← All jobs · More in this country

DFIR Analyst

SentinelOne

Auckland

Mid · Full-time

The Role

The analyst conducts digital forensic investigations and incident response across endpoint, network, cloud, and SaaS environments, covering ransomware, business email compromise, and identity compromise cases. Responsibilities include evidence acquisition, chain-of-custody management, containment support, case documentation, and contributing to customer-facing status updates and formal investigative reports.

Skills & Experience

Candidates need two or more years of hands-on DFIR or threat-hunting experience, ideally in a consulting environment. Proficiency with forensic tools such as X-Ways Forensics, Axiom, and FTK is expected, alongside familiarity with EDR/XDR platforms, SIEMs, network forensics, Windows artifact analysis, and scripting or automation capabilities.

Who It Suits

This role suits an early-to-mid career DFIR professional who thrives in fast-paced, high-pressure environments and is comfortable working a rotating on-call schedule. Those with a degree in digital forensics or cybersecurity and a consulting background will be well positioned to contribute across multi-region investigations.

Learn More/Apply

Applications are handled entirely by the employer or the original listing site. Forensic Focus aggregates and summarises public listings; details can change after publication — always confirm on the employer's page.

Listed: 2026-09-16