Senior Consultant, DFIR, Reactive Services (Unit 42)

The Role This position sits within a specialist incident response practice, where consultants investigate active cybersecurity incidents, conduct forensic analysis, and support client recovery efforts. Day to day, work involves collaborating with senior practitioners across varied client environments, contributing technical

Senior Incident Response Consultant, DFIR

The Role Consultants lead end-to-end incident response engagements for external clients, conducting digital forensics investigations, malware analysis, and threat actor attribution. The position requires 24/7 on-call availability, remote and on-site deployment, executive briefings, and maintaining a 75% billable utilisation target

Senior DFIR Consultant – Remote (Anywhere in the U.S.)

The Role This fully remote position involves leading and executing complex digital forensics and incident response investigations, including host forensics, network traffic analysis, log review, malware triage, and business email compromise analysis. The consultant communicates findings to both technical and

Senior Incident Response Consultant | USA, Remote | $120,000 – $155,000

The Role This position leads complex digital forensic investigations from initial triage through containment and recovery, covering host, network, cloud, and application environments. Consultants direct client teams during live incidents, scope engagements, develop detection logic from attacker behaviour, and deliver

Principal DFIR Consultant

The Role This senior consulting position leads digital forensics and incident response engagements, with a focus on business email compromise and ransomware cases. Day to day, the work spans forensic investigation, log and artifact analysis, containment support, client communication, team

Lead Cyber Incident Response Consultant

The Role This position leads complex cyber security incident investigations end to end, performing advanced digital forensics across Windows, Linux, macOS, and multi-cloud environments. Day to day involves analysing logs, network traffic, memory, and disk artefacts, maintaining chain-of-custody, and delivering

Senior Incident Response Security Consultant, Mandiant, Google Cloud (Hebrew)

The Role This remote position, based in Israel, involves leading end-to-end incident response engagements for clients, encompassing forensic investigation, threat hunting, malware triage, containment, and remediation. Consultants communicate findings to technical teams and executive stakeholders, manage crisis situations, and occasionally

Sr. Cyber Analyst, Digital Forensics Incident Response

The Role This position involves conducting end-to-end incident investigations for insured clients, including evidence collection, forensic analysis, timeline development, and root cause identification. The analyst also participates in threat actor negotiations, supports recovery efforts, produces detailed incident reports, and delivers

CTN – Digital Forensics/Law Enforcement Integration SME

The Role This remote position supports a DoD counter-narcotics programme by providing senior technical expertise to a partner-nation defence force. Day-to-day work involves designing and delivering training curricula, integrating digital forensics with law-enforcement workflows, mentoring local personnel, and improving interagency

DFIR Consultant

The Role This fully remote position involves supporting clients through the full lifecycle of cyber incidents, from initial triage and evidence preservation through forensic analysis and final reporting. Day-to-day work centres on investigating Business Email Compromise and ransomware cases, delivering

Incident Response Senior Consultant (Remote)

The Role This position involves leading incident response engagements for major organisations, investigating breaches, analysing attacker behaviour, and delivering technical findings. Consultants work remotely across a varied caseload, responding to complex, high-profile incidents and helping clients understand and contain advanced

Principal Incident Response Security Consultant, Mandiant

The Role This senior consulting position involves leading end-to-end incident response engagements for clients facing complex, high-profile security incidents. Day-to-day responsibilities include conducting forensic investigations, performing threat hunting, triaging malware, supporting containment and remediation efforts, and communicating findings to both

Incident Response Principal Consultant (Remote)

The Role This position involves leading complex incident response engagements for major global organisations, investigating breaches, analysing threat actor activity, and delivering expert guidance throughout the full incident lifecycle. Consultants work across a varied caseload, handling high-profile investigations that demand

Incident Response Principal Consultant (Remote)

The Role This remote position involves leading complex incident response investigations for major global organisations, responding to advanced cyber threats and breaches. Day to day, consultants conduct forensic analysis, manage high-stakes engagements, and advise clients on containment and remediation strategies

Principal Incident Response Security Consultant, Mandiant

Senior Mandiant consultant managing complex incident response engagements, performing digital forensics, threat hunting, and malware analysis across cloud and on-premise environments, while communicating findings to executive and legal stakeholders.

Incident Response Senior Consultant (Remote, CAN)

Lead incident response engagements and intrusion investigations for global organisations, conducting host and network forensics across Windows, Mac and Linux, performing malware analysis, and delivering findings to senior stakeholders.

Senior Incident Response Consultant, DFIR

The Role This position leads digital forensics and incident response engagements for external clients facing active cybersecurity threats. Day-to-day work includes malware analysis, forensic examination of compromised systems, threat actor attribution, and delivering executive briefings, with 24/7 on-call availability and

Consulting Director, DFIR, Reactive Services (Unit 42)

The Role This senior position leads cybersecurity incident response and digital forensics engagements for enterprise clients, combining strategic advisory responsibilities with hands-on technical leadership. Day to day involves guiding organisations through complex breaches, overseeing forensic investigations including memory and disk

Digital Forensic Examiner (Remote 10-99)

The Role The examiner analyses digital evidence from computers, mobile devices, cloud environments, and data return packages obtained via legal process, such as those from Google, iCloud, and Facebook. Work also includes preparing clear forensic reports, collaborating with attorneys and

Consulting Director, DFIR, Reactive Services (Unit 42)

Senior consulting director leading technical breach response teams and delivering expert DFIR guidance to clients across industries. Requires 10+ years hands-on experience with forensic tools, threat landscape knowledge, and strong client relationship management.

DFIR Consultant

Join a specialist DFIR team responding to BEC and ransomware incidents. Responsibilities include evidence acquisition, forensic analysis, malware triage, timeline development, client communication, and written reporting across endpoint, server, and cloud environments.

DFIR Consultant

The Role This position involves conducting digital forensics and incident response investigations across Windows and Linux environments. Day to day, the consultant collects disk and memory images, analyses forensic artefacts for indicators of compromise, reviews host and appliance logs, builds

DFIR Cybersecurity Consultant (Remote)

Conduct forensic analysis and incident response investigations covering ransomware, business email compromise and litigation support. Collect and analyse data, produce technical reports, develop modern forensic techniques, and assist with EDR deployment and triage.

Senior DFIR Specialist

The Role This remote position involves leading hands-on digital forensics and incident response engagements across enterprise and regulated environments. Day to day, the specialist investigates active incidents, preserves and analyses evidence, and guides clients through containment, eradication, and recovery, while

Senior Information Security Incident Response Analyst

The Role This senior position leads complex security incident investigations and digital forensic examinations across host, disk, memory, network, cloud, and mobile environments. Day to day, the analyst guides clients through containment and recovery, reconstructs event timelines, communicates findings to

Principal DFIR Consultant – Remote (Anywhere in the U.S.)

The Role This senior individual contributor position leads the most complex and high-visibility incident response engagements, including ransomware, APT, and insider threat cases. Day to day involves conducting advanced host forensics, network analysis, cloud forensics, and malware triage, while also

Director, DFIR (Remote)

The Role This fully remote position involves leading digital forensics and incident response engagements across a range of cyber threats, including ransomware and data theft. The director oversees multiple concurrent incidents, coordinates cross-functional teams, and liaises with external stakeholders such

Principal DFIR Consultant

The job posting is cut off at “Client Management And” but I have enough information to write the description. Let me craft the HTML with the three required sections. Key points from the posting: – Principal DFIR Consultant, remote USA

Principal Consultant, Digital Forensic and Incident Response (DFIR) (Remote)

The Role This fully remote position involves leading digital forensics and incident response engagements across a range of industries, conducting sophisticated forensic analysis, managing investigations of varying complexity, and serving as a senior technical expert for clients navigating active cyber

Principal Consultant, DFIR, Reactive Services (Unit 42) – Remote Weekend Shift

The Role This senior individual contributor position involves leading expert-level incident response and digital forensics engagements across diverse industries. Day to day, consultants conduct forensic investigations, analyse attacker activity, assess scope and impact, and guide clients through containment, remediation, and

Contract Bench, Incident Responder (DFIR)

The Role This contract position involves conducting digital forensic investigations and incident response engagements on a flexible, as-needed basis. Responders analyse live response data, investigate threat actor activity across Windows environments and cloud platforms, and help eradicate adversaries across clients’

Senior Consultant, DFIR (Wed-Sun)

The Role This position involves leading digital forensics and incident response engagements across modern enterprise environments, investigating threat actor activity on endpoints, cloud platforms including AWS, Azure, and GCP, SaaS applications, and identity providers, while supporting clients through active incidents

Senior Incident Response Consultant

The Role This position leads forensic investigations across host, network, and application environments while guiding clients through containment, remediation, and recovery. Day to day involves triaging active security incidents, identifying attacker tactics, developing investigative tooling, producing reports, and working directly

Principal Engagement Lead (Remote)

The Role This fully remote position centres on leading multiple concurrent cybersecurity incident response engagements, serving as the primary point of contact for clients, insurance carriers, and legal counsel. Day-to-day responsibilities include scoping engagements, coordinating cross-functional response teams, and driving

ICITAP Forensic Digital Evidence Advisor

The Role This advisory position involves delivering specialist training and mentorship to host-country law enforcement professionals on the collection, preservation, examination, and court presentation of digital evidence, including data recovered from mobile devices, computers, and other digital sources, in support

Senior Incident Response Security Consultant, Mandiant, Google Cloud

The Role This senior-level position involves leading end-to-end incident response engagements for clients facing complex, high-profile security incidents. Day to day, consultants perform forensic analysis across network, disk, memory, and cloud environments, conduct threat hunting, triage malware, and support containment,

Incident Response Security Consultant, Mandiant (English)

The Role This position involves leading end-to-end incident response engagements, helping organisations detect, contain, and recover from security incidents. Day to day work spans forensic investigation, malware triage, threat analysis, and communicating findings to both technical teams and senior stakeholders,

Incident Response Security Consultant, Mandiant (English)

The Role This position involves leading end-to-end incident response engagements, helping organisations detect, contain, and recover from security incidents. Day-to-day work spans network forensics, malware triage, cloud and memory analysis, and communicating findings clearly to both technical teams and executive

Principal Consultant, Incident Response (Weekend Schedule)

The Role This position involves leading client-facing incident response engagements on a Friday-to-Monday schedule, working ten hours per day. Responsibilities include scoping work, managing forensic investigations end to end, advising clients on immediate containment measures, and providing long-term remediation guidance

Senior Information Security Incident Response Analyst

The Role This senior position leads complex security incident investigations, performing forensic analysis across host, disk, memory, network, cloud, and mobile environments. The analyst guides clients through containment and recovery, reconstructs event timelines, communicates findings to technical and executive audiences,

Senior Incident Response Security Consultant, Mandiant, Google Cloud

The Role This senior consulting position centres on leading end-to-end incident response engagements for clients facing complex, high-profile cyber incidents. Day-to-day responsibilities include forensic analysis across disk, memory, network, and cloud environments, threat hunting, malware triage, containment, remediation, and crisis

Principal Consultant, Incident Response (Weekend Schedule)

The Role This position centres on leading end-to-end incident response engagements for a range of clients, covering initial scoping, forensic investigation, containment, and long-term remediation guidance. It operates on a Friday-to-Monday schedule, ten hours per day, with Tuesday through Thursday

Principal Consultant, Incident Response (Unit 42)

The Role This position leads end-to-end incident response engagements for clients, managing scope, guiding forensic investigations, and overseeing containment and remediation. Day to day involves hands-on host-based analysis across Windows, Linux, and macOS environments, as well as reviewing firewall, web,

Cyber Security Analyst

The Role This position leads complex cyber security incident investigations across diverse technology environments, performing advanced digital forensics on Windows, Linux, macOS and multi-cloud platforms. Day-to-day responsibilities include analysing logs, network traffic and memory artefacts, establishing attacker timelines, preserving evidence

Digital Forensics Consultant (PST hours)

The Role This position involves conducting forensic collections of electronically stored information from computers, mobile devices, servers, cloud platforms, and other digital sources, both on-site and remotely. Day-to-day work includes forensic analysis supporting investigations and litigation, preparing detailed reports and

Senior Incident Response Security Consultant, Mandiant, Google Cloud (Hebrew)

The Role This senior consulting position involves leading end-to-end incident response engagements for clients, covering investigation, containment, remediation, and crisis management. Day-to-day work includes forensic analysis across network, cloud, disk, and memory environments, as well as threat hunting, malware triage,

Senior Consultant, Digital Forensic and Incident Response (DFIR) (Remote)

The Role This fully remote position sits within a collaborative incident response team, where the successful candidate leads and supports investigations into cyber incidents including ransomware, business email compromise, malware, and data theft, conducting forensic analysis and delivering clear, high-quality

German Senior Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves leading complex incident response engagements and conducting forensic investigations across Windows, Unix, Linux, and network environments. Day-to-day work includes collecting forensic artifacts, analysing logs and memory images, identifying indicators of compromise, and applying remediation strategies

Dutch Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves hands-on incident response work, including collecting forensic artifacts, analysing disk and memory images, reviewing host and appliance logs, and building event timelines. The consultant collaborates with insurers, legal teams, and client technical staff to assess

Cyber Analyst, Digital Forensics Incident Response

The Role Analysts conduct end-to-end incident response engagements for insured businesses, including forensic evidence collection, compromise analysis, timeline reconstruction, and root cause identification. Responsibilities also extend to threat actor negotiations, recovery support, report writing, and delivering tailored training and simulations

Junior DFIR Analyst

The Role The analyst supports incident response operations around the clock, conducting live endpoint investigations, gathering forensic artifacts, performing traffic analysis, and producing technical reports for clients. The role also involves contributing to the development of IR processes, maintaining incident

German Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves responding to cyber incidents on behalf of clients, conducting Windows and Unix/Linux forensic investigations, collecting disk and memory images from physical and virtual systems, analysing artefacts for indicators of compromise, reviewing host and appliance logs,

Senior iOS Forensics Engineer

The Role This full-time remote position centres on developing and maintaining sophisticated forensic tooling for iOS devices. Day to day, the engineer analyses iOS internals, extracts and preserves digital evidence, builds automated data collection workflows, reverse engineers system components, and

DFIR Senior Cybersecurity Consultant (Remote)

The Role This position leads forensic analysis and incident response engagements across a range of cases including ransomware, business email compromise, and litigation support. Day to day involves collecting and analysing data, producing high-quality technical reports, mentoring junior team members,

Senior Director, Digital Forensics and Incident Response

The Role This senior leadership position involves commanding complex cyber investigations end-to-end, from initial response through containment and recovery. Day to day, the role spans ransomware, business email compromise, cloud and identity compromise, and insider threat investigations, alongside executive briefings,

Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves responding to active cyber incidents, conducting forensic acquisition and analysis of physical and virtual systems, reviewing host and appliance logs, correlating events into timelines, and applying mitigation strategies to contain and remediate threats such as

Corporate Forensic Analyst

The Role This position centres on conducting structured digital forensic examinations across Windows computers, mobile devices, cloud platforms and email environments. Day-to-day work involves acquiring and analysing evidence from dead-box investigations, supporting business email compromise and ransomware cases, and contributing

Principal Consultant, Cloud DFIR (Unit 42) – Remote

The Role This senior individual contributor position focuses on leading cloud-focused incident response and digital forensics investigations across AWS, Azure, GCP, and hybrid enterprise environments. Day to day involves acting as technical lead on active security incidents, scoping breaches, containing

Security Incident Responder (m/w/d)

The Role Practitioners lead technical responses to active cyber incidents, primarily ransomware and business email compromise cases, on behalf of mid-sized organisations. Day-to-day work spans log analysis, attack vector investigation, containment planning, system recovery, and producing forensic reports that support

Principal Consultant, Incident Response

The Role This position leads client-facing incident response engagements from initial scoping through to resolution, conducting host-based forensic analysis across Windows, Linux, and macOS environments, examining log sources including firewalls and databases, and guiding organisations through containment and long-term remediation

Principal Consultant, DFIR, Reactive Services (Unit 42)

The Role This position involves leading and managing incident response engagements on a reactive basis, conducting host-based forensic analysis across Windows, Linux, and macOS environments, examining diverse log sources to uncover malicious activity, investigating data breaches, and providing clients with

Principal Consultant, DFIR, Reactive Services (Unit 42)

The Role This position involves leading and managing incident response engagements on a reactive basis, conducting host-based forensic analysis across Windows, Linux, and macOS environments, examining diverse log sources to uncover malicious activity, investigating data breaches, and advising clients on