Forensics / Incident Response SME

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Forensics / Incident Response SME based in United States.

This is a senior cybersecurity role combining hands-on incident response with advanced digital forensics expertise.
You’ll help protect critical government environments by investigating sophisticated threats, analyzing evidence, and managing complex security incidents.
The role spans enterprise infrastructure, cloud environments, endpoints, networks, and digital media across a broad technology landscape.
You’ll work closely with SOC, security, engineering, and leadership teams to transform forensic findings into actionable detections and remediation strategies.
You’ll also contribute to threat hunting, malware analysis, tabletop exercises, security assessments, and continuous improvement of incident response capabilities.
The position offers significant autonomy in a fast-moving environment where you’ll solve complex security challenges and help shape evolving cybersecurity practices.
This is an ideal opportunity for an experienced DFIR professional who combines deep technical expertise with strong investigative judgment and operational discipline.

Accountabilities:

  • Serve as a senior subject matter expert across Incident Response and Digital Forensics, supporting both real-time incident handling and in-depth forensic investigations.
  • Participate in rotating on-call coverage and provide incident management and forensic support, including during off-hours when required.
  • Lead and support investigations involving security incidents, breaches, compromises, malware, lateral movement, data collection, and potential exfiltration.
  • Perform forensic analysis across enterprise networks, hosts, digital media, operating systems, mobile devices, and cloud environments, including AWS and SaaS, PaaS, and IaaS platforms.
  • Conduct live incident response, volatile evidence collection, forensic imaging, filesystem analysis, Windows registry analysis, file-system timeline reconstruction, and advanced network and protocol analysis.
  • Analyze malware behavior and characteristics, perform reverse engineering, and apply memory-forensics techniques to identify and understand threats.
  • Maintain and optimize malware and forensic analysis laboratory environments and ensure forensic processes follow established standards and procedures.
  • Maintain digital evidence chain of custody in accordance with organizational policies, industry standards, and applicable legal requirements.
  • Process and triage security alerts from endpoint security tools, SIEM platforms, email security solutions, threat intelligence sources, and other monitoring systems.
  • Evaluate security events, determine appropriate prioritization, and guide response activities based on incident severity and potential impact.
  • Develop, maintain, and improve security policies, instructions, standards, SOPs, and procedures related to incident response and forensic operations.
  • Prepare detailed technical reports documenting investigative methodology, evidence, findings, conclusions, and recommended actions.
  • Work with security and SOC leadership to convert intelligence and forensic findings into effective detection rules and improvements to enterprise security tooling.
  • Collaborate with incident response teams to rapidly develop and refine detections and support remediation activities.
  • Participate in threat hunting, threat intelligence operations, customer security assessments, tabletop exercises, lessons-learned activities, and ad-hoc investigations.
  • Produce and review performance metrics and contribute to the continuous improvement of DFIR capabilities and operational processes.
  • Requirements

    • 8+ years of specialized experience in incident response, advanced persistent threat management, digital forensics, and evidentiary data handling, including recent experience within the past four years.
    • Demonstrated experience conducting incident response, forensic investigations, and post-mortem analysis in cloud environments, preferably AWS.
    • Hands-on mobile device forensics experience and familiarity with Windows, macOS, iOS, Android, Linux/Unix, and other enterprise environments.
    • Strong expertise in malware analysis, behavioral analysis, malware characteristics, and reverse engineering using x86/x64 assembly.
    • Demonstrated ability to conduct Windows memory forensics and analyze malicious activity.
    • Experience with SIFT, REMnux, or comparable forensic and malware-analysis frameworks.
    • Strong knowledge of forensic imaging, filesystem media analysis, advanced Windows Registry analysis, timeline analysis, volatile evidence collection, and network event/protocol analysis.
    • Experience presenting and reporting forensic evidence and technical findings to security, technical, and leadership audiences.
    • Expert understanding of incident response processes, investigation methodologies, evidence handling, and DFIR best practices.
    • Experience developing, implementing, and following standard operating procedures and security response processes.
    • Proven ability to triage security alerts from multiple sources and prioritize incidents based on risk, severity, and available intelligence.
    • Experience supporting threat hunting and threat intelligence operations.
    • Strong analytical, investigative, problem-solving, and communication skills, with the ability to work independently in complex and evolving environments.
    • Ability to collaborate effectively with SOC teams, security leadership, engineers, and other stakeholders while providing authoritative technical guidance.
    • Strongly preferred certifications include GCFE, GCFA, CCE, ACE, EnCE, MCFE, MCGE, AWS Solutions Architect, GCIH, GCIA, GNFA, GCED, GREM, CSIH, and CFCE.
    • A strong commitment to continuous learning and staying current with emerging threats, forensic technologies, cloud security, and incident response techniques.
    • Benefits

      • Fully remote work opportunity within the United States.
      • Competitive annual salary range of $145,000–$155,000, with final compensation determined by factors such as experience, skills, education, geographic location, achievements, and security clearance.
      • Medical, dental, and vision coverage with 99% of employee premiums covered.
      • Employer contribution covering 25% of health coverage costs for family and dependents.
      • 100% employer-paid short-term disability and life insurance for full-time employees.
      • 100% employer-paid professional certifications.
      • 401(k) retirement plan with company matching of up to 4%.
      • Paid time off and paid federal holidays.
      • Wellness and fitness program.
      • Online education and professional development through an internal training portal.
      • Flexible Spending Account options for medical expenses, dependent care, transit, and parking.
      • Employee referral bonus opportunities.
      • A collaborative, employee-focused environment with opportunities for professional growth and continuous technical development.
      • Remote-work flexibility supported by clear expectations around availability, performance, security, and collaboration.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available