DFIR Consultant
Colossus Technologies Group
United States
The Role
This position involves conducting digital forensics and incident response investigations across Windows and Linux environments. Day to day, the consultant collects disk and memory images, analyses forensic artefacts for indicators of compromise, reviews host and appliance logs, builds event timelines, and applies remediation strategies to contain and resolve identified threats.
Skills & Experience
Candidates should have at least two years in DFIR, with solid knowledge of Windows and Unix/Linux systems, EDR/EPP platforms, and storage technologies including RAID, NAS, and SAN. Familiarity with malware analysis tooling, forensic acquisition methods, BEC investigation techniques, and the cyber kill chain framework is essential.
Who It Suits
This role suits a self-directed forensics professional comfortable working independently under pressure and delivering high-quality outputs with minimal oversight. The position is remote but demands significant flexibility, including rotating on-call availability, weekend working, and the ability to deploy to client sites at short notice for engagements of one to two weeks.
Typical advertised salary for Incident Response roles in United States: $125,000–$179,000 (median $149,000 — from 108 recent listings analysed by Forensic Focus).
Learn More/Apply





