Sr. DFIR Analyst
SentinelOne
United States
The Role
Operating within a 24x7x365 follow-the-sun DFIR team, this role takes technical lead on small to medium-scale breach investigations. Day-to-day responsibilities span EDR-driven incident response, forensic acquisition, threat hunting, containment guidance, and the preparation of defensible investigative reports for clients, breach counsel, and stakeholders.
Skills & Experience
Candidates require strong, well-rounded expertise across endpoint, network, cloud, and SaaS forensics, covering incident types such as ransomware, BEC, and identity compromise. Experience with EDR tooling, chain-of-custody procedures, scripting, and the ability to build or improve forensic workflows — including AI-assisted approaches — are expected.
Who It Suits
This role suits an experienced DFIR professional ready to own complex investigations end-to-end, mentor junior analysts, and thrive under pressure during large-scale incidents. Those who enjoy working across technical and client-facing dimensions within a global, fast-paced security consultancy will find it a strong fit.
Typical advertised salary for Incident Response roles in United States: $125,000–$180,000 (median $150,000 — from 154 recent listings analysed by Forensic Focus).
Learn More/Apply





