← Back to jobs

Remote job

Principal Consultant: DFIR

Other Full-time Freelance US

Job details

Not specified Salary
US Eligibility
Principal Experience
Full-time Employment

About this role

Role overview A senior consulting role focused on leading responses to major information security incidents for enterprise clients. The position serves as the primary point of contact during crises, coordinating cross-functional teams and driving investigations from initial triage through remediation and lessons learned.

Responsibilities - Act as lead responder on high-profile and sensitive client engagements, coordinating teams and resources throughout the engagement - Perform scope, urgency, and impact analysis during incident triage, and recommend remediation actions that enable rapid containment - Operate across the entire IR lifecycle, from preparation through detection, containment, eradication, recovery, and post-incident reporting - Collect, triage, and analyze forensic artifacts from networks and devices to support active investigations - Leverage EDR tools and data analytics platforms to conduct large-scale investigations across endpoint and network telemetry - Communicate clearly with customers throughout every phase of an incident, producing verbal updates and written reports - Mentor, train, and supervise junior and ad-hoc responders while contributing to continuous improvement of incident response services

Requirements - Minimum of five years in professional services or information security, with at least three years dedicated to incident response - An industry-recognized certification such as GCIH, GCFA, GCFE, CFCE, GREM, EnCE, or CCE - Demonstrated ability to communicate complex technical topics to both technical and non-technical audiences - Experience coordinating incidents and leading response teams under pressure - Hands-on investigation experience across Windows, Linux, macOS, and cloud environments - Competence in endpoint, memory, network forensics, and malware analysis, with deep specialization in at least one area using tools such as Axiom, FTK, or X-Ways - Applied knowledge of the Incident Response Lifecycle, the Cyber Kill Chain, and the MITRE ATT&CK Framework - Bachelor's degree in a related discipline; proficiency with Python or PowerShell; familiarity with SIEMs, Elasticsearch, and forensically sound evidence preservation

Nice to have - Certifications such as CISSP, OSCP, ITIL, COBiT, or SABSA - Working knowledge of NIST SP800-61r2 and ISO 27035 - Familiarity with ISO 27001 and ISO 27002

Benefits and work setup - Base salary range of $175,000 to $190,000 - Hybrid work model with two to three days in office - Medical insurance covering employees and dependents, plus life insurance - Retirement match program, paid time off, sick and casual leave - Maternity and paternity leave, bereavement and volunteer time - Professional development reimbursement and access to a large online learning library - Mobile phone reimbursement

Skills detected in the listing

PythonGoInformation Security
Detected Oct 7, 2026
Last verified Oct 8, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight