Digital Forensics Jobs Round-Up, August 10 2026

A selection of the latest DFIR job vacancies (got a job you want to feature in the next round-up? Submit the details here):

No jobs match the selected filters.

United States

Principal DFIR Consultant

GuidePoint Security

Remote

Remote · Lead/Principal

Serves as the highest individual contributor in a DFIR practice, leading complex ransomware, APT and insider threat investigations, conducting advanced host, network and cloud forensics, mentoring staff, and supporting business development.

View Job

Principal Consultant, Cloud DFIR (Unit 42)

Palo Alto Networks

Harrisburg, PA

Remote · Lead/Principal · $151,000 – $208,000 a year

Lead cloud-focused DFIR engagements across AWS, Azure, and GCP environments, investigating ransomware, identity compromise, and data breaches. Deliver forensic analysis, executive reporting, remediation guidance, and mentor team members within Unit 42.

View Job

Senior Consultant, Digital Forensic and Incident Response (DFIR)

Surefire Cyber

Remote

Remote · Senior · Full-time

Senior DFIR consultant role conducting forensic analysis and leading incident response engagements across ransomware, BEC and malware cases. Involves client-facing work, mentoring junior staff, report writing and on-call support.

View Job

Principal Consultant, DFIR, Reactive Services (Unit 42)

Palo Alto Networks

Burbank, CA

Remote · Lead/Principal · $151,000 – $208,000 a year

Senior DFIR practitioner role within Unit 42 leading incident response and forensic investigations across enterprise environments. Covers host, network and cloud forensics, ransomware response, evidence acquisition, and client remediation guidance on a weekend overnight shift.

View Job

Digital Forensic Examiner

City of Fort Myers, FL

Fort Myers, FL

Onsite · Mid · Full-time · $5,369.60 – $8,121.60 a month

Conduct forensic examinations of computers, mobile devices and storage media; recover and analyse digital evidence; prepare detailed reports; and provide expert court testimony supporting criminal investigations for a municipal law enforcement agency.

View Job

Forensic Computer Analyst

U.S. Postal Service

Anaheim, CA

Onsite · Mid · Full-time · $78,160 – $144,820 a year

Conduct forensic examinations of digital and multimedia evidence for criminal and civil investigations, provide expert witness testimony, support crime scene collections, deliver training, and advise on evidence handling and cybersecurity breaches.

View Job

ICITAP Forensic Digital Evidence Advisor

Amentum

Remote

Remote · Senior · Part-time · $506.18 a day

Subject matter expert advising and mentoring host-nation forensic examiners on digital evidence collection, examination, analysis tools, chain of custody, and report writing under a DOJ ICITAP programme supporting international rule-of-law initiatives.

View Job

Digital Forensics / Malware Analyst

Digital Global Connectors

McLean, VA

Hybrid · Senior · Full-time · $125,000 – $165,000 a year

Experienced analyst required to conduct forensic investigations, malware analysis, and evidence preservation supporting a federal cybersecurity programme. Responsibilities include endpoint/cloud forensics, reverse engineering, IOC development, and incident response support using industry-standard tools.

View Job

Digital Media Forensics Analyst Expert

General Dynamics Information Technology

Fort Meade, MD

Onsite · Lead/Principal · $164,382 – $195,155 a year

Expert-level digital forensics analyst supporting US Army counterintelligence and counterterrorism missions. Responsibilities include forensic examination of digital media, evidence acquisition, malware analysis, incident response support, and evaluating emerging forensic technologies.

View Job

Back to country list ↑

UK & Ireland

Information Security Incident Response Analyst

NTT DATA

London EC4N, England

Hybrid · Mid · Full-time

Join a global DFIR team performing host, disk, memory, network and cloud forensic investigations across Windows, Linux and macOS environments. Support clients through containment, remediation and IR readiness, with OT experience and UK SC required.

View Job

Cyber Response and Recovery – Assistant Manager (Reactive)

KPMG

London, England

Hybrid · Mid · Permanent, Full-time

Hands-on reactive DFIR role within a Tier 1 UK incident response team, conducting digital forensics across disk, memory, network and logs, managing smaller cases, supporting client IR capability development and on-call incident response.

View Job

Senior DFIR Investigator

Solis

London EC2N, England

Onsite · Senior · Permanent, Full-time

Lead complex cyber incident investigations across host, network and cloud environments, analysing threat actor activity, producing forensic reports, mentoring junior investigators and delivering proactive cyber resilience services for global clients.

View Job

Director, Digital Forensics & Incident Response (Global)

NCC Group

Manchester M3, England

Onsite · Lead/Principal · Full-time

Lead a global Digital Forensics and Incident Response function, setting strategic direction, overseeing major cyber incidents, developing advanced forensic capabilities, and driving operational excellence across regionally distributed teams.

View Job

Senior Digital Forensics and Incident Response (DFIR) Consultant

Cypfer

London EC3A, England

Hybrid · Senior · Full-time

Lead complex DFIR investigations for a global cybersecurity first-responder firm, conducting forensic analysis across Windows/Linux/virtual platforms, malware triage, threat hunting, and incident response for ransomware and cyber-extortion events.

View Job

Senior Digital Forensics and Incident Response Analyst

Barclays

Knutsford, England

Onsite · Senior · Permanent

Senior DFIR Analyst role within a financial institution’s Security Operations Centre, leading investigation of complex cyber incidents, applying digital forensic techniques, analysing endpoint and network artefacts, and improving detection and response capabilities.

View Job

Digital Forensics and Incident Response (DFIR) Consultant

Cypfer

London EC3A, England

Hybrid · Mid · Full-time

Consultant role covering end-to-end incident response and digital forensics, including forensic acquisition, Windows triage, malware analysis, IOC investigation, log review, and client-facing remediation for ransomware and cyber-extortion cases.

View Job

Digital Forensics Practitioner

HM Revenue and Customs

Nottingham, England

Onsite · Mid · Permanent, Part-time, Full-time · £31,096 – £37,919 a year

Support HMRC fraud investigations by conducting forensic acquisition and examination of digital devices including computers, mobile phones and CCTV systems within a world-class law enforcement forensic laboratory in Nottingham or Stratford.

View Job

Senior Incident Response Security Consultant

Google

Remote, United Kingdom

Remote · Senior

Lead complex incident response engagements for Mandiant clients, conducting host and network forensics, malware triage, threat hunting, and cloud investigations while mentoring junior consultants and communicating findings to executive stakeholders.

View Job

Senior Security Analyst, Incident Response

Google

Dublin, County Dublin, Ireland

Onsite · Senior · Full-time · €116,000–€118,000 a year

Investigate and coordinate security and privacy incidents across a large tech organisation, analysing data sources, writing reports, managing stakeholder communications, and driving improvements to incident management processes and tooling.

View Job

Senior Cyber Incident Response Analyst

Integrity360

Dublin, County Dublin, Ireland

Onsite · Senior

Senior analyst role conducting cyber incident response, host and network intrusion analysis, malware reverse engineering, digital forensics, and threat intelligence for mid-market and enterprise clients across multiple sectors.

View Job

Associate, eDiscovery/Digital Forensics

Interpath Advisory

Dublin, County Dublin, Ireland

Mid · Full-time

Join a data and technology investigations team delivering litigation support, digital forensic collections, and eDiscovery services across complex, cross-border disputes. Manage ESI processing, forensic evidence, and leading platforms including RelativityOne and Nuix.

View Job

Back to country list ↑

Australia & New Zealand

Senior Cybersecurity Incident Responder

Datacom

Perth WA, Australia

Hybrid · Senior · Full-time

Senior DFIR role within a managed cybersecurity team, leading incident response and forensic investigations, delivering compromise assessments, threat hunting, tabletop exercises, and producing detailed DFIR reports for commercial and government clients across Australia and New Zealand.

View Job

Senior Director, Advanced Threat Services, Cybersecurity

FTI Consulting

Sydney NSW, Australia

Lead/Principal · $205,000 – $245,000 a year

Senior Director leading a multidisciplinary cybersecurity team covering digital forensics and incident response, offensive security, and security engineering. Oversees major client engagements, mentors consultants, and manages key relationships across law firms and insurers.

View Job

Digital Forensic Investigator (DFIR Specialist)

Cybernetic Global Intelligence

Brisbane QLD, Australia

Onsite · Senior · Full-time

Lead end-to-end digital forensic investigations across endpoints, cloud, and networks following cyber incidents. Produce court-admissible reports, reconstruct attack timelines, support containment, and engage client executives and legal teams. Minimum 5 years DFIR experience required.

View Job

Manager, Forensic Technology

BDO

Sydney NSW, Australia

Onsite · Manager · Full-time

Lead and deliver digital forensic and eDiscovery services across investigations, cyber incident response and litigation support. Manage engagements, supervise junior staff, analyse digital evidence from multiple sources and author expert reports.

View Job

Electronic Forensic Investigator

New Zealand Government

Auckland City, Auckland, New Zealand

Onsite · Mid · Fixed term contract

Join a government fraud agency’s Electronic Forensic Unit supporting partner agencies. Responsibilities include digital evidence acquisition, preservation, analysis, forensic reporting, mobile and cloud investigations, and acting as an expert witness in court.

View Job

Senior Security Specialist – Cyber Defence

BNZ

Auckland City, Auckland, New Zealand

Hybrid · Senior · Full-time

Lead complex incident response investigations, threat hunting and detection engineering within a major bank’s cyber defence team. Mentor analysts, refine SOAR playbooks and build SIEM/EDR use cases to strengthen organisational resilience.

View Job

Back to country list ↑

Canada

SOC Specialist (Incident Responder)

Genetec

Montréal, QC

Onsite · Mid · Full-time

SOC Specialist handling escalated security incidents, performing endpoint forensic investigations, developing IR runbooks, monitoring threats, and conducting cloud and on-premise security event analysis within a 24/7 operational team.

View Job

Security Specialist – Incident Commander (DFIR)

Ubisoft

Montréal, QC

Onsite · Senior · Full-time

Lead response to high-severity cybersecurity incidents across global infrastructure, conducting digital forensic investigations, threat hunting, and coordinating cross-functional teams. Improve IR processes, mentor SOC staff, and deliver post-incident reporting to technical and executive stakeholders.

View Job

Senior Investigator – Digital Forensics & Incident Response

Accenture

Toronto, ON

Hybrid · Senior · Full-time · $75,400–$125,400 a year

Senior DFIR investigator conducting complex forensic analysis, memory forensics, malware triage, threat hunting, and incident response across cloud and enterprise environments, while mentoring junior staff and delivering client-facing reports and briefings.

View Job

Senior Specialist, Incident Response

SITA Switzerland Sarl

Montréal, QC

Senior · Full-time

Senior DFIR specialist role conducting forensic investigations across endpoints, servers, cloud and SaaS environments, managing incident response lifecycles, analysing malware and ransomware artefacts, and enhancing forensic readiness within a global aviation IT security team.

View Job

Senior Digital Forensic Investigator

eSentire

Canada

Senior · Full-time · $120,000–$160,000 a year

Senior DFIR role leading complex cyber investigations spanning ransomware, data breaches and espionage cases. Responsibilities include cloud forensics, threat hunting, containment, evidence analysis, mentoring junior staff and producing court-admissible findings.

View Job

Senior DFIR Specialist

Malleum

Remote

Remote · Senior · Full-time

Lead and deliver digital forensics and incident response engagements across endpoint, network, cloud, and hybrid environments. Investigate ransomware, intrusions, and insider threats while helping shape a growing DFIR practice and mentoring junior practitioners.

View Job

Incident Response Analyst

ISA Cybersecurity

Toronto, ON

Hybrid · Mid · Full-time · $75,000–$105,000 a year

Hands-on DFIR analyst role supporting incident response engagements across endpoint, network, and cloud environments. Responsibilities include forensic acquisition, evidence analysis, timeline reconstruction, report writing, and playbook development under an Incident Commander.

View Job

Cybersecurity Incident Response Commander

ISA Cybersecurity

Toronto, ON

Hybrid · Lead/Principal · Full-time · $135,000–$180,000 a year

Serves as Incident Commander for all IR retainer and emergency engagements, leading digital forensic investigations across endpoint, network, mobile and cloud sources, developing DFIR playbooks, and presenting evidence reports to legal and client stakeholders.

View Job

Senior Consultant, Digital Forensics

MNP

Calgary, AB

Onsite · Senior · Permanent

Senior consultant role delivering digital forensic investigations and litigation support, including forensic imaging, artifact analysis, eDiscovery, fraud investigations and regulatory matters, while leading junior team members and contributing to business development.

View Job

Back to country list ↑

Singapore

Senior Incident Responder

Blackpanda

Singapore

Senior · Full-time

Lead end-to-end cyber incident response engagements across BEC, ransomware, data breach and digital forensics cases. Scope incidents, conduct forensic analysis across Windows, Linux, macOS and cloud environments, mentor junior responders, and advise clients on remediation and recovery.

View Job

Digital Forensics Incident Responder

IMD Info-communications Media Development Authority

Pasir Panjang

Onsite · Mid · Full-time

Investigate cybersecurity incidents involving digital forensics, malware and log analysis within a SOC environment. Provide technical guidance on threat assessments, maintain IR playbooks, and prepare incident reports for stakeholders.

View Job

Senior Digital Forensics Investigator – Global Security Organization

TikTok

Singapore

Onsite · Senior

Lead end-to-end digital forensic investigations covering insider and external threats across endpoint, mobile, cloud, and network environments. Produce audit-ready findings, mentor junior analysts, and develop detection rules and investigation playbooks.

View Job

Associate – Assurance, Forensic – Cyber Investigations (2027 Graduates)

EY

Singapore

Hybrid · Junior

Graduate-entry forensic technology role supporting digital forensic investigations, eDiscovery workflows, cyber incident response, and evidence analysis across diverse client engagements from a forensic lab and client sites.

View Job

SR&T : Analyst – Forensic & Financial Crime: Digital Forensic – SG

Deloitte

Singapore

Junior · Fresh graduate

Join a forensic and financial crime practice supporting fraud, corruption and complex litigation investigations. Collect, preserve and analyse electronic evidence using digital forensic tools and eDiscovery technology across devices, servers and cloud repositories.

View Job

Incident Response Consultant, Cyber Security

Google

Singapore

Mid · Full-time

Join Mandiant (Google Cloud) as an IR consultant in Singapore, conducting host and network forensics, malware triage, threat hunting, and log analysis to help clients detect, investigate, contain and remediate complex security incidents.

View Job

Back to country list ↑

Netherlands

Consultant – DFIR

NCC Group

Rijswijk

Mid · Fulltime

DFIR consultant role delivering client engagements covering digital forensic investigations, incident response, containment strategies, risk assessments and security training. Requires forensic tooling knowledge, scripting skills and familiarity with EDR, SIEM and the PICERL framework.

View Job

Digital Forensic and Incident Response Specialist

Bureau Veritas

Nederland

Mid

Respond to cybersecurity incidents and conduct forensic investigations across IT and OT environments, including critical infrastructure. Analyse compromised systems, gather digital evidence, advise clients, and support cyber crisis preparedness in the Netherlands.

View Job

German Senior Digital Forensics and Incident Response (DFIR) Consultant

Cypfer

Utrecht

Remote · Senior · Fulltime

Bilingual English/German Senior DFIR Consultant leading complex cyber incident investigations, conducting forensic analysis across Windows/Unix/Linux platforms, performing threat hunting, malware analysis, and delivering clear client reports. Up to 50% travel required.

View Job

German Digital Forensics and Incident Response (DFIR) Consultant

Cypfer

Utrecht

Remote · Mid · Fulltime

Bilingual English/German DFIR consultant conducting forensic acquisitions, artifact analysis, IOC identification, and incident response for ransomware and cyber-attack cases. Requires 2+ years’ experience, Windows/Linux knowledge, and willingness to travel on short notice.

View Job

Staff Cybersecurity Specialist – Incident Response

Eye Security

Den Haag

Onsite · Senior · Fulltime

Senior incident responder leading end-to-end cyber incident investigations, conducting forensic analysis, mentoring junior staff, and driving improvements across security operations within a European MDR organisation serving 1,000+ customers.

View Job

Dutch Digital Forensics and Incident Response (DFIR) Consultant

Cypfer

Utrecht Binnenstad

Remote · Mid · Fulltime

Bilingual Dutch/English DFIR consultant role handling ransomware and cyber-attack first response. Responsibilities include forensic imaging, artifact analysis, IOC identification, log review, timeline correlation, and client-facing incident remediation with up to 50% travel.

View Job

Lecturer-Researcher Digital Forensics

Hogeschool Leiden

Leiden

Onsite · Mid · Fulltime · € 4.632,17 – € 6.677,44 per maand

Develop and deliver Master’s-level digital forensics education while conducting applied research in areas including DFIR, eDiscovery, OSINT and IoT forensics. Supervise student theses and collaborate with industry and public sector partners.

View Job

(Senior) Consultant Digital Forensics

Deloitte

Amsterdam Zuid

Hybrid · Mid · Parttime, Fulltime

Consultant role within a forensic investigations team, conducting digital evidence collection and analysis, mobile device examination, fraud investigations, and producing datasets for legal proceedings, while guiding junior analysts.

View Job

Senior Cyber Incident Responder

Deloitte

Amsterdam Zuid

Hybrid · Senior · Parttime, Fulltime

Senior Cyber Incident Responder leading technical investigations into ransomware, breaches and insider threats. Performs log analysis, artifact forensics, EDR correlation, threat hunting, compromise assessments and builds client IR capabilities within an international team.

View Job

Back to country list ↑

Germany

(Senior) Manager – Digital Forensics / Cyber Forensics

Deloitte

Berlin

Hybrid · Manager · Vollzeit

Lead digital and cyber forensic investigations into cybercrime and economic crime, managing client projects covering incident response, forensic analysis, and innovative service development, while supporting business development and recruitment in Germany.

View Job

Senior Consultant Cyber

Deloitte GmbH

Frankfurt am Main

Hybrid · Senior · Vollzeit

Join a global consulting team delivering digital forensics and incident response services, supporting clients with cyber attack investigation, forensic evidence handling, cybercrime analysis, and compliance with standards such as ISO 27001, DORA and NIS2.

View Job

Senior Digital Forensics and Incident Response Consultant

NTT Ltd

Erfurt

Hybrid · Senior

Join a specialist DFIR team supporting clients during security incidents. Responsibilities include host and network forensic analysis, malware reverse engineering, incident response reporting, and developing proactive IR plans and playbooks.

View Job

(Senior) Cyber Security Expert DFIR

TÜV Informationstechnik GmbH

Essen

Hybrid · Senior · Teilzeit, Vollzeit

Join a Cyber Security & Reaction Service team handling national and international DFIR cases, conducting incident response, compromise assessments, penetration tests, and adversary simulations using MITRE ATT&CK, with court-admissible reporting responsibilities.

View Job

Incident Response Lead

Coalition – Germany

Berlin

Lead/Principal

Lead cyber incident response engagements for customers in Germany and the wider region, conducting forensic investigations, analysing IOCs across Windows/Linux/macOS, and delivering remediation guidance in both German and English.

View Job

IT-Forensik Analyst (Senior)

Hassmann IT-Forensik GmbH

Saarbrücken

Onsite · Mid · 42.000 € – 60.000 € pro Jahr

Join a growing IT forensics team producing court-admissible expert reports. Responsibilities include evidence preservation, data processing and documentation. Suitable for qualified IT professionals at analyst or senior level, based onsite in Saarbrücken.

View Job

IT-Forensiker

Response informations design

Ingolstadt

Onsite · Mid · Vollzeit

Full-time digital forensics examiner role producing impartial expert reports for prosecutors, courts, companies and private clients. Requires CS degree, experience with digital media, Python/C++ skills and fluent German.

View Job

IT-Forensik Analyst

Hassmann IT-Forensik GmbH

Saarbrücken

Onsite · Junior

IT forensics analyst role involving digital evidence acquisition from PCs, laptops, smartphones, tablets and consoles, plus data analysis, documentation and contribution to court-admissible expert reports. Onsite position in Saarbrücken.

View Job

Incident Response Lead

Coalition, Inc.

Berlin

Lead/Principal

Lead cyber incident response engagements for customers in Germany, conducting forensic investigations, analysing compromised systems, identifying IOCs, managing breaches, and providing remediation guidance. Fluency in German and English required.

View Job

Back to country list ↑

United Arab Emirates

Incident Response Lead (DFIR), UAE

DeepSource Technologies

Dubai

Onsite · Lead/Principal · Full-time

Leads cybersecurity incident response and digital forensic investigations in enterprise environments, performing triage, containment, root cause analysis, and malware analysis while developing IR playbooks and coordinating cross-functional security teams.

View Job

Digital Forensics and Incident Response Consultant

DTS Solution

Dubai

Onsite · Senior · Full-time

DFIR consultant role supporting cyber breach investigations, forensic and malware analysis, threat hunting, and post-compromise assessments. Requires court-ready reporting, chain of custody handling, and 6+ years’ experience with industry-standard forensic tools.

View Job

Senior Digital Forensics Examiner

TransPerfect

Dubai

Onsite · Senior · Full-time

Senior examiner role performing forensic preservation and analysis of digital devices, mobile platforms and cloud systems. Responsibilities include evidence management, expert testimony, client reporting, and mentoring junior forensic practitioners.

View Job

Back to country list ↑

India

Sr Mgr Information Security

Amgen

Hyderabad, Telangana

Onsite · Manager

Senior manager leading a digital forensics team in Hyderabad, overseeing investigations into cyber incidents, insider risk, eDiscovery and HR matters, while guiding tool workflows, evidence handling standards, and AI-assisted forensic capabilities.

View Job

Senior Information Security Analyst

Eurofins GSC IT DC

Bengaluru, Karnataka

Senior · Full-time

Senior SOC L3 analyst leading complex security incident investigations, containment and remediation. Role encompasses DFIR, memory forensics, malware triage, threat hunting, and mentoring junior analysts within a 24/7 global SOC environment.

View Job

L2 SOC Analyst

UST

Bengaluru, Karnataka

Onsite · Mid

Lead high-impact DFIR investigations across file systems, memory, and networks within a managed SOC environment. Responsibilities include incident response, malware analysis, custom tool development, root cause analysis, and scaling DFIR service delivery for clients.

View Job

Senior DFIR Analyst

Barclays

Pune, Maharashtra

Onsite · Senior · Permanent

Senior DFIR analyst role responsible for digital forensic investigations, cyber incident response, security monitoring, log analysis, and threat detection within a large, complex enterprise banking environment. Requires strong forensic and IR skills across Windows, Linux, and Mac platforms.

View Job

DFIR Expert (Lead)

UST

Bengaluru, Karnataka

Lead/Principal

Lead DFIR investigations across file systems, memory, and networks; manage incident response efforts as highest escalation point; develop automation tools; deliver root cause analysis reports; and help scale the DFIR service offering.

View Job

T&T I Cyber: D&R I Manager | Incident Response & Handling

Deloitte

Bengaluru, Karnataka

Onsite · Manager

Manages client incident response engagements, conducting DFIR analysis, malware triage, network forensics and threat intelligence. Leads and mentors IR staff, develops reports for technical and executive audiences, and supports business development.

View Job

T&T | Cyber : D&R | Director | Incident Response & Handling

Deloitte

Delhi

Onsite · Lead/Principal

Director-level DFIR role managing client incident response engagements, conducting forensic investigations, malware triage and network analysis, mentoring IR staff, and contributing to business development within a global consulting practice.

View Job

Senior Information Security Incident Response Analyst

NTT DATA

Hyderabad, Telangana

Remote · Senior · Full-time

Senior DFIR analyst role leading complex incident investigations and forensic analysis across host, disk, memory, network, cloud, and mobile environments. Mentors junior staff, guides clients through containment and remediation, and delivers technical findings to stakeholders.

View Job

OSINT Analyst

Drona Cyber Solutions Pvt Ltd

Ahmedabad, Gujarat

Onsite · Mid · Full-time · ₹3,50,000 – ₹5,00,000 a year

Seeks an analyst to conduct open-source intelligence gathering, perform digital investigations, verify data, identify threats and risks, and produce actionable intelligence reports for investigations and risk assessments.

View Job

Back to country list ↑

South Africa

Senior Cyber Incident Response Analyst (Cape Town or Johannesburg)

Integrity360

Cape Town, Western Cape

Senior

Senior analyst role delivering incident response, threat hunting, host and network intrusion analysis, malware reverse engineering, digital forensics and cyber threat intelligence services for mid-market and enterprise customers across multiple sectors.

View Job

Information Security Team Leader

Sourceworx

South Africa

Lead/Principal

Leads cybersecurity operations including SOC monitoring, penetration testing, vulnerability management, and digital forensic investigations. Mentors a security team, oversees incident response, ensures evidence integrity, and supports risk governance and compliance frameworks.

View Job

Back to country list ↑

Leave a Comment