Senior Digital Forensics and Incident Response (DFIR) Consultant

Cypfer

$110K — $130K *
Plano, TX 75025In-Person
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in digital forensics or incident response
  • Strong knowledge of Windows and Unix/Linux systems
  • Expertise in EDR / EPP technologies
  • Familiarity with forensic acquisition of physical and virtual systems
  • Working knowledge of RAID, NAS, SAN, and related storage technologies
  • Ability to analyze and interpret technical logs
  • Experience with threat research and investigation techniques

Responsibilities

  • Engage in incident response tasks with diverse stakeholders
  • Utilize forensic tools to collect artifacts from compromised systems
  • Conduct Windows forensics to assess breaches
  • Apply remediation strategies for identified threats
  • Analyze collections for indicators of compromise
  • Review logs to detect suspicious activities
  • Collect forensic data from various endpoints and servers

Benefits

  • Medical benefits
  • Opportunity for multiple bonus programs
  • Flexible remote work arrangement with travel opportunities
  • Opportunity to work independently and produce quality deliverables
  • Access to ongoing training in emerging threats and techniques
Full Job Description
Core Responsibilities:
  • Engage on behalf of CYPFER in incident response tasks, interacting with various insurance partners, legal counsel, incident response units, client executives, and technical teams.
  • Utilize standard tools and methodologies to collect forensic artifacts and images from affected systems.
  • Assist with Windows forensics and triage to assess compromise and investigations.
  • Familiarity with malware analysis tools and methodologies.
  • Apply mitigation strategies and concepts to remediate identified threats.
  • Analyze triage collections/artifacts for indicators of compromise (IOCs) and potentially malicious activity.
  • Review logs from host systems and appliances to identify suspicious activities.
  • Collect forensic disk and memory images from physical and virtual endpoints and servers.
  • Understanding of an incident lifecycle and cyber-kill-chain.
  • Correlate events and build timelines of events.
  • Maintain current knowledge on emerging threats and vulnerabilities.
  • Analyze files for IOCs using various techniques.


Technical Requirements:
  • 8+ years of experience in digital forensics, incident response, or a similar role.
  • Knowledge of Windows and Unix/Linux operating systems.
  • Understanding of the functionality of EDR / EPP technologies.
  • Familiarity with forensic acquisition and analysis of physical and virtual systems.
  • Working knowledge of storage technologies such as RAID, NAS, SAN, Fiber Channel, iSCSI, and NFS.
  • Ability to analyze and interpret logs from various sources.
  • Ability to perform threat research and analyze current threats.
  • Understanding of business email compromise (BEC) cases and investigation techniques.
  • Participate in a rotating on-call schedule; ability to work on weekends and outside normal business hours as needed.
  • This role is remote but requires the ability to travel on short notice to a client site up to 50%. Must maintain flexibility to travel frequently within 24-48 hours' notice for deployments typically 1-2 weeks in duration.


Business Responsibilities:
  • Maintain current knowledge of information security, incident response techniques, emerging threats, and tools.
  • Work independently and produce high-quality deliverables with minimal supervision.
  • Exhibit strong customer service and consulting skills.
  • Adhere to client and internal policies, procedures, and security practices.
  • Maintain detailed notes and draft updates and reports as required.
  • Remain calm, composed, and articulate in tough customer situations.
  • Exhibit excellent relationship management and communication skills.


Preferred Skills:
  • Understand obfuscation techniques used to conceal malicious commands and traffic, and lateral movement strategies employed by threat actors.
  • Familiarity with exfiltration techniques used by threat actors.
  • Knowledge of SIEM and SOAR solutions.
  • Experience with e-discovery tools and methodologies.
  • Proficiency in collecting and analyzing data from mobile devices/cell phones.
  • Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar are a plus.


Compensation package includes a base salary, medical benefits and multiple bonus opportunities.

Similar Jobs

More Jobs at Cypfer

More Information Technology Jobs

Find similar Senior Digital Forensics and Incident Response (DFIR) Consultant jobs: