Digital Forensics and Incident Response (DFIR) Specialist
- Hiring from
- Probably Worldwide
- Work type
- Remote
- Posted
- Sep 23, 2026
Is this job info correct?
Job Description
This is a remote position.
Digital Forensics and Incident Response (DFIR) Specialist
Job Details
- Employment Type: Contract
- Work Mode: Remote
- Location: Offshore
- Total Experience Required: 5 to 8 years
- Relevant Experience Required: 4+ years of dedicated experience conducting digital forensics investigations and deep incident response execution
- Mandatory Certification: GIAC Certified Forensic Analyst (GCFA), GIAC Certified Incident Handler (GCIH), or Certified Computer Examiner (CCE)
Job Summary
We are seeking an experienced DFIR Specialist to lead our post-breach investigation pipelines, threat containment lifecycles, and digital forensics operations. The ideal candidate will isolate compromised systems, perform low-level disk and memory trace analyses, reconstruct complex attack timelines, and preserve legally admissible digital evidence to help the business understand and recover from advanced cyber incidents.
Key Responsibilities
- Direct high-severity incident response lifecycles, spearheading rapid threat hunting sweeps, system isolations, and malicious compromise containment operations across the global network.
- Perform deep digital forensic investigations, analyzing live volatile host memory dumps, master file tables (MFT), system registries, and volatile kernel memory layers.
- Reconstruct chronological threat attack timelines, tracing advanced persistence methods, command-and-control (C2) callback patterns, lateral network movements, and data exfiltration markers.
- Enforce rigid chain-of-custody data preservation parameters, collecting digital image snapshots of target drives and network captures in compliance with international legal and evidentiary standards.
- Analyze complex malware behaviors and payload scripts, reverse engineering malicious scripts, unpacking obfuscated code loops, and translating findings into actionable local indicator blocks (IOCs).
- Author detailed forensic investigation runbooks and expert reports, presenting clear summaries of breach roots, compromised asset matrices, data exposure volumes, and recovery steps to legal and executive stakeholders.
- Collaborate with GRC and legal compliance teams, evaluating data breach notification requirements in accordance with corporate mandates and regional privacy laws (e.g., GDPR, HIPAA).
Requirements
- 5 to 8 years of core cybersecurity systems engineering experience, with 4+ dedicated years actively running complex post-breach digital forensic track assessments.
- Strong technical mastery of advanced forensic software environments (e.g., EnCase, FTK, Volatility, X-Ways Forensics), memory acquisition tools, and packet analysis suites.
- Deep structural understanding of file system layout matrices (NTFS, EXT4, FAT), operating system log architectures, network layer packet capture parsing, and malware persistence mechanics.
- Mandatory certification: GCFA, GCIH, or CCE.
Preferred Qualifications
- Prior experience dealing with ransomware negotiations or navigating high-stakes ransomware containment events under tight timeline expectations.
- Scripting background in Python or Perl used to build custom string searching queries or parse non-standard database application trace files.