Senior DFIR Analyst

USD 108,000-130,000 per year
SENIOR
✅ Remote

Tech Stack

AI AWS @ 4 Azure @ 4 GCP @ 4 Linux @ 4 Python @ 4 Scoping @ 7 Security @ 7 macOS @ 4

Details

As a Senior DFIR Analyst, you will serve as the technical lead on small- to medium-sized breach response investigations for SentinelOne's 24x7x365, follow-the-sun DFIR team. You will own case-level evidence and documentation quality end to end, partner with an Engagement Manager on scoping, case strategy, and customer communications, and apply strong technical expertise across threat hunting and endpoint, network, and cloud forensics.

Responsibilities

  • Serve as technical lead on DFIR engagements, directing analytical focus and partnering with the Engagement Manager to align technical work with scope and client expectations.
  • Support case intake by gathering initial technical details and assessing scope.
  • Conduct EDR-driven incident response and vendor-agnostic advanced forensic analysis across endpoint, network, cloud, and SaaS environments, including ransomware, business email compromise, identity compromise, and other common incident types.
  • Develop tactical containment guidance and remediation recommendations tailored to each engagement's attack pattern.
  • Contribute observed attacker techniques and indicators to the team's shared knowledge base.
  • Acquire and preserve forensic evidence from endpoint, network, and cloud sources following standard chain-of-custody procedures, with clear and thorough case documentation.
  • Support the preparation and delivery of interim status updates and deliverables.
  • Own evidence handling, documentation standards, and the accuracy and quality of formal investigative reports, ensuring findings are defensible, well-supported, and peer-reviewed before reaching customers, breach counsel, or other stakeholders.
  • Lead case handovers for assigned engagements, ensuring a complete and clear transfer of status across regions.
  • Mentor analysts on technical methodology, evidence handling, and investigative best practices.
  • Manage triage and analysis during high-pressure, large-scale incidents while maintaining composure and clear decision-making.
  • Build or improve scripts, tooling, and internal processes, including AI-assisted approaches where useful, to streamline recurring forensic, analysis, and reporting workflows.
  • Escalate scope, resourcing, or customer relationship concerns to the Engagement Manager promptly while owning technical escalations directly.
  • Track investigation hours accurately and in a timely manner.
  • Participate in a rotating on-call schedule for weekends and holidays to support active incident response.
  • Maintain awareness of emerging threats, attacker techniques, and evolving cybersecurity trends.

Requirements

  • Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field, or equivalent practical self-study.
  • 4+ years of hands-on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environment.
  • Experience serving as a lead or technical contributor on complex breach response engagements and working independently with minimal guidance.
  • Experience analyzing Windows, Linux, and macOS environments.
  • Expert-level experience with forensic investigative tools such as X-Ways Forensics, Axiom, and FTK.
  • Strong experience with EDR/XDR platforms, preferably SentinelOne, and SIEMs.
  • Strong understanding of network protocols, network security architecture, and network-based forensic analysis.
  • Working knowledge of cloud incident response methodology across at least one major provider: AWS, Azure, or GCP.
  • Experience conducting dynamic malware analysis and understanding of the reverse engineering process.
  • Experience conducting endpoint-based threat hunting and compromise assessments.
  • Scripting ability, preferably Python, with experience automating investigative or analysis tasks.
  • Ability to write clear, evidence-backed findings and reason through ambiguous or incomplete data in writing.
  • Ability to communicate findings to customer technical teams, executives, and legal counsel.
  • Self-starter with intellectual curiosity and the ability to adapt to change.

Benefits

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave and grandparent leave
  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary benefits, including hospital, accident, and critical illness coverage
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance
  • Home office allowance
  • Mobile phone reimbursement
  • Wellness coach and wellness/gym reimbursement
  • Fertility coverage
  • Adoption and surrogacy reimbursement

This is a U.S. role. The base pay range varies based on the candidate's location, and a different pay range may apply in some locations. SentinelOne participates in the E-Verify Program for all U.S.-based roles.

More jobs at SentinelOne

Similar jobs