German Digital Forensics and Incident Response (DFIR) Consultant

Posted 10 Hours Ago
Be an Early Applicant
Hiring Remotely in Utrecht, NLD
In-Office or Remote
Junior
Information Technology • Professional Services • Consulting • Cybersecurity
The Role
Perform DFIR engagements: collect forensic disk and memory images, analyze host and appliance logs, triage Windows and Unix systems, identify IOCs, build timelines, support malware analysis, apply mitigation/remediation, participate in on-call rotations, and travel for short-notice deployments.
Summary Generated by Built In

CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware events. Our team collaborates with prominent global insurance carriers, leading law firms, and Fortune 1000 businesses. 


Core Responsibilities: 

  • Engage on behalf of CYPFER in incident response tasks, interacting with various insurance partners, legal counsel, incident response units, client executives, and technical teams. 
  • Utilize standard tools and methodologies to collect forensic artifacts and images from affected systems. 
  • Assist with Windows forensics and triage to assess compromise and investigations. 
  • Familiarity with malware analysis tools and methodologies. 
  • Apply mitigation strategies and concepts to remediate identified threats. 
  • Analyze triage collections/artifacts for indicators of compromise (IOCs) and potentially malicious activity. 
  • Review logs from host systems and appliances to identify suspicious activities. 
  • Collect forensic disk and memory images from physical and virtual endpoints and servers. 
  • Understanding of an incident lifecycle and cyber-kill-chain. 
  • Correlate events and build timelines of events. 
  • Maintain current knowledge on emerging threats and vulnerabilities.  
  • Analyze files for IOCs using various techniques. 

Technical Requirements:

  • Bilingual English and German 
  • 2+ years of experience in digital forensics, incident response, or a similar role. 
  • Knowledge of Windows and Unix/Linux operating systems. 
  • Understanding of the functionality of EDR / EPP technologies. 
  • Familiarity with forensic acquisition and analysis of physical and virtual systems. 
  • Working knowledge of storage technologies such as RAID, NAS, SAN, Fiber Channel, iSCSI, and NFS. 
  • Ability to analyze and interpret logs from various sources. 
  • Ability to perform threat research and analyze current threats. 
  • Understanding of business email compromise (BEC) cases and investigation techniques. 
  • Participate in a rotating on-call schedule; ability to work on weekends and outside normal business hours as needed. 
  • This role is remote but requires the ability to travel on short notice to a client site up to 50%. Must maintain flexibility to travel frequently within 24-48 hours' notice for deployments typically 1-2 weeks in duration. 

Business Responsibilities: 

  • Maintain current knowledge of information security, incident response techniques, emerging threats, and tools. 
  • Work independently and produce high-quality deliverables with minimal supervision. 
  • Exhibit strong customer service and consulting skills. 
  • Adhere to client and internal policies, procedures, and security practices. 
  • Maintain detailed notes and draft updates and reports as required. 
  • Remain calm, composed, and articulate in tough customer situations. 
  • Exhibit excellent relationship management and communication skills. 

Preferred Skills: 

  • Understand obfuscation techniques used to conceal malicious commands and traffic, and lateral movement strategies employed by threat actors. 
  • Familiarity with exfiltration techniques used by threat actors. 
  • Knowledge of SIEM and SOAR solutions. 
  • Experience with e-discovery tools and methodologies. 
  • Proficiency in collecting and analyzing data from mobile devices/cell phones. 
  • Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar are a plus. 

Compensation package includes a base salary, medical benefits and multiple bonus opportunities. 


CYPFER is an equal opportunity employer. If you need accommodation during the interview process or beyond, please let us know. We celebrate our inclusive work environment and welcome applicants from all backgrounds and perspectives. 


We thank you for your interest in joining the CYPFER team! While we welcome all applicants, only those selected for an interview will be contacted. 

 

Skills Required

  • Bilingual English and German
  • 2+ years experience in digital forensics or incident response
  • Knowledge of Windows and Unix/Linux operating systems
  • Understanding of EDR/EPP technologies
  • Familiarity with forensic acquisition and analysis of physical and virtual systems
  • Experience collecting forensic disk and memory images
  • Working knowledge of storage technologies (RAID, NAS, SAN, Fiber Channel, iSCSI, NFS)
  • Ability to analyze and interpret logs from various sources
  • Ability to perform threat research and analyze current threats
  • Understanding of business email compromise (BEC) investigations
  • Participate in rotating on-call schedule and work outside normal hours/weekends as needed
  • Ability to travel on short notice to client sites up to 50%
  • Maintain detailed notes and produce high-quality deliverables with minimal supervision
  • Strong customer service, consulting, and communication skills
  • Familiarity with obfuscation, lateral movement, and exfiltration techniques
  • Knowledge of SIEM and SOAR solutions
  • Experience with e-discovery tools and methodologies
  • Proficiency collecting and analyzing mobile device data
  • Industry certifications (MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
140 Employees
Year Founded: 2019

What We Do

CYPFER is a global leader in cybersecurity, specializing in cyber-attack incident response and ransomware post-breach recovery. The firm provides a comprehensive suite of services, including ransomware remediation, digital forensics, and cyber risk management, aimed at delivering 'Cyber Certainty™.' Their in-house team of experts supports organizations worldwide 24/7, helping them recover from cyber-extortion incidents and strengthen their overall digital resilience.

Similar Jobs

CYPFER Logo CYPFER

Consultant

Information Technology • Professional Services • Consulting • Cybersecurity
In-Office or Remote
Utrecht, NLD
140 Employees

HiBob Logo HiBob

Sales Engineer

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
Netherlands
1350 Employees

Tufin Logo Tufin

Consultant

Security • Cybersecurity
Remote or Hybrid
27 Locations
500 Employees

Datadog Logo Datadog

Senior Sales Engineer

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
4 Locations
6500 Employees

Similar Companies Hiring

Amplify Platform Thumbnail
Fintech • Financial Services • Consulting • Cloud • Business Intelligence • Big Data Analytics
Scottsdale, AZ
62 Employees
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account