Fyerx logo

Digital Forensics and Incident Response (DFIR) Specialist

Hiring from
Probably Worldwide
Work type
Remote
Posted
Sep 23, 2026
Is this job info correct?

Job Description

This is a remote position.

Digital Forensics and Incident Response (DFIR) Specialist

Job Details
  • Employment Type: Contract
  • Work Mode: Remote
  • Location: Offshore
  • Total Experience Required: 5 to 8 years
  • Relevant Experience Required: 4+ years of dedicated experience conducting digital forensics investigations and deep incident response execution
  • Mandatory Certification: GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), or Certified Computer Examiner (CCE)

Job Summary
We are seeking an experienced DFIR Specialist to lead our post-breach investigation pipelines, threat containment lifecycles, and digital forensics operations. The ideal candidate will isolate compromised systems, perform low-level disk and memory trace analyses, reconstruct complex attack timelines, and preserve legally admissible digital evidence to help the business understand and recover from advanced cyber incidents.

Key Responsibilities
  • Direct high-severity incident response lifecycles, spearheading rapid threat hunting sweeps, system isolations, and malicious compromise containment operations across the global network.
  • Perform deep digital forensic investigations, analyzing live volatile host memory dumps, master file tables (MFT), system registries, and volatile kernel memory layers.
  • Reconstruct chronological threat attack timelines, tracing advanced persistence methods, command-and-control (C2) callback patterns, lateral network movements, and data exfiltration markers.
  • Enforce rigid chain-of-custody data preservation parameters, collecting digital image snapshots of target drives and network captures in compliance with international legal and evidentiary standards.
  • Analyze complex malware behaviors and payload scripts, reverse engineering malicious scripts, unpacking obfuscated code loops, and translating findings into actionable local indicator blocks (IOCs).
  • Author detailed forensic investigation runbooks and expert reports, presenting clear summaries of breach roots, compromised asset matrices, data exposure volumes, and recovery steps to legal and executive stakeholders.
  • Collaborate with GRC and legal compliance teams, evaluating data breach notification requirements in accordance with corporate mandates and regional privacy laws (e.g., GDPR, HIPAA).



Requirements

  • 5 to 8 years of core cybersecurity systems engineering experience, with 4+ dedicated years actively running complex post-breach digital forensic track assessments.
  • Strong technical mastery of advanced forensic software environments (e.g., EnCase, FTK, Volatility, X-Ways Forensics), memory acquisition tools, and packet analysis suites.
  • Deep structural understanding of file system layout matrices (NTFS, EXT4, FAT), operating system log architectures, network layer packet capture parsing, and malware persistence mechanics.
  • Mandatory certification: GCFA, GCIH, or CCE.

Preferred Qualifications
  • Prior experience dealing with ransomware negotiations or navigating high-stakes ransomware containment events under tight timeline expectations.
  • Scripting background in Python or Perl used to build custom string searching queries or parse non-standard database application trace files.





Similar jobs

Apply for this job