Incident Response
Cyber Security Analyst — DFIR
The Digital Forensics & Incident Response (DFIR) Analyst is responsible for detecting, investigating, containing, and documenting cybersecurity incidents across enterprise environments.
Role Overview
The Digital Forensics & Incident Response (DFIR) Analyst is responsible for detecting, investigating, containing, and documenting cybersecurity incidents across enterprise environments. The role combines structured incident response, digital forensic investigation, proactive threat hunting, and dark web intelligence monitoring to reduce organizational risk.
This position focuses on identifying Indicators of Compromise (IOCs), conducting forensic analysis, performing hypothesis-driven threat hunting, and ensuring investigations are properly documented, defensible, and actionable. Strong emphasis is placed on evidence integrity, structured reporting, cross-team collaboration, and continuous improvement of detection and response capabilities.
Depending on experience level, the role ranges from supporting investigations under supervision to leading complex incidents and mentoring junior analysts.
Key Responsibilities
- Incident Monitoring & Response
- Monitor and analyze alerts from SIEM, EDR/XDR, NDR, and cloud security tools.
- Perform initial triage, severity classification, and escalation where required.
- Conduct root cause analysis to determine attack vectors and scope of compromise.
- Coordinate containment, eradication, and recovery activities with IT and SOC teams.
- Support post-incident reviews and corrective action tracking.
- Digital Forensics & Evidence Handling
- Collect, preserve, and analyze digital evidence following standard forensic procedures.
- Maintain proper chain-of-custody documentation and evidence logs.
- Perform:
- Log correlation and timeline reconstruction
- Endpoint artifact analysis
- Basic disk and memory analysis
- Ensure evidence integrity and defensibility of findings.
- Assist in preparing forensic summaries suitable for internal and external stakeholders.
- Threat Hunting
- Proactively hunt for threats across endpoints, networks, servers, and cloud environments.
- Conduct hypothesis-driven investigations based on emerging threat intelligence.
- Identify advanced threats, insider activity, and stealth persistence mechanisms.
- Map findings to MITRE ATT&CK techniques.
- Develop and refine detection use cases and hunting queries.
- Dark Web & Threat Intelligence Monitoring
- Monitor dark web forums, marketplaces, and breach sites for:
- Leaked credentials
- Stolen corporate data
- Threat actor chatter referencing the organization
- Correlate external threat intelligence with internal telemetry.
- Produce actionable intelligence briefs and risk notifications.
- Recommend proactive mitigation measures based on intelligence findings.
- Documentation & Reporting
- Maintain detailed incident response case files and investigation reports.
- Document:
- Timeline of events
- Affected systems
- Indicators identified
- Business impact
- Remediation recommendations
- Present findings clearly to SOC, IT teams, and management.
- Contribute to development and refinement of incident response playbooks and SOPs.
- Tooling & Continuous Improvement
- Assist in deployment, tuning, and optimization of:
- SIEM platforms (Splunk, QRadar, Sentinel, ELK)
- EDR/XDR tools
- SOAR platforms
- Contribute to detection engineering improvements.
- Stay updated on emerging threats, vulnerabilities, and forensic methodologies.
- Required Skills & Qualifications
Technical Skills
- Strong understanding of networking fundamentals.
- Working knowledge of Windows and Linux operating systems.
- Hands-on experience with SIEM platforms (Splunk, QRadar, Sentinel, ELK).
- Experience with EDR/XDR tools (CrowdStrike, Defender, Carbon Black, etc.).
- Knowledge of MITRE ATT&CK framework.
- Log analysis and IOC/IOA identification.
- Understanding of forensic acquisition and preservation principles.
- Basic malware analysis and incident response lifecycle knowledge.
- Professional & Soft Skills
- Strong investigative and analytical mindset.
- Excellent technical report writing and documentation skills.
- Ability to present investigation findings clearly to technical and non-technical audiences.
- Strong written and verbal communication.
- Ability to work under pressure during active incidents.
- Structured thinking and prioritization ability.
- High integrity and confidentiality awareness.
- Nice to Have
- Experience with cloud environments (AWS, Azure, GCP).
- Familiarity with SOAR and automation platforms.
- Scripting skills (Python, PowerShell, Bash).
- Exposure to malware sandboxing and reverse engineering basics.
Certifications
- Certifications such as GCED, GCIA, GCIH, CEH, CHF
Experience Level
- Intern / Trainee – DFIR
- Assists in alert monitoring and evidence collection.
- Supports log analysis and documentation under supervision.
- Learns incident response workflows and forensic handling procedures.
- Participates in guided threat hunting exercises.
- DFIR Analyst
- Independently handles low-to-medium severity incidents.
- Conducts structured forensic investigations and root cause analysis.
- Performs proactive threat hunting using SIEM and EDR tools.
- Produces clear, well-structured incident reports.
- Contributes to detection rule improvements.
- Senior DFIR Analyst
- Leads complex, high-severity investigations end-to-end.
- Oversees forensic evidence collection and validates investigative accuracy.
- Designs threat hunting methodologies and detection improvements.
- Mentors junior analysts and reviews case documentation.
- Presents findings to senior stakeholders and management.
- Contributes to incident response strategy and maturity improvement.
What Success Looks Like in This Role
- Incidents are detected and contained efficiently.
- Forensic investigations are structured, defensible, and well-documented.
- Threat hunting activities uncover hidden or dormant risks.
- Dark web intelligence leads to proactive mitigation.
- Detection and response capabilities improve continuously.
Why Join Us
- Work on meaningful GRC and risk-focused initiatives that impact business decisions.
- Gain exposure to compliance frameworks, audits, and leadership reporting.
- Opportunity to grow expertise in data analysis, visualization, and risk management.
- Collaborative environment that values accuracy, accountability, and continuous improvement.
- Application Instructions
- Subject: DFIR Analyst – Digital Forensics & Incident ResponseEmail your resume to [email protected]
- Please include one of the following:
- Incident investigation report excerpt
- Threat hunting case study
- Forensic analysis write-up
- Detection engineering improvement example