Senior Digital Forensics & Incident Response Consultant - DT #12 - Remote
| Hours | Full-time |
|---|---|
| Location | Philadelphia, PA Philadelphia, Pennsylvania open_in_new |
About this job
Job Description
Location: Remote
Duration: 1–2 Weeks with potential extension
We are seeking an experienced Senior Digital Forensics & Incident Response (DFIR) Consultant to lead complex cybersecurity investigations and provide senior-level technical guidance across digital forensics and incident response engagements.
The consultant will lead investigations involving sophisticated threats such as ransomware, insider threats, advanced persistent threats (APTs), and data breaches. The role requires strong expertise in forensic analysis, incident containment, attack-path reconstruction, malware investigation, and executive-level reporting.
The ideal candidate will also provide technical mentorship to junior investigators and collaborate closely with SOC, threat intelligence, legal, and compliance teams.
Key Responsibilities DFIR Leadership- Lead complex digital forensic and incident response engagements from investigation through remediation.
- Direct evidence collection, preservation, forensic analysis, and incident containment activities.
- Establish investigation strategies, priorities, and technical approaches.
- Provide senior-level technical guidance throughout active security incidents.
- Perform detailed digital forensic investigations across endpoints, systems, memory, and networks.
- Conduct root-cause and attack-path analysis.
- Investigate major cybersecurity incidents, including:
- Ransomware
- Insider threats
- Advanced Persistent Threats (APTs)
- Data breaches
- Analyze attacker activity, persistence mechanisms, lateral movement, and indicators of compromise.
- Correlate evidence from multiple sources to reconstruct attack timelines.
- Support malware, memory, and network forensic investigations.
- Coordinate containment, eradication, and recovery activities.
- Work with security and infrastructure teams to identify affected systems and limit threat impact.
- Support threat hunting and post-incident investigations.
- Provide recommendations for remediation and security improvements.
- Develop detailed technical findings and forensic reports.
- Prepare concise executive-level incident summaries for leadership and stakeholders.
- Present investigation findings, attack paths, root causes, and remediation recommendations.
- Provide technical consulting and guidance to client security teams.
- Collaborate with:
- SOC teams
- Threat intelligence teams
- Legal teams
- Compliance teams
- Security and infrastructure teams
- Mentor and provide technical guidance to junior forensic investigators.
- Establish and promote effective DFIR investigation methodologies and best practices.
- DFIR
- Digital forensics
- Incident response
- Evidence collection and preservation
- Root-cause analysis
- Attack-path analysis
- Incident timeline development
- EDR / XDR
- SIEM
- Threat intelligence
- Threat hunting
- Incident containment and remediation
- Malware analysis
- Memory forensics
- Network forensics
- Ransomware investigations
- Insider threat investigations
- APT investigations
- Data breach investigations
- MITRE ATT&CK
- EnCase
- FTK
- Magnet AXIOM
- Volatility
- Python
- PowerShell
- Extensive professional experience in Digital Forensics and Incident Response (DFIR).
- Demonstrated experience leading complex cybersecurity investigations.
- Strong expertise in digital evidence collection, preservation, and forensic analysis.
- Proven ability to lead incident containment and response activities.
- Experience conducting root-cause and attack-path analysis.
- Hands-on experience investigating ransomware, insider threats, APTs, and data breaches.
- Strong knowledge of EDR/XDR and SIEM platforms.
- Experience with malware, memory, and network forensics.
- Strong understanding of MITRE ATT&CK and modern attacker techniques.
- Proficiency with forensic tools such as EnCase, FTK, Magnet AXIOM, and/or Volatility.
- Strong Python and/or PowerShell scripting capabilities.
- Excellent technical writing, presentation, and stakeholder communication skills.
- Experience mentoring junior investigators and working with multidisciplinary security teams.
- Ability to work independently in a remote consulting environment.