DFIR Analyst
SentinelOne
Israel
The Role
Operating within a 24x7x365 follow-the-sun DFIR team, analysts conduct hands-on forensic examination and incident response across endpoint, network, cloud, and SaaS environments. Day-to-day work spans evidence acquisition, threat hunting, malware and memory analysis support, case documentation, and contributing to formal investigative reports for global enterprise clients.
Skills & Experience
Candidates should bring solid grounding in EDR-driven incident response and vendor-agnostic forensic analysis, with exposure to malware and memory analysis. Familiarity with chain-of-custody procedures, common incident types such as ransomware and business email compromise, and the ability to distil complex technical findings for non-technical stakeholders are all expected.
Who It Suits
This foundational technical role suits an evidence-focused analyst who thrives under pressure, is committed to continuous learning, and wants to build deep DFIR expertise within a globally recognised cybersecurity organisation. Those comfortable with on-call rotations and cross-regional handovers will find the environment well-matched to their working style.





