A selection of the latest DFIR job vacancies (got a job you want to feature in the next round-up? Submit the details here):
No jobs match the selected filters.
United States
Principal DFIR Consultant
GuidePoint Security
Remote
Serves as the highest individual contributor in a DFIR practice, leading complex ransomware, APT and insider threat investigations, conducting advanced host, network and cloud forensics, mentoring staff, and supporting business development.
View JobPrincipal Consultant, Cloud DFIR (Unit 42)
Palo Alto Networks
Harrisburg, PA
Lead cloud-focused DFIR engagements across AWS, Azure, and GCP environments, investigating ransomware, identity compromise, and data breaches. Deliver forensic analysis, executive reporting, remediation guidance, and mentor team members within Unit 42.
View JobSenior Consultant, Digital Forensic and Incident Response (DFIR)
Surefire Cyber
Remote
Senior DFIR consultant role conducting forensic analysis and leading incident response engagements across ransomware, BEC and malware cases. Involves client-facing work, mentoring junior staff, report writing and on-call support.
View JobPrincipal Consultant, DFIR, Reactive Services (Unit 42)
Palo Alto Networks
Burbank, CA
Senior DFIR practitioner role within Unit 42 leading incident response and forensic investigations across enterprise environments. Covers host, network and cloud forensics, ransomware response, evidence acquisition, and client remediation guidance on a weekend overnight shift.
View JobDigital Forensic Examiner
City of Fort Myers, FL
Fort Myers, FL
Conduct forensic examinations of computers, mobile devices and storage media; recover and analyse digital evidence; prepare detailed reports; and provide expert court testimony supporting criminal investigations for a municipal law enforcement agency.
View JobForensic Computer Analyst
U.S. Postal Service
Anaheim, CA
Conduct forensic examinations of digital and multimedia evidence for criminal and civil investigations, provide expert witness testimony, support crime scene collections, deliver training, and advise on evidence handling and cybersecurity breaches.
View JobICITAP Forensic Digital Evidence Advisor
Amentum
Remote
Subject matter expert advising and mentoring host-nation forensic examiners on digital evidence collection, examination, analysis tools, chain of custody, and report writing under a DOJ ICITAP programme supporting international rule-of-law initiatives.
View JobDigital Forensics / Malware Analyst
Digital Global Connectors
McLean, VA
Experienced analyst required to conduct forensic investigations, malware analysis, and evidence preservation supporting a federal cybersecurity programme. Responsibilities include endpoint/cloud forensics, reverse engineering, IOC development, and incident response support using industry-standard tools.
View JobDigital Media Forensics Analyst Expert
General Dynamics Information Technology
Fort Meade, MD
Expert-level digital forensics analyst supporting US Army counterintelligence and counterterrorism missions. Responsibilities include forensic examination of digital media, evidence acquisition, malware analysis, incident response support, and evaluating emerging forensic technologies.
View JobUK & Ireland
Information Security Incident Response Analyst
NTT DATA
London EC4N, England
Join a global DFIR team performing host, disk, memory, network and cloud forensic investigations across Windows, Linux and macOS environments. Support clients through containment, remediation and IR readiness, with OT experience and UK SC required.
View JobCyber Response and Recovery – Assistant Manager (Reactive)
KPMG
London, England
Hands-on reactive DFIR role within a Tier 1 UK incident response team, conducting digital forensics across disk, memory, network and logs, managing smaller cases, supporting client IR capability development and on-call incident response.
View JobSenior DFIR Investigator
Solis
London EC2N, England
Lead complex cyber incident investigations across host, network and cloud environments, analysing threat actor activity, producing forensic reports, mentoring junior investigators and delivering proactive cyber resilience services for global clients.
View JobDirector, Digital Forensics & Incident Response (Global)
NCC Group
Manchester M3, England
Lead a global Digital Forensics and Incident Response function, setting strategic direction, overseeing major cyber incidents, developing advanced forensic capabilities, and driving operational excellence across regionally distributed teams.
View JobSenior Digital Forensics and Incident Response (DFIR) Consultant
Cypfer
London EC3A, England
Lead complex DFIR investigations for a global cybersecurity first-responder firm, conducting forensic analysis across Windows/Linux/virtual platforms, malware triage, threat hunting, and incident response for ransomware and cyber-extortion events.
View JobSenior Digital Forensics and Incident Response Analyst
Barclays
Knutsford, England
Senior DFIR Analyst role within a financial institution’s Security Operations Centre, leading investigation of complex cyber incidents, applying digital forensic techniques, analysing endpoint and network artefacts, and improving detection and response capabilities.
View JobDigital Forensics and Incident Response (DFIR) Consultant
Cypfer
London EC3A, England
Consultant role covering end-to-end incident response and digital forensics, including forensic acquisition, Windows triage, malware analysis, IOC investigation, log review, and client-facing remediation for ransomware and cyber-extortion cases.
View JobDigital Forensics Practitioner
HM Revenue and Customs
Nottingham, England
Support HMRC fraud investigations by conducting forensic acquisition and examination of digital devices including computers, mobile phones and CCTV systems within a world-class law enforcement forensic laboratory in Nottingham or Stratford.
View JobSenior Incident Response Security Consultant
Remote, United Kingdom
Lead complex incident response engagements for Mandiant clients, conducting host and network forensics, malware triage, threat hunting, and cloud investigations while mentoring junior consultants and communicating findings to executive stakeholders.
View JobSenior Security Analyst, Incident Response
Dublin, County Dublin, Ireland
Investigate and coordinate security and privacy incidents across a large tech organisation, analysing data sources, writing reports, managing stakeholder communications, and driving improvements to incident management processes and tooling.
View JobSenior Cyber Incident Response Analyst
Integrity360
Dublin, County Dublin, Ireland
Senior analyst role conducting cyber incident response, host and network intrusion analysis, malware reverse engineering, digital forensics, and threat intelligence for mid-market and enterprise clients across multiple sectors.
View JobAssociate, eDiscovery/Digital Forensics
Interpath Advisory
Dublin, County Dublin, Ireland
Join a data and technology investigations team delivering litigation support, digital forensic collections, and eDiscovery services across complex, cross-border disputes. Manage ESI processing, forensic evidence, and leading platforms including RelativityOne and Nuix.
View JobAustralia & New Zealand
Senior Cybersecurity Incident Responder
Datacom
Perth WA, Australia
Senior DFIR role within a managed cybersecurity team, leading incident response and forensic investigations, delivering compromise assessments, threat hunting, tabletop exercises, and producing detailed DFIR reports for commercial and government clients across Australia and New Zealand.
View JobSenior Director, Advanced Threat Services, Cybersecurity
FTI Consulting
Sydney NSW, Australia
Senior Director leading a multidisciplinary cybersecurity team covering digital forensics and incident response, offensive security, and security engineering. Oversees major client engagements, mentors consultants, and manages key relationships across law firms and insurers.
View JobDigital Forensic Investigator (DFIR Specialist)
Cybernetic Global Intelligence
Brisbane QLD, Australia
Lead end-to-end digital forensic investigations across endpoints, cloud, and networks following cyber incidents. Produce court-admissible reports, reconstruct attack timelines, support containment, and engage client executives and legal teams. Minimum 5 years DFIR experience required.
View JobManager, Forensic Technology
BDO
Sydney NSW, Australia
Lead and deliver digital forensic and eDiscovery services across investigations, cyber incident response and litigation support. Manage engagements, supervise junior staff, analyse digital evidence from multiple sources and author expert reports.
View JobElectronic Forensic Investigator
New Zealand Government
Auckland City, Auckland, New Zealand
Join a government fraud agency’s Electronic Forensic Unit supporting partner agencies. Responsibilities include digital evidence acquisition, preservation, analysis, forensic reporting, mobile and cloud investigations, and acting as an expert witness in court.
View JobSenior Security Specialist – Cyber Defence
BNZ
Auckland City, Auckland, New Zealand
Lead complex incident response investigations, threat hunting and detection engineering within a major bank’s cyber defence team. Mentor analysts, refine SOAR playbooks and build SIEM/EDR use cases to strengthen organisational resilience.
View JobCanada
SOC Specialist (Incident Responder)
Genetec
Montréal, QC
SOC Specialist handling escalated security incidents, performing endpoint forensic investigations, developing IR runbooks, monitoring threats, and conducting cloud and on-premise security event analysis within a 24/7 operational team.
View JobSecurity Specialist – Incident Commander (DFIR)
Ubisoft
Montréal, QC
Lead response to high-severity cybersecurity incidents across global infrastructure, conducting digital forensic investigations, threat hunting, and coordinating cross-functional teams. Improve IR processes, mentor SOC staff, and deliver post-incident reporting to technical and executive stakeholders.
View JobSenior Investigator – Digital Forensics & Incident Response
Accenture
Toronto, ON
Senior DFIR investigator conducting complex forensic analysis, memory forensics, malware triage, threat hunting, and incident response across cloud and enterprise environments, while mentoring junior staff and delivering client-facing reports and briefings.
View JobSenior Specialist, Incident Response
SITA Switzerland Sarl
Montréal, QC
Senior DFIR specialist role conducting forensic investigations across endpoints, servers, cloud and SaaS environments, managing incident response lifecycles, analysing malware and ransomware artefacts, and enhancing forensic readiness within a global aviation IT security team.
View JobSenior Digital Forensic Investigator
eSentire
Canada
Senior DFIR role leading complex cyber investigations spanning ransomware, data breaches and espionage cases. Responsibilities include cloud forensics, threat hunting, containment, evidence analysis, mentoring junior staff and producing court-admissible findings.
View JobSenior DFIR Specialist
Malleum
Remote
Lead and deliver digital forensics and incident response engagements across endpoint, network, cloud, and hybrid environments. Investigate ransomware, intrusions, and insider threats while helping shape a growing DFIR practice and mentoring junior practitioners.
View JobIncident Response Analyst
ISA Cybersecurity
Toronto, ON
Hands-on DFIR analyst role supporting incident response engagements across endpoint, network, and cloud environments. Responsibilities include forensic acquisition, evidence analysis, timeline reconstruction, report writing, and playbook development under an Incident Commander.
View JobCybersecurity Incident Response Commander
ISA Cybersecurity
Toronto, ON
Serves as Incident Commander for all IR retainer and emergency engagements, leading digital forensic investigations across endpoint, network, mobile and cloud sources, developing DFIR playbooks, and presenting evidence reports to legal and client stakeholders.
View JobSenior Consultant, Digital Forensics
MNP
Calgary, AB
Senior consultant role delivering digital forensic investigations and litigation support, including forensic imaging, artifact analysis, eDiscovery, fraud investigations and regulatory matters, while leading junior team members and contributing to business development.
View JobSingapore
Senior Incident Responder
Blackpanda
Singapore
Lead end-to-end cyber incident response engagements across BEC, ransomware, data breach and digital forensics cases. Scope incidents, conduct forensic analysis across Windows, Linux, macOS and cloud environments, mentor junior responders, and advise clients on remediation and recovery.
View JobDigital Forensics Incident Responder
IMD Info-communications Media Development Authority
Pasir Panjang
Investigate cybersecurity incidents involving digital forensics, malware and log analysis within a SOC environment. Provide technical guidance on threat assessments, maintain IR playbooks, and prepare incident reports for stakeholders.
View JobSenior Digital Forensics Investigator – Global Security Organization
TikTok
Singapore
Lead end-to-end digital forensic investigations covering insider and external threats across endpoint, mobile, cloud, and network environments. Produce audit-ready findings, mentor junior analysts, and develop detection rules and investigation playbooks.
View JobAssociate – Assurance, Forensic – Cyber Investigations (2027 Graduates)
EY
Singapore
Graduate-entry forensic technology role supporting digital forensic investigations, eDiscovery workflows, cyber incident response, and evidence analysis across diverse client engagements from a forensic lab and client sites.
View JobSR&T : Analyst – Forensic & Financial Crime: Digital Forensic – SG
Deloitte
Singapore
Join a forensic and financial crime practice supporting fraud, corruption and complex litigation investigations. Collect, preserve and analyse electronic evidence using digital forensic tools and eDiscovery technology across devices, servers and cloud repositories.
View JobIncident Response Consultant, Cyber Security
Singapore
Join Mandiant (Google Cloud) as an IR consultant in Singapore, conducting host and network forensics, malware triage, threat hunting, and log analysis to help clients detect, investigate, contain and remediate complex security incidents.
View JobNetherlands
Consultant – DFIR
NCC Group
Rijswijk
DFIR consultant role delivering client engagements covering digital forensic investigations, incident response, containment strategies, risk assessments and security training. Requires forensic tooling knowledge, scripting skills and familiarity with EDR, SIEM and the PICERL framework.
View JobDigital Forensic and Incident Response Specialist
Bureau Veritas
Nederland
Respond to cybersecurity incidents and conduct forensic investigations across IT and OT environments, including critical infrastructure. Analyse compromised systems, gather digital evidence, advise clients, and support cyber crisis preparedness in the Netherlands.
View JobGerman Senior Digital Forensics and Incident Response (DFIR) Consultant
Cypfer
Utrecht
Bilingual English/German Senior DFIR Consultant leading complex cyber incident investigations, conducting forensic analysis across Windows/Unix/Linux platforms, performing threat hunting, malware analysis, and delivering clear client reports. Up to 50% travel required.
View JobGerman Digital Forensics and Incident Response (DFIR) Consultant
Cypfer
Utrecht
Bilingual English/German DFIR consultant conducting forensic acquisitions, artifact analysis, IOC identification, and incident response for ransomware and cyber-attack cases. Requires 2+ years’ experience, Windows/Linux knowledge, and willingness to travel on short notice.
View JobStaff Cybersecurity Specialist – Incident Response
Eye Security
Den Haag
Senior incident responder leading end-to-end cyber incident investigations, conducting forensic analysis, mentoring junior staff, and driving improvements across security operations within a European MDR organisation serving 1,000+ customers.
View JobDutch Digital Forensics and Incident Response (DFIR) Consultant
Cypfer
Utrecht Binnenstad
Bilingual Dutch/English DFIR consultant role handling ransomware and cyber-attack first response. Responsibilities include forensic imaging, artifact analysis, IOC identification, log review, timeline correlation, and client-facing incident remediation with up to 50% travel.
View JobLecturer-Researcher Digital Forensics
Hogeschool Leiden
Leiden
Develop and deliver Master’s-level digital forensics education while conducting applied research in areas including DFIR, eDiscovery, OSINT and IoT forensics. Supervise student theses and collaborate with industry and public sector partners.
View Job(Senior) Consultant Digital Forensics
Deloitte
Amsterdam Zuid
Consultant role within a forensic investigations team, conducting digital evidence collection and analysis, mobile device examination, fraud investigations, and producing datasets for legal proceedings, while guiding junior analysts.
View JobSenior Cyber Incident Responder
Deloitte
Amsterdam Zuid
Senior Cyber Incident Responder leading technical investigations into ransomware, breaches and insider threats. Performs log analysis, artifact forensics, EDR correlation, threat hunting, compromise assessments and builds client IR capabilities within an international team.
View JobGermany
(Senior) Manager – Digital Forensics / Cyber Forensics
Deloitte
Berlin
Lead digital and cyber forensic investigations into cybercrime and economic crime, managing client projects covering incident response, forensic analysis, and innovative service development, while supporting business development and recruitment in Germany.
View JobSenior Consultant Cyber
Deloitte GmbH
Frankfurt am Main
Join a global consulting team delivering digital forensics and incident response services, supporting clients with cyber attack investigation, forensic evidence handling, cybercrime analysis, and compliance with standards such as ISO 27001, DORA and NIS2.
View JobSenior Digital Forensics and Incident Response Consultant
NTT Ltd
Erfurt
Join a specialist DFIR team supporting clients during security incidents. Responsibilities include host and network forensic analysis, malware reverse engineering, incident response reporting, and developing proactive IR plans and playbooks.
View Job(Senior) Cyber Security Expert DFIR
TÜV Informationstechnik GmbH
Essen
Join a Cyber Security & Reaction Service team handling national and international DFIR cases, conducting incident response, compromise assessments, penetration tests, and adversary simulations using MITRE ATT&CK, with court-admissible reporting responsibilities.
View JobIncident Response Lead
Coalition – Germany
Berlin
Lead cyber incident response engagements for customers in Germany and the wider region, conducting forensic investigations, analysing IOCs across Windows/Linux/macOS, and delivering remediation guidance in both German and English.
View JobIT-Forensik Analyst (Senior)
Hassmann IT-Forensik GmbH
Saarbrücken
Join a growing IT forensics team producing court-admissible expert reports. Responsibilities include evidence preservation, data processing and documentation. Suitable for qualified IT professionals at analyst or senior level, based onsite in Saarbrücken.
View JobIT-Forensiker
Response informations design
Ingolstadt
Full-time digital forensics examiner role producing impartial expert reports for prosecutors, courts, companies and private clients. Requires CS degree, experience with digital media, Python/C++ skills and fluent German.
View JobIT-Forensik Analyst
Hassmann IT-Forensik GmbH
Saarbrücken
IT forensics analyst role involving digital evidence acquisition from PCs, laptops, smartphones, tablets and consoles, plus data analysis, documentation and contribution to court-admissible expert reports. Onsite position in Saarbrücken.
View JobIncident Response Lead
Coalition, Inc.
Berlin
Lead cyber incident response engagements for customers in Germany, conducting forensic investigations, analysing compromised systems, identifying IOCs, managing breaches, and providing remediation guidance. Fluency in German and English required.
View JobUnited Arab Emirates
Incident Response Lead (DFIR), UAE
DeepSource Technologies
Dubai
Leads cybersecurity incident response and digital forensic investigations in enterprise environments, performing triage, containment, root cause analysis, and malware analysis while developing IR playbooks and coordinating cross-functional security teams.
View JobDigital Forensics and Incident Response Consultant
DTS Solution
Dubai
DFIR consultant role supporting cyber breach investigations, forensic and malware analysis, threat hunting, and post-compromise assessments. Requires court-ready reporting, chain of custody handling, and 6+ years’ experience with industry-standard forensic tools.
View JobSenior Digital Forensics Examiner
TransPerfect
Dubai
Senior examiner role performing forensic preservation and analysis of digital devices, mobile platforms and cloud systems. Responsibilities include evidence management, expert testimony, client reporting, and mentoring junior forensic practitioners.
View JobIndia
Sr Mgr Information Security
Amgen
Hyderabad, Telangana
Senior manager leading a digital forensics team in Hyderabad, overseeing investigations into cyber incidents, insider risk, eDiscovery and HR matters, while guiding tool workflows, evidence handling standards, and AI-assisted forensic capabilities.
View JobSenior Information Security Analyst
Eurofins GSC IT DC
Bengaluru, Karnataka
Senior SOC L3 analyst leading complex security incident investigations, containment and remediation. Role encompasses DFIR, memory forensics, malware triage, threat hunting, and mentoring junior analysts within a 24/7 global SOC environment.
View JobL2 SOC Analyst
UST
Bengaluru, Karnataka
Lead high-impact DFIR investigations across file systems, memory, and networks within a managed SOC environment. Responsibilities include incident response, malware analysis, custom tool development, root cause analysis, and scaling DFIR service delivery for clients.
View JobSenior DFIR Analyst
Barclays
Pune, Maharashtra
Senior DFIR analyst role responsible for digital forensic investigations, cyber incident response, security monitoring, log analysis, and threat detection within a large, complex enterprise banking environment. Requires strong forensic and IR skills across Windows, Linux, and Mac platforms.
View JobDFIR Expert (Lead)
UST
Bengaluru, Karnataka
Lead DFIR investigations across file systems, memory, and networks; manage incident response efforts as highest escalation point; develop automation tools; deliver root cause analysis reports; and help scale the DFIR service offering.
View JobT&T I Cyber: D&R I Manager | Incident Response & Handling
Deloitte
Bengaluru, Karnataka
Manages client incident response engagements, conducting DFIR analysis, malware triage, network forensics and threat intelligence. Leads and mentors IR staff, develops reports for technical and executive audiences, and supports business development.
View JobT&T | Cyber : D&R | Director | Incident Response & Handling
Deloitte
Delhi
Director-level DFIR role managing client incident response engagements, conducting forensic investigations, malware triage and network analysis, mentoring IR staff, and contributing to business development within a global consulting practice.
View JobSenior Information Security Incident Response Analyst
NTT DATA
Hyderabad, Telangana
Senior DFIR analyst role leading complex incident investigations and forensic analysis across host, disk, memory, network, cloud, and mobile environments. Mentors junior staff, guides clients through containment and remediation, and delivers technical findings to stakeholders.
View JobOSINT Analyst
Drona Cyber Solutions Pvt Ltd
Ahmedabad, Gujarat
Seeks an analyst to conduct open-source intelligence gathering, perform digital investigations, verify data, identify threats and risks, and produce actionable intelligence reports for investigations and risk assessments.
View JobSouth Africa
Senior Cyber Incident Response Analyst (Cape Town or Johannesburg)
Integrity360
Cape Town, Western Cape
Senior analyst role delivering incident response, threat hunting, host and network intrusion analysis, malware reverse engineering, digital forensics and cyber threat intelligence services for mid-market and enterprise customers across multiple sectors.
View JobInformation Security Team Leader
Sourceworx
South Africa
Leads cybersecurity operations including SOC monitoring, penetration testing, vulnerability management, and digital forensic investigations. Mentors a security team, oversees incident response, ensures evidence integrity, and supports risk governance and compliance frameworks.
View Job





