Remote job
Principal Consultant: DFIR
Job details
About this role
Role overview A senior consulting role focused on leading responses to major information security incidents for enterprise clients. The position serves as the primary point of contact during crises, coordinating cross-functional teams and driving investigations from initial triage through remediation and lessons learned.
Responsibilities - Act as lead responder on high-profile and sensitive client engagements, coordinating teams and resources throughout the engagement - Perform scope, urgency, and impact analysis during incident triage, and recommend remediation actions that enable rapid containment - Operate across the entire IR lifecycle, from preparation through detection, containment, eradication, recovery, and post-incident reporting - Collect, triage, and analyze forensic artifacts from networks and devices to support active investigations - Leverage EDR tools and data analytics platforms to conduct large-scale investigations across endpoint and network telemetry - Communicate clearly with customers throughout every phase of an incident, producing verbal updates and written reports - Mentor, train, and supervise junior and ad-hoc responders while contributing to continuous improvement of incident response services
Requirements - Minimum of five years in professional services or information security, with at least three years dedicated to incident response - An industry-recognized certification such as GCIH, GCFA, GCFE, CFCE, GREM, EnCE, or CCE - Demonstrated ability to communicate complex technical topics to both technical and non-technical audiences - Experience coordinating incidents and leading response teams under pressure - Hands-on investigation experience across Windows, Linux, macOS, and cloud environments - Competence in endpoint, memory, network forensics, and malware analysis, with deep specialization in at least one area using tools such as Axiom, FTK, or X-Ways - Applied knowledge of the Incident Response Lifecycle, the Cyber Kill Chain, and the MITRE ATT&CK Framework - Bachelor's degree in a related discipline; proficiency with Python or PowerShell; familiarity with SIEMs, Elasticsearch, and forensically sound evidence preservation
Nice to have - Certifications such as CISSP, OSCP, ITIL, COBiT, or SABSA - Working knowledge of NIST SP800-61r2 and ISO 27035 - Familiarity with ISO 27001 and ISO 27002
Benefits and work setup - Base salary range of $175,000 to $190,000 - Hybrid work model with two to three days in office - Medical insurance covering employees and dependents, plus life insurance - Retirement match program, paid time off, sick and casual leave - Maternity and paternity leave, bereavement and volunteer time - Professional development reimbursement and access to a large online learning library - Mobile phone reimbursement