Job SummaryJob SummaryThe Principal Consultant, Cloud DFIR, Reactive Services is a senior individual contributor within Unit 42 responsible for leading cloud-focused incident response and digital forensics investigations across AWS, Azure, GCP, and hybrid enterprise environments.
In this role, you will serve as a technical lead on active incidents, partnering with Consulting Directors and clients to investigate security breaches, determine scope and impact, contain threats, and guide recovery efforts. You will perform advanced cloud forensic analysis, identify attacker activity, and provide actionable remediation recommendations during high-severity cybersecurity events.
Key Responsibilities- Lead cloud-focused incident response and digital forensics engagements.
- Investigate attacks involving cloud infrastructure, identity compromise, ransomware, data theft, and unauthorized access.
- Analyze cloud telemetry, including audit logs, IAM activity, network traffic, storage access, containers, and endpoint data.
- Conduct forensic acquisition and analysis across cloud, hybrid, and enterprise environments.
- Serve as a technical lead during active investigations, guiding strategy and client communications.
- Deliver clear findings, executive-ready reporting, and remediation guidance.
- Support development of cloud investigation methodologies, playbooks, and tooling.
- Mentor team members and contribute to knowledge sharing across Unit 42.
Qualifications Required Qualifications- 6-8+ years of experience in DFIR, incident response, cloud security, or related cybersecurity disciplines.
- 3+ years of hands-on experience securing, operating, or investigating AWS, Azure, or GCP environments.
- Experience leading investigations involving cloud breaches, ransomware, advanced intrusions, or data compromise incidents.
- Strong understanding of cloud architecture, IAM, networking, logging, and security controls.
- Experience analyzing cloud-native telemetry such as AWS CloudTrail, Azure Activity Logs, Microsoft Entra ID, or Google Cloud Audit Logs.
- Hands-on experience with industry-standard DFIR and investigative tools.
- Experience investigating Windows, Linux, macOS, cloud workloads, and hybrid environments.
- Strong client-facing communication and consulting skills.
Preferred Qualifications- Experience responding to enterprise-scale cloud security incidents.
- Knowledge of cloud security platforms such as AWS Security Hub, GuardDuty, Microsoft Defender, Sentinel, or Google Security Command Center.
- Experience investigating containerized or Kubernetes environments.
- Knowledge of MITRE ATT&CK and modern cloud threat actor tradecraft.
- Consulting, MDR, or professional services experience.
- Certifications such as GCFA, GCIH, CISSP, AWS Security Specialty, Azure Security Engineer, or equivalent.
- Ability to travel up to 20% as required for client engagements.
Compensation DisclosureThe compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.
$151,000.00 - $208,000.00/yr