SonicJobs Logo
Left arrow iconBack to search

DFIR Specialist

Trillium Information Security Systems (TISS)
Posted 11 days ago, valid for 11 days
Salary

$100,000 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • We are seeking a Digital Forensics and Incident Response (DFIR) Analyst to join our Security Consultancy and Forensic team.
  • The role requires a Bachelor's degree in Computer Science or a related field, along with 2 years of hands-on experience in digital forensics or incident response.
  • Key responsibilities include conducting compromise assessments, digital forensic investigations, and preparing comprehensive incident response reports.
  • The ideal candidate should be proficient with DFIR tools, have a strong understanding of operating systems, and possess excellent analytical and communication skills.
  • The salary for this position is competitive and commensurate with experience.
About the Role

We are looking for a Digital Forensics and Incident Response (DFIR) Analyst to join our Security Consultancy and Forensic team. The DFIR Analyst will be responsible for conducting compromise assessments, incident response investigations, and forensic analysis across Windows and Linux environments. The ideal candidate will have hands-on experience with open-source and industrystandard DFIR tools, a strong understanding of operating system internals, and the ability to deliver detailed forensic and incident reports.

Key Responsibilities

• Conduct compromise assessments to identify potential intrusions, persistence mechanisms, lateral movement, privilege escalation, and data exfiltration.
• Conduct digital forensic investigations across Windows and Linux systems and environments.
• Collect, preserve, and analyze digital evidence in accordance with established forensic best practices
• Correlate forensic findings with the MITRE ATT&CK framework to identify adversary tactics, techniques, and procedures (TTPs).
• Leverage Threat Intelligence platforms to enrich investigations, validate Indicators of Compromise (IOCs), and identify relevant threat actor activity.
• Respond to security incidents, including ransomware attacks, data breaches, unauthorized access, and other cyber incidents.
• Prepare comprehensive forensic and incident response reports covering technical findings, incident timelines, impact analysis, root-cause analysis, and remediation recommendations.
• Collaborate with SOC, Threat Hunting, IT, and other relevant teams to support the containment, eradication, and recovery of security incidents.
• Contribute to the continuous improvement of DFIR processes, forensic capabilities, investigation methodologies, tools, and incident response playbooks.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or related field (or equivalent experience)
  • 2 years of hands-on experience in digital forensics and/or incident response.
  • Strong understanding of:
    o Windows and Linux OS internals and artifacts
    o Network protocols, attack vectors, and adversary techniques
    o File systems (NTFS, EXT4) and memory
  • Experience using and interpreting outputs from tools such as:
     o Velociraptor, KAPE, EZ Tools (Eric Zimmerman), UAC, Log Analysis Tools, Volatility, etc.
  • Familiarity with threat intelligence, IOCs, and MITRE ATT&CK mapping.
  • Strong analytical and problem-solving skills with attention to detail.
  • Excellent written communication skills - ability to produce clear, technical investigation reports for both technical and non-technical audiences.
  • Ability to work under pressure and manage multiple cases in parallel.
Nice-to-Have

• Certifications such as eCIR, CHFI, BTL1, etc.,
• Experience with cloud forensics (AWS, Azure, GCP).
• Familiarity with SIEM tools (Splunk, ELK, IBM QRadar) and endpoint telemetry.
• Knowledge of PowerShell or Python scripting for automation.
• Experience documenting and presenting case findings to clients or executive teams.





Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.