Principal DFIR Consultant
MOXFIVE
United States
The Role
This principal-level position involves leading and supporting forensic investigations across traditional Windows environments and cloud-native infrastructure, including multi-cloud intrusions spanning AWS, GCP and Azure. Day-to-day work covers ransomware response, nation-state threat investigations, cloud identity abuse, and contributing to the development of an LLM-based investigative platform.
Skills & Experience
Candidates must bring deep Windows forensics expertise — including MFT and $I30 artefact analysis — alongside hands-on cloud forensics experience across CloudTrail, GuardDuty, Entra ID audit logs and GCP Data Access logs. Familiarity with AI and LLM tooling applied to investigative workflows is highly valued, as is experience investigating account takeover and identity-based attacks.
Who It Suits
This role suits a seasoned DFIR professional ready to operate at principal level, comfortable both leading high-stakes investigations and shaping methodology and tooling. Those with a builder’s mindset — keen to translate investigative instinct into AI-assisted platforms — will find particular opportunity here.
Typical advertised salary for Incident Response roles in United States: $125,000–$180,000 (median $150,000 — from 154 recent listings analysed by Forensic Focus).
Learn More/Apply





