Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
AWS @ 4
Azure @ 4
GCP @ 4
Linux @ 4
Python @ 4
Scoping @ 7
Security @ 7
macOS @ 4
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
As a Senior DFIR Analyst, you will serve as the technical lead on small- to medium-sized breach response investigations for SentinelOne's 24x7x365, follow-the-sun DFIR team. You will own case-level evidence and documentation quality end to end, partner with an Engagement Manager on scoping, case strategy, and customer communications, and apply strong technical expertise across threat hunting and endpoint, network, and cloud forensics.
Responsibilities
- Serve as technical lead on DFIR engagements, directing analytical focus and partnering with the Engagement Manager to align technical work with scope and client expectations.
- Support case intake by gathering initial technical details and assessing scope.
- Conduct EDR-driven incident response and vendor-agnostic advanced forensic analysis across endpoint, network, cloud, and SaaS environments, including ransomware, business email compromise, identity compromise, and other common incident types.
- Develop tactical containment guidance and remediation recommendations tailored to each engagement's attack pattern.
- Contribute observed attacker techniques and indicators to the team's shared knowledge base.
- Acquire and preserve forensic evidence from endpoint, network, and cloud sources following standard chain-of-custody procedures, with clear and thorough case documentation.
- Support the preparation and delivery of interim status updates and deliverables.
- Own evidence handling, documentation standards, and the accuracy and quality of formal investigative reports, ensuring findings are defensible, well-supported, and peer-reviewed before reaching customers, breach counsel, or other stakeholders.
- Lead case handovers for assigned engagements, ensuring a complete and clear transfer of status across regions.
- Mentor analysts on technical methodology, evidence handling, and investigative best practices.
- Manage triage and analysis during high-pressure, large-scale incidents while maintaining composure and clear decision-making.
- Build or improve scripts, tooling, and internal processes, including AI-assisted approaches where useful, to streamline recurring forensic, analysis, and reporting workflows.
- Escalate scope, resourcing, or customer relationship concerns to the Engagement Manager promptly while owning technical escalations directly.
- Track investigation hours accurately and in a timely manner.
- Participate in a rotating on-call schedule for weekends and holidays to support active incident response.
- Maintain awareness of emerging threats, attacker techniques, and evolving cybersecurity trends.
Requirements
- Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field, or equivalent practical self-study.
- 4+ years of hands-on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environment.
- Experience serving as a lead or technical contributor on complex breach response engagements and working independently with minimal guidance.
- Experience analyzing Windows, Linux, and macOS environments.
- Expert-level experience with forensic investigative tools such as X-Ways Forensics, Axiom, and FTK.
- Strong experience with EDR/XDR platforms, preferably SentinelOne, and SIEMs.
- Strong understanding of network protocols, network security architecture, and network-based forensic analysis.
- Working knowledge of cloud incident response methodology across at least one major provider: AWS, Azure, or GCP.
- Experience conducting dynamic malware analysis and understanding of the reverse engineering process.
- Experience conducting endpoint-based threat hunting and compromise assessments.
- Scripting ability, preferably Python, with experience automating investigative or analysis tasks.
- Ability to write clear, evidence-backed findings and reason through ambiguous or incomplete data in writing.
- Ability to communicate findings to customer technical teams, executives, and legal counsel.
- Self-starter with intellectual curiosity and the ability to adapt to change.
Benefits
- Restricted Stock Units (RSUs)
- Employee Stock Purchase Plan (ESPP)
- Flexible time off
- Paid company holidays and paid sick time
- Gender-neutral parental leave and grandparent leave
- Medical, dental, and vision coverage
- 401(k) retirement plan with company match
- Life and disability insurance
- Health and dependent care FSA
- Voluntary benefits, including hospital, accident, and critical illness coverage
- Employee Assistance Program (EAP)
- ARAG pre-paid legal
- Nationwide pet insurance
- Cancer Care program
- Global business travel medical insurance
- Home office allowance
- Mobile phone reimbursement
- Wellness coach and wellness/gym reimbursement
- Fertility coverage
- Adoption and surrogacy reimbursement
This is a U.S. role. The base pay range varies based on the candidate's location, and a different pay range may apply in some locations. SentinelOne participates in the E-Verify Program for all U.S.-based roles.
More jobs at SentinelOne
Threat Response Advisor
SentinelOne · United States
USD 108,000-130,000 per year
DFIR Analyst
SentinelOne · United States
USD 108,000-120,000 per year
Senior Threat Hunter
SentinelOne · United States
USD 108,000-130,000 per year
Application Security Consultant
SentinelOne · United States
USD 132,000-160,000 per year
Engagement Manager
SentinelOne · United States
USD 132,000-160,000 per year
Similar jobs
Member of Technical Staff (Offensive Security Engineer)
Perplexity AI · Serbia, United States, London, United Kingdom, New York City, United States, San Francisco, United States
USD 220,000-405,000 per year
Security Engineer, Offensive Security
Anthropic · New York City, United States, San Francisco, United States
USD 300,000-320,000 per year
Staff+ Software Engineer, Infrastructure (Distributed Systems)
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-485,000 per year
Staff+ Software Engineer, Claude App Infrastructure
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-485,000 per year
Principal Site Reliability Engineer
Nvidia · Santa Clara, United States
USD 248,000-396,800 per year
Senior Engineer System Software, SDN Operations
Nvidia · Santa Clara, United States
USD 184,000-287,500 per year
Staff Backend Software Engineer, Agent Platform
SentinelOne · United States
USD 156,000-215,000 per year
Senior Systems Software Engineer, Kubernetes Node Lifecycle - DGX Cloud
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year