GCP.
- Experience conducting dynamic malware analysis and a solid understanding of the reverse engineering process.
- Experience conducting endpoint-based threat hunting and compromise assessments.
- Scripting ability, preferably Python, with experience automating investigative or analysis tasks.
- Ability to write clear, evidence-backed findings and reason through ambiguous or incomplete data in writing.
- Ability to communicate findings to customer technical teams, executives, and legal counsel.
- Self-starter with intellectual curiosity and the ability to adapt to change.
On-Call Requirements
Participation in a rotating on-call schedule for weekends and holidays is required.
Benefits
- Restricted Stock Units (RSUs)
- Employee Stock Purchase Plan (ESPP)
- Flexible time off
- Paid company holidays and paid sick time
- Gender-neutral parental leave and grandparent leave
- Medical, dental, and vision coverage
- 401(k) retirement plan with company match
- Life and disability insurance
- Health and dependent care FSA
- Voluntary hospital, accident, and critical illness benefits
- Employee Assistance Program (EAP)
- ARAG pre-paid legal
- Nationwide pet insurance
- Cancer Care program
- Global business travel medical insurance
- Home office allowance
- Mobile phone reimbursement
- Wellness coach and wellness/gym reimbursement
- Fertility coverage
- Adoption and surrogacy reimbursement
Compensation
The U.S. base salary range is $108,000–$120,000 USD. The range may vary based on the candidate's location, and a different range may apply in some locations.
More jobs at SentinelOne
Senior Threat Hunter
SentinelOne · United States
USD 108,000-130,000 per year
Application Security Consultant
SentinelOne · United States
USD 132,000-160,000 per year
Engagement Manager
SentinelOne · United States
USD 132,000-160,000 per year
Senior Staff Forward Deployed Engineer, AI
SentinelOne · United States
USD 184,000-253,000 per year
Staff Forward Deployed Engineer, AI
SentinelOne · United States
USD 156,000-215,000 per year
Similar jobs
Member of Technical Staff (Offensive Security Engineer)
Perplexity AI · Serbia, United States, London, United Kingdom, New York City, United States, San Francisco, United States
USD 220,000-405,000 per year
Security Engineer, Offensive Security
Anthropic · New York City, United States, San Francisco, United States
USD 300,000-320,000 per year
Staff+ Software Engineer, Claude App Infrastructure
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-485,000 per year
Principal Site Reliability Engineer
Nvidia · Santa Clara, United States
USD 248,000-396,800 per year
Senior Engineer System Software, SDN Operations
Nvidia · Santa Clara, United States
USD 184,000-287,500 per year
Staff Backend Software Engineer, Agent Platform
SentinelOne · United States
USD 156,000-215,000 per year
Senior Systems Software Engineer, Kubernetes Node Lifecycle - DGX Cloud
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Staff Software Engineer - Databases SRE | Ireland | Remote
Grafana Labs · Germany, Spain, United Kingdom, Ireland, Sweden
EUR 117,600-141,100 per year