DFIR
Cyesec
United States
The Role
This position sits at the front line of cyber defence, handling the full incident response lifecycle for clients worldwide. Day to day, practitioners perform digital forensic investigations across Windows, Linux, and cloud environments, conduct proactive threat hunting, analyse adversary TTPs, and collaborate closely with red team, threat intelligence, and cyber architecture colleagues.
Skills & Experience
One to two years of hands-on DFIR experience is expected, along with solid knowledge of network forensics, threat hunting models, TTP and IoC analysis, and cloud platforms such as Azure and AWS. Proficiency with data analysis tools including Splunk, Elasticsearch, SQL, or VQL is required, alongside strong written and verbal English communication skills.
Who It Suits
This role suits an early-career DFIR professional eager to work on complex, real-world incidents across diverse enterprise environments. It is particularly well matched to someone comfortable engaging directly with CISOs and global technology leaders, who thrives under pressure and wants exposure to both forensic investigation and proactive threat hunting work.
Typical advertised salary for Incident Response roles in United States: $125,000–$179,000 (median $149,000 — from 108 recent listings analysed by Forensic Focus).
Learn More/Apply





