Senior Digital Forensics and Incident Response (DFIR) Consultant

Reposted One Month Ago
Be an Early Applicant
Hiring Remotely in Miami, FL, USA
In-Office or Remote
Senior level
Information Technology • Professional Services • Consulting • Cybersecurity
The Role
Lead and perform digital forensics and incident response engagements, collecting disk and memory images, analyzing logs and artifacts for IOCs, building timelines, and applying mitigation strategies. Coordinate with insurers, legal counsel, and client teams, conduct malware and threat research, and produce detailed reports. Participate in on-call rotations and deploy to client sites as needed.
Summary Generated by Built In

About the Role 

The Senior Consultant leads small workstreams within active incident response and recovery engagements, coordinating Consultants and ensuring deliverable quality and alignment with client objectives. Operating under the direction of a Manager or Senior Manager, the Senior Consultant owns workstream planning, validates technical outputs, and presents interim findings to client stakeholders — while continuing to execute hands-on DFIR and PBR tasks across insurance, legal, and enterprise client engagements. The role sits at the intersection of technical execution and emerging service delivery leadership. 

  Core Responsibilities 

  • Understand the client challenge and objective; ensure operational tasks across the workstream are executed in line with the path to recovery. 
  • Lead small workstreams under the supervision of a Manager or Senior Manager; coordinate task execution across the team and ensure deliverable quality and alignment with client objectives. 
  • Own workstream planning, stand-ups, and risk tracking across active engagements. 
  • Validate technical outputs; present interim findings to client stakeholders and manage expectations. 
  • Deliver discrete work packages including forensic acquisition, IOC triage, and recovery steps. 
  • Maintain accurate case notes and produce client-ready artefacts; adhere to SOPs and QA standards throughout all engagements. 
  • Escalate risks early; follow chain-of-custody and compliance requirements at all times. 
  • Analyze triage collections and artefacts for indicators of compromise (IoCs) and potentially malicious activity. 
  • Review logs from host systems and appliances to identify suspicious activities. 
  • Collect forensic disk and memory images from physical and virtual endpoints and servers. 
  • Own and drive event correlation and timeline construction across the engagement. 
  • Conduct independent threat research based on IOCs collected during investigations, and direct junior team members in targeted research tasks. 
  • Participate in a rotating on-call schedule; ability to work on weekends and outside normal business hours as needed. 
  • This role is remote but requires the ability to travel on short notice to a client site up to 50%. Must maintain flexibility to travel within 24–48 hours' notice for deployments typically 1–2 weeks in duration. 

  Technical Requirements 

  • 3–5+ years of experience in incident response, digital forensics, or a related cybersecurity role. 
  • Advanced capability in DFIR and post-breach recovery analysis — able to perform deeper forensic investigation and lead technical analysis workstreams; GCFA or GCFR certification is strongly preferred. 
  • Demonstrated ability to coordinate plans, tasks, and risks across an engagement workstream with multiple contributors, maintaining quality and alignment with client objectives. 
  • Experience presenting interim findings to client stakeholders, managing expectations, and leading the creation of client-ready deliverables. 
  • Basic scripting proficiency in Python and/or PowerShell to automate forensic or recovery tasks. 
  • Working knowledge of endpoint forensics — evidence acquisition, preservation, and artefact triage across physical and virtual systems. 
  • Hands-on experience operating EDR platforms (e.g., CrowdStrike Falcon) for threat hunting, host isolation, and telemetry collection. 
  • Familiarity with SIEM, SOAR, or IR orchestration platforms. 
  • Ability to perform estimation and short-cycle planning within an engagement workstream. 

  Business Responsibilities 

  • Exhibit strong customer service and consulting skills in all client interactions. 
  • Adhere to client and internal policies, procedures, and security practices. 
  • Remain calm, composed, and articulate in high-pressure client situations. 
  • Exhibit excellent relationship management and communication skills. 
  • Ensure a high level of confidentiality due to having access to sensitive client and incident data. 

  Preferred Skills 

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field — or equivalent hands-on experience. 
  • Industry certifications such as GCFA, GCFR, GCIH, CCFR, CCHF, AWS Certified or similar are a strong asset. 
  • Exposure to threat hunting, network forensics, or malware analysis methodologies. 
  • Experience in a professional services or consulting environment. 


Skills Required

  • 8+ years of experience in digital forensics, incident response, or similar
  • Knowledge of Windows and Unix/Linux operating systems
  • Understanding of EDR / EPP technologies
  • Familiarity with forensic acquisition and analysis of physical and virtual systems
  • Working knowledge of storage technologies: RAID, NAS, SAN, Fibre Channel, iSCSI, NFS
  • Ability to analyze and interpret logs from various sources
  • Ability to perform threat research and analyze current threats
  • Understanding of business email compromise (BEC) investigations
  • Experience with malware analysis tools and methodologies
  • Participate in rotating on-call schedule and work outside normal hours/weekends as needed
  • Ability to travel on short notice to client sites up to 50%, deployments typically 1-2 weeks
  • Strong customer service, consulting, communication, and relationship management skills
  • Maintain detailed notes and produce high-quality deliverables and reports
  • Understanding of obfuscation, lateral movement, and exfiltration techniques
  • Familiarity with SIEM and SOAR solutions
  • Experience with e-discovery tools and methodologies
  • Proficiency in mobile device/cell phone data collection and analysis
  • Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
140 Employees
Year Founded: 2019

What We Do

CYPFER is a global leader in cybersecurity, specializing in cyber-attack incident response and ransomware post-breach recovery. The firm provides a comprehensive suite of services, including ransomware remediation, digital forensics, and cyber risk management, aimed at delivering 'Cyber Certainty™.' Their in-house team of experts supports organizations worldwide 24/7, helping them recover from cyber-extortion incidents and strengthen their overall digital resilience.

Similar Jobs

AdAction Logo AdAction

Recruiter

AdTech • Digital Media • Marketing Tech • Mobile
Remote
United States
50 Employees

Shield AI Logo Shield AI

Director, Enterprise Strategy and Operations (R5626)

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
In-Office or Remote
4 Locations
190K-290K Annually

Zscaler Logo Zscaler

Account Executive

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
Florida, USA
8697 Employees
170K-205K Annually

Samsara Logo Samsara

Principal Product Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
137K-245K Annually

Similar Companies Hiring

Axle Health Thumbnail
Artificial Intelligence • Healthtech • Information Technology • Logistics
Santa Monica, CA
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account