Lead breach response engagements with strategic direction and hands-on DFIR leadership
Deliver expert consulting across incident response, digital forensics, and cyber risk scenarios
Guide clients through complex incidents with tailored, high-impact solutions
Stay current on threat landscape, vulnerabilities, and attacker techniques (TTPs, persistence methods)
Perform and oversee forensic investigations (memory/disk acquisition, analysis) using specified tools
Manage client relationships, lead technical discussions, and run multiple engagements concurrently
Support business growth through client expansion and new opportunity identification
Benefits
Flexible remote working arrangements
Emphasis on a culture of trust, accountability, and shared success
Opportunities for professional growth and collaboration
Commitment to diversity and inclusion in the workplace
Support for reasonable accommodations for individuals with disabilities
Full Job Description
Job Summary
Summary Senior-level consulting role leading cybersecurity incident response and breach investigations for Unit 42 clients. Acts as both a strategic advisor and hands-on technical leader across industries and environments, driving outcomes on complex security incidents.
Key Responsibilities
Lead breach response engagements, providing both strategic direction and hands-on DFIR leadership
Deliver expert consulting across incident response, digital forensics, and cyber risk scenarios
Guide clients through complex incidents with tailored, high-impact solutions
Stay current on threat landscape, vulnerabilities, and attacker techniques (TTPs, persistence methods)
Perform and oversee forensic investigations (memory/disk acquisition, analysis) using tools like EnCase, FTK, Volatility
Manage client relationships, lead technical discussions, and run multiple engagements concurrently
Support business growth through client expansion (cross-sell/upsell) and new opportunity identification
Qualifications
Required Qualifications
10+ years of DFIR consulting experience (breach response, investigations)
Proven leadership of technical incident response teams in high-pressure environments
Deep expertise in forensic methodologies (chain of custody, disk/memory analysis)
Hands-on experience with tools: EnCase, FTK, SleuthKit, Volatility (or equivalent)
Strong operating system expertise (Windows, Linux, or macOS)
The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.
$183,000.00 - $252,000.00/yr
About Palo Alto Networks
Palo Alto Networks, Inc. is an American multinational cybersecurity company with headquarters in Santa Clara, California. Its core products are a platform that includes advanced firewalls and cloud-based offerings that extend those firewalls to cover other aspects of security. The company serves over 70,000 organizations in over 150 countries, including 85 of the Fortune 100. It is home to the Unit 42 threat research team and hosts the Ignite cybersecurity conference.