
Principal Consultant, DFIR, Reactive Services β LATAM
Posted Aug 11

Posted Aug 11
This is a fully remote position, open to applicants in Brazil, +1 more country.
β’ Oversee and carry out intricate digital forensics and incident response investigations in enterprise settings.
β’ Act as a technical lead during investigations involving ransomware, business email compromise, malware, insider threats, unauthorized access, data theft, and advanced intrusions.
β’ Execute advanced forensic analysis of endpoints, systems, logs, networks, and cloud infrastructures.
β’ Direct host, network, identity, and cloud investigations during active incidents.
β’ Conduct and supervise forensic acquisition, preservation, and analysis while adhering to chain-of-custody protocols.
β’ Utilize DFIR tools, investigative techniques, and threat intelligence to aid in containment, eradication, and recovery efforts.
β’ Manage technical workflows and coordinate efforts among client teams, internal stakeholders, and third-party partners.
β’ Interpret technical findings into investigative summaries, timelines, executive briefings, and reports for clients.
β’ Present findings and recommendations to technical teams, business leaders, legal counsel, and executives.
β’ Offer remediation advice throughout the incident response and recovery phases.
β’ Mentor junior and mid-level consultants.
β’ Assist in engagement planning, scoping, quality assurance, delivery, business development, client briefings, and technical discussions.
β’ Contribute to internal DFIR processes, playbooks, tools, training materials, and knowledge-sharing initiatives.
β’ Stay informed about emerging threats, attacker techniques, forensic methodologies, and cybersecurity trends.
β’ Travel up to 20% across Latin America for client engagements.
β’ Bachelor's degree in Computer Science, Information Security, Digital Forensics, or a related field, or equivalent practical experience.
β’ 6β8 years of direct experience in Digital Forensics and Incident Response, Security Operations, SOC, threat hunting, or related cybersecurity areas.
β’ Proven experience leading or managing complex enterprise incident response investigations independently.
β’ Background in investigating ransomware, intrusion incidents, phishing, malware, business email compromise, insider threats, data theft, or unauthorized access cases.
β’ Strong understanding of forensic methodologies, evidence handling, forensic acquisition techniques, and chain-of-custody practices.
β’ Practical experience with EnCase, FTK, Sleuth Kit, Volatility, Velociraptor, X-Ways, Magnet AXIOM, or similar forensic frameworks.
β’ Experience in investigating Microsoft Windows, Linux, and macOS environments.
β’ Proficient in analyzing endpoint, network, identity, cloud, and security-platform data.
β’ Knowledge of attacker techniques, persistence mechanisms, lateral movement, credential access, and indicators of compromise.
β’ Strong analytical and problem-solving capabilities.
β’ Excellent written and verbal communication skills.
β’ Ability to convey complex technical findings to both technical and executive audiences.
β’ Capacity to manage client relationships and offer trusted technical advice during critical incidents.
β’ LATAM candidates must be fluent in English and Spanish, English and Portuguese, or Spanish and Portuguese; proficiency in all three languages is preferred.
β’ Ability to effectively communicate with clients and internal teams throughout Latin America.
β’ Preferred: experience with cloud, hybrid, or multinational investigations; familiarity with MITRE ATT&CK; malware analysis; threat hunting; EDR; AWS; Microsoft Azure; Google Cloud Platform; Microsoft 365; cybersecurity consulting; managed security services; MDR; incident response organizations; mentoring; concurrent investigations; relevant industry certifications; and experience with multinational or enterprise clients in Latin America.
β’ Willingness to travel up to 20% across Latin America.
β’ Applicants must not require immigration sponsorship; the employer will not provide work visa sponsorship.
β’ Flexible remote work arrangement
β’ Travel support for client engagements (up to 20% throughout Latin America)
β’ Reasonable accommodations for qualified individuals with disabilities
β’ Immigration sponsorship is not available
Vigil
Aptive Resources
Aptive Resources
Truelogic Software
Get handpicked remote jobs straight to your inbox weekly.