
Principal DFIR Consultant
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in United States.
• Respond to and investigate threat activities as an incident response consultant.
• Support and lead forensic investigations related to ransomware and nation-state threats.
• Examine both traditional enterprise and cloud-native environments.
• Manage multi-cloud intrusions across AWS, GCP, and Azure.
• Investigate identity and API misuse, account takeovers, and suspicious activity in the cloud.
• Utilize AI-assisted tools to expedite investigations and reporting while upholding forensic integrity.
• Assist in shaping the logic, prompts, and guardrails of a LLM-based investigative platform.
• Contribute to MOXFIVE’s technology stack, investigative methodologies, and service offerings.
• Apply investigative judgment and insights from casework to enhance internal tools.
• Experience in responding to threat activities as an incident response consultant or SOC analyst.
• Solid understanding of the fundamentals of Windows, Mac, and Linux.
• Knowledge of forensic artifacts and network analysis techniques.
• Existing knowledge or a strong desire to learn about cloud-native investigations across AWS, GCP, and Azure.
• Familiarity with AWS CloudTrail and VPC Flow Logs.
• Understanding of GCP Admin Activity and Data Access logs.
• Knowledge of Entra ID/M365 audit logs.
• A curiosity about LLMs and AI-assisted tools for investigations and reporting.
• An interest in contributing to the development of an internal LLM-based investigative platform.
• A steadfast commitment to maintaining high investigation quality.
• [Insert benefits here]
• [Insert additional benefits here]
OBAN Corporation
Arkestro
CLOUD MANTA GmbH
Get handpicked remote jobs straight to your inbox weekly.