DFIR Consultant

Tokio Marine HCC

$87K — $131K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cyber Security, Computer Science, or related IT field.
  • 2+ years in digital forensics, incident response, or security operations.
  • Experience with endpoint, server, and cloud log analysis.
  • Familiarity with DFIR tools and report writing.
  • Strong communication skills for technical concepts.

Responsibilities

  • Perform triage and analysis of digital evidence to determine impact and root cause.
  • Document findings clearly and defensively, developing accurate timelines.
  • Analyze malware and suspicious activity to support incident response.
  • Communicate with clients and stakeholders during active investigations.
  • Prepare updates and reports translating technical details into actionable guidance.
  • Contribute to playbooks and procedures for operational efficiency.
  • Participate in after-action reviews to enhance DFIR practices.

Benefits

  • Full-time remote work opportunity.
  • Participation in continuous improvement initiatives.
  • Engagement in meaningful, high-impact investigations.
  • Access to professional development and certifications.
Full Job Description
Job Title: DFIR Consultant
Location: Remote, USA
Reports to: Managing Director
Employment Type: Full time
Job Req ID: 2026
Req Begin Date: 8/11/2026

Job Summary

Join us in shaping the future of TMHCC-CPLG as a key contributor in our Digital Forensics and Incident Response (DFIR) team, Vector3. You will apply your investigative experience to support client incidents from initial triage through evidence preservation, analysis, and reporting. You will work closely with your team on complex investigations, helping deliver timely, accurate, and defensible findings that support recovery and informed decision-making.

Key Responsibilities

Relying on extensive security knowledge and advanced technical expertise, this role is accountable for the following responsibilities

Relying on advanced knowledge and strong leadership skills, this role is accountable for the following responsibilities:

Incident Response and Forensic Analysis:
  • Perform triage, acquisition, preservation, and analysis of endpoint, server, cloud, and log evidence to determine scope, impact, and root cause.
  • Develop accurate timelines, identify affected assets and accounts, and document investigative findings in a clear and defensible manner.
  • Support analysis of malware, suspicious scripts, persistence mechanisms, credential theft, lateral movement, and data theft activity.
  • Use repeatable methods and validated workflows to ensure evidence integrity and investigation quality.

Client Engagement and Communication:
  • Communicate professionally with internal stakeholders, clients, insurers, legal counsel, and other approved parties during active matters.
  • Prepare concise updates, investigation notes, and report content that translate technical detail into actionable business and response guidance.
  • Support status calls, evidence requests, and coordination of next steps across involved teams.

Operational Support and Continuous Improvement:
  • Contribute to playbooks, templates, evidence handling procedures, and knowledge articles that improve team efficiency and consistency.
  • Identify repeatable investigative tasks that can be standardized, automated, or improved for scale.
  • Support after-action reviews and lessons learned to strengthen the DFIR practice and client outcomes.


Competencies

Planning
  • Contribute to the development of both short-term and long-term plans for designated area of the organization.

Technical Excellence
  • Apply strong technical analysis skills to digital forensic evidence, incident data, and client environments.
  • Write, or is a major contributor to, investigative reports and documentation.
  • Work accurately under time pressure while maintaining defensible methods and attention to detail.

Cost Management
  • Develop innovative ways to improve financials and increase operational efficiency.

Business Controls and Policies
  • Comply with all corporate policies and procedures.
  • Identify control objectives for the designated function and help implement cost effective controls designed to meet those objectives.


Education

Minimum 4 Year / bachelor's degree in cyber security, Computer Science, Information Technology related degree.

Certifications, Licenses, and Designations

Preferred advanced degrees or certifications (CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE) are a plus

Experience

2+ years of professional experience in digital forensics, incident response, security operations, or related investigative work.

Other
  • Experience performing endpoint, server, and cloud log analysis in support of cyber incidents.
  • Experience with common DFIR tools, evidence handling, and report writing.
  • Ability to manage multiple active matters while maintaining quality and deadlines.
  • Excellent communication skills to clearly and concisely communicate complex technical concepts to stakeholders.


The pay range for this position is $87,400-$131,000 which includes geographic adjustments, where applicable. The pay range is the range THMCC, in good faith, believes is the range of compensation for this role at the time of this posting. The hired applicant will be offered pay within the entire range based on the candidate's geographic location, qualifications, work experience, education, and/or skill level. The Company is fully committed to ensuring equal pay opportunities for equal work regardless of color, race, sex, national origin, sexual orientation, religion, age, veteran status, disability, pregnancy, citizenship status, genetic information, or any other basis protected by federal, state, or local pay equity laws.
California 1212Use CA Fair Chance language.

Similar Jobs

More Jobs at Tokio Marine HCC

More Information Technology Jobs

Find similar DFIR Consultant jobs: