
Principal DFIR Consultant
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in California.
• Oversee incident response operations during cybersecurity breaches, encompassing the initial triage, threat assessment, containment, eradication, and recovery stages.
• Serve as the “Incident Commander” for insured parties or their representatives during cyber incidents, ensuring effective communication, guidance for recovery, and updates regarding the investigation's status.
• Conduct initial scoping discussions with clients to grasp the disruption, devise a strategy to address the cybersecurity event, and deliver initial triage to control the threat.
• Articulate intricate cybersecurity concepts both internally and externally.
• Cultivate strong relationships with insured clients and maintain trust through effective communication and prompt delivery of investigation outcomes.
• Utilizing extensive knowledge and advanced leadership capabilities, responsible for aiding in the recruitment and development of a high-performing DFIR team.
• Mentor a team that will expand with experience and time.
• Lead case teams by assigning tasks, delegating responsibilities, and ensuring quality control on all analyses and deliverables.
• Execute post-incident analyses to uncover root causes and implement preventive strategies to reduce future risks.
• A minimum of a 4-year/bachelor’s degree in cybersecurity, Computer Science, Information Technology, or a comparable professional background.
• At least 5 years of prior professional experience in leading and managing a DFIR team and handling active cybersecurity engagements, including incident response, digital forensics investigations, and collaboration with insured clients and legal advisors.
• Advanced degrees or certifications (CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE) are advantageous.
• A minimum of 2 years in people management or team leadership positions.
• Demonstrated success in leading and building DFIR teams while managing complex cyber incidents.
• Proficient in conducting security investigations in both Linux and Windows environments.
• Familiarity with cloud platforms and security considerations in AWS, Azure, Microsoft 365, and GCP.
• Knowledge of digital forensic artifacts and tools such as ELK, Axiom, Encase, X-Ways, SIFT, FTK, Volatility, or open-source tools.
• Experience in Digital Forensics, Network Forensics, Memory Forensics, and/or Malware Analysis.
• Proficiency in scripting languages (PowerShell, Bash, Python, Go).
• Familiarity with EDR solutions (Defender, SentinelOne, CrowdStrike).
• Strong understanding of legal and regulatory frameworks pertinent to cybersecurity investigations, such as PCI and NIST CSF.
• Exceptional communication and presentation skills to convey complex technical findings clearly and concisely to clients and stakeholders.
• Strong leadership qualities to inspire and mentor team members.
• Excellent organizational and analytical skills; proven ability to manage multiple tasks simultaneously.
• Awareness of industry changes, legal updates, and technical advancements relevant to the Company's business to proactively adapt to the evolving business landscape.
• Advanced proficiency and experience with the Microsoft Office suite.
• Subsidized medical, prescription, dental, vision, and basic life and disability insurance.
• Employee assistance program.
• Paid parental leave.
• 401(k) plan with company matching contributions.
• At least 20 days of paid time off (PTO).
• 11 paid holidays.
• One paid volunteer day.
• Two paid floating holidays.
BCD Travel
Ascensus
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.