Digital Forensics and Incident Response (DFIR) Consultant

Reposted One Month Ago
Hiring Remotely in Miami, FL, USA
In-Office or Remote
Junior
Information Technology • Professional Services • Consulting • Cybersecurity
The Role
Respond to ransomware and cyber incidents: collect forensic disk/memory images, triage Windows/Unix systems, analyze logs and artifacts for IOCs, perform malware and threat research, build timelines, apply remediation, and support clients and partners during deployments.
Summary Generated by Built In

About the Role
The Consultant is an engagement delivery contributor within CYPFER's DFIR and Post-Breach Recovery practice. Operating at the task execution level, the Consultant works alongside senior practitioners on active incident response and recovery engagements — collecting evidence, executing playbooks, triaging artefacts, and producing client-ready documentation. The role interacts directly with insurance partners, legal counsel, client technical teams, and executives as part of structured engagement delivery. This is a hands-on role suited to early-career cybersecurity professionals building deep technical expertise across DFIR and PBR.

Core Responsibilities: 

  • Understand the client challenge and objective; execute defined tasks in line with engagement scope and the path to recovery.
  • Deliver discrete work packages including forensic acquisition, IOC triage, and recovery steps under the direction of senior team members.
  • Maintain accurate case notes and produce client-ready artefacts; adhere to SOPs and QA standards throughout all engagements.
  • Escalate risks early; follow chain-of-custody and compliance requirements at all times.
  • Analyze triage collections and artefacts for indicators of compromise (IoCs) and potentially malicious activity.
  • Review logs from host systems and appliances to identify suspicious activities.
  • Collect forensic disk and memory images from physical and virtual endpoints and servers.
  • Contribute to event correlation and the building of engagement timelines under senior guidance.
  • Conduct initial threat research based on IOCs collected during investigations.
  • Participate in a rotating on-call schedule; ability to work on weekends and outside normal business hours as needed.
  • This role is remote but requires the ability to travel on short notice to a client site up to 50%. Must maintain flexibility to travel within 24–48 hours' notice for deployments typically 1–2 weeks in duration.

Technical Requirements: 

  • 1–3 years of experience in incident response, digital forensics, or a related cybersecurity role.
  • Working knowledge of endpoint forensics — acquire and preserve evidence from physical and virtual systems, and triage artefacts to support investigations; SANS FOR500 (GCFE) certification is an asset.
  • Hands-on experience operating EDR platforms (e.g., CrowdStrike Falcon) for threat hunting, host isolation, and telemetry collection; vendor EDR certification (e.g., Falcon Administrator) is an asset.
  • Ability to execute DFIR and PBR playbooks accurately under guidance, following structured SOPs from initial triage through to recovery.
  • Ability to produce clear, accurate, client-ready case notes and reports throughout an engagement.
  • Familiarity with IR orchestration platforms or case management tooling is an asset.

Business Responsibilities: 

  • Exhibit strong customer service and consulting skills in all client interactions.
  • Adhere to client and internal policies, procedures, and security practices.
  • Remain calm, composed, and articulate in high-pressure client situations.
  • Exhibit excellent relationship management and communication skills.
  • Ensure a high level of confidentiality due to having access to sensitive client and incident data.

Preferred Skills: 

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field — or equivalent hands-on experience.
  • Industry certifications such as GCFE, GCIH, or similar are a strong asset.
  • Familiarity with SIEM and SOAR solutions.
  • Exposure to threat hunting, network forensics, or malware analysis methodologies.
  • Experience in a professional services or consulting environment
  • Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar are a plus. 

Compensation package includes a base salary, medical benefits and multiple bonus opportunities. 

Cypfer is an equal opportunity employer. If you need accommodation during the interview process or beyond, please let us know. We celebrate our inclusive work environment and welcome applicants from all backgrounds and perspectives. 

We thank you for your interest in joining the Cypfer team! While we welcome all applicants, only those selected for an interview will be contacted. 

Skills Required

  • 2+ years of experience in digital forensics, incident response, or a similar role.
  • Knowledge of Windows and Unix/Linux operating systems.
  • Understanding of the functionality of EDR / EPP technologies.
  • Familiarity with forensic acquisition and analysis of physical and virtual systems.
  • Working knowledge of storage technologies such as RAID, NAS, SAN, Fiber Channel, iSCSI, and NFS.
  • Ability to analyze and interpret logs from various sources.
  • Ability to perform threat research and analyze current threats.
  • Understanding of business email compromise (BEC) cases and investigation techniques.
  • Participate in a rotating on-call schedule; ability to work weekends and outside normal business hours.
  • Ability to travel on short notice to client sites up to 50% for 1-2 week deployments.
  • Familiarity with SIEM and SOAR solutions.
  • Experience with e-discovery tools and methodologies.
  • Proficiency in collecting and analyzing data from mobile devices/cell phones.
  • Familiarity with malware analysis tools and methodologies.
  • Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
140 Employees
Year Founded: 2019

What We Do

CYPFER is a global leader in cybersecurity, specializing in cyber-attack incident response and ransomware post-breach recovery. The firm provides a comprehensive suite of services, including ransomware remediation, digital forensics, and cyber risk management, aimed at delivering 'Cyber Certainty™.' Their in-house team of experts supports organizations worldwide 24/7, helping them recover from cyber-extortion incidents and strengthen their overall digital resilience.

Similar Jobs

CYPFER Logo CYPFER

Consultant

Information Technology • Professional Services • Consulting • Cybersecurity
In-Office or Remote
Miami, FL, USA
140 Employees

FloQast Logo FloQast

Accountant

Artificial Intelligence • Fintech • Software
In-Office or Remote
2 Locations
800 Employees
150K-190K Annually

Samsara Logo Samsara

Manager, Firmware Engineering

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
155K-260K Annually
Easy Apply
Remote
United States
900 Employees
100K-110K Annually

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account