Digital Forensics and Incident Response (DFIR) Consultant
Posted 837 days ago, which is unusual. The employer's own board was still carrying it when we last read it, 2 hours ago.
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2h ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 837d ago
The date the source published, not the day we noticed it (2024-06-18). Last seen at its source 2h ago.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
United States
The description states no restriction of its own. This is the source's own tag.
Pay not stated
Similar roles pay $111.8k–169.5k/yr
Middle 50% of 301 listings that do state pay — Consulting · all levels · United States · USD/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
bamboohr employer's own board first seen 2h ago · last seen 2h ago
The listing
About the Role
The Consultant is an engagement delivery contributor within CYPFER's DFIR and Post-Breach Recovery practice. Operating at the task execution level, the Consultant works alongside senior practitioners on active incident response and recovery engagements — collecting evidence, executing playbooks, triaging artefacts, and producing client-ready documentation. The role interacts directly with insurance partners, legal counsel, client technical teams, and executives as part of structured engagement delivery. This is a hands-on role suited to early-career cybersecurity professionals building deep technical expertise across DFIR and PBR.
Core Responsibilities:
- Understand the client challenge and objective; execute defined tasks in line with engagement scope and the path to recovery.
- Deliver discrete work packages including forensic acquisition, IOC triage, and recovery steps under the direction of senior team members.
- Maintain accurate case notes and produce client-ready artefacts; adhere to SOPs and QA standards throughout all engagements.
- Escalate risks early; follow chain-of-custody and compliance requirements at all times.
- Analyze triage collections and artefacts for indicators of compromise (IoCs) and potentially malicious activity.
- Review logs from host systems and appliances to identify suspicious activities.
- Collect forensic disk and memory images from physical and virtual endpoints and servers.
- Contribute to event correlation and the building of engagement timelines under senior guidance.
- Conduct initial threat research based on IOCs collected during investigations.
- Participate in a rotating on-call schedule; ability to work on weekends and outside normal business hours as needed.
- This role is remote but requires the ability to travel on short notice to a client site up to 50%. Must maintain flexibility to travel within 24–48 hours' notice for deployments typically 1–2 weeks in duration.
Technical Requirements:
- 1–3 years of experience in incident response, digital forensics, or a related cybersecurity role.
- Working knowledge of endpoint forensics — acquire and preserve evidence from physical and virtual systems, and triage artefacts to support investigations; SANS FOR500 (GCFE) certification is an asset.
- Hands-on experience operating EDR platforms (e.g., CrowdStrike Falcon) for threat hunting, host isolation, and telemetry collection; vendor EDR certification (e.g., Falcon Administrator) is an asset.
- Ability to execute DFIR and PBR playbooks accurately under guidance, following structured SOPs from initial triage through to recovery.
- Ability to produce clear, accurate, client-ready case notes and reports throughout an engagement.
- Familiarity with IR orchestration platforms or case management tooling is an asset.
Business Responsibilities:
- Exhibit strong customer service and consulting skills in all client interactions.
- Adhere to client and internal policies, procedures, and security practices.
- Remain calm, composed, and articulate in high-pressure client situations.
- Exhibit excellent relationship management and communication skills.
- Ensure a high level of confidentiality due to having access to sensitive client and incident data.
Preferred Skills:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field — or equivalent hands-on experience.
- Industry certifications such as GCFE, GCIH, or similar are a strong asset.
- Familiarity with SIEM and SOAR solutions.
- Exposure to threat hunting, network forensics, or malware analysis methodologies.
- Experience in a professional services or consulting environment
- Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar are a plus.
Compensation package includes a base salary, medical benefits and multiple bonus opportunities.
Cypfer is an equal opportunity employer. If you need accommodation during the interview process or beyond, please let us know. We celebrate our inclusive work environment and welcome applicants from all backgrounds and perspectives.
We thank you for your interest in joining the Cypfer team! While we welcome all applicants, only those selected for an interview will be contacted.