Incident response researcher/ DFIR
Undisclosed
Center District
The Role
This position involves conducting forensic investigations and incident response engagements across complex, large-scale cyberattacks. Day to day, the analyst performs log analysis, host and network forensics, threat hunting in client environments, and security simulations, while producing detailed professional reports and collaborating closely with IT and security teams.
Skills & Experience
A minimum of three years in DFIR or advanced threat investigation is required, alongside strong knowledge of the MITRE ATT&CK framework, Windows and Linux forensic artefacts, network protocols, and firewall and proxy log analysis. Cloud investigation experience covering Microsoft 365, Azure AD, and AWS CloudTrail is also expected.
Who It Suits
This role suits an experienced DFIR professional, whether from a military or industry background, who thrives in fast-paced, high-stakes environments. Someone who enjoys proactively hunting emerging threats, developing investigative tooling, and communicating complex technical findings clearly to varied stakeholders will find this position a strong fit.





