DFIR Analyst
SentinelOne
Auckland
The Role
The analyst conducts digital forensic investigations and incident response across endpoint, network, cloud, and SaaS environments, covering ransomware, business email compromise, and identity compromise cases. Responsibilities include evidence acquisition, chain-of-custody management, containment support, case documentation, and contributing to customer-facing status updates and formal investigative reports.
Skills & Experience
Candidates need two or more years of hands-on DFIR or threat-hunting experience, ideally in a consulting environment. Proficiency with forensic tools such as X-Ways Forensics, Axiom, and FTK is expected, alongside familiarity with EDR/XDR platforms, SIEMs, network forensics, Windows artifact analysis, and scripting or automation capabilities.
Who It Suits
This role suits an early-to-mid career DFIR professional who thrives in fast-paced, high-pressure environments and is comfortable working a rotating on-call schedule. Those with a degree in digital forensics or cybersecurity and a consulting background will be well positioned to contribute across multi-region investigations.





