← All jobs · More in this country

DFIR Analyst

SentinelOne

Israel

Mid · Full-time

The Role

Operating within a 24x7x365 follow-the-sun DFIR team, analysts conduct hands-on forensic examination and incident response across endpoint, network, cloud, and SaaS environments. Day-to-day work spans evidence acquisition, threat hunting, malware and memory analysis support, case documentation, and contributing to formal investigative reports for global enterprise clients.

Skills & Experience

Candidates should bring solid grounding in EDR-driven incident response and vendor-agnostic forensic analysis, with exposure to malware and memory analysis. Familiarity with chain-of-custody procedures, common incident types such as ransomware and business email compromise, and the ability to distil complex technical findings for non-technical stakeholders are all expected.

Who It Suits

This foundational technical role suits an evidence-focused analyst who thrives under pressure, is committed to continuous learning, and wants to build deep DFIR expertise within a globally recognised cybersecurity organisation. Those comfortable with on-call rotations and cross-regional handovers will find the environment well-matched to their working style.

Learn More/Apply

Applications are handled entirely by the employer or the original listing site. Forensic Focus aggregates and summarises public listings; details can change after publication — always confirm on the employer's page.

Listed: 2026-09-11