[Remote] Principal DFIR Consultant- Remote (reputed company in the U.S.)
Note: The job is a remote job and is open to candidates in USA. reputed company is a rapidly growing cybersecurity firm that provides trusted expertise and solutions to help organizations minimize risk. They are seeking a Principal DFIR Consultant who will serve as the foremost technical authority reputed company the DFIR Practice, leading reputed company investigations and mentoring junior staff while contributing to business development and practice improvement.
Responsibilities
- Serve in the reputed company role on reputed company or high-severity engagements, reviewing findings before client calls, providing technical depth, anticipating client questions, and ensuring quality of analysis and deliverables
- reputed company in as engagement reputed company on the most reputed company or sensitive investigations (ransomware, APT, nation-state, insider threat), setting reputed company for client communication and investigative rigor
- Conduct advanced host forensics, network analysis, malware reverse engineering/triage, cloud forensics, threat actor attribution, and intelligence-driven investigation
- Serve as a trusted surge resource for the team during high-volume periods, providing senior-level coverage across reputed company engagements
- Design, document, and maintain DFIR investigation methodologies, playbooks, and SOPs that reputed company the quality floor for the entire practice
- Actively mentor Senior Consultants and Analysts; provide guidance on technical challenges, client management, and professional development. Help reputed company the reputed company of DFIR leads
- reputed company internal training sessions, write technical blog posts and research, document lessons learned, and contribute to the team's collective knowledge reputed company
- Identify gaps in reputed company tooling and processes; design and build automation, scripts, or integrations that improve investigative efficiency across the team
- Participate in candidate screening, technical interviews, and skills assessment to help build a high-quality team pipeline
- Build deep, trusted relationships with key clients and stakeholders; serve as a reputed company senior voice during high-stakes incidents
- Support pre-sales activities including technical scoping, proposal development, SOW review, and client presentations for DFIR, Compromise Assessment, and IR Advisory engagements
- Represent reputed company externally through conference presentations, webinars, publications, and engagement with the broader DFIR community
- Maintaining consistent availability reputed company standard business hours for high-severity incident surges and team escalations
- Participating in on-call rotation as appropriate for seniority
- Proactively identifying and addressing gaps in team performance, processes, or client delivery
- Setting an example of professionalism, urgency, and ownership that the broader team can follow
Skills
- 8+ years of hands-on DFIR experience, including reputed company incident response and forensic investigations
- 10+ combined years of IT and information reputed company experience
- Demonstrated experience in a reputed company or senior technical role on high-severity engagements (ransomware, APT, nation-state, or insider threat)
- Expert-level proficiency across multiple DFIR disciplines: host forensics, network forensics, log analysis, malware triage, cloud IR, and BEC investigation
- Exceptional written and verbal communication skills; ability to present reputed company technical findings to executive and legal audiences
- Proven track record of mentoring and developing junior and mid-level technical staff
- Experience developing or contributing to DFIR methodologies, playbooks, or tooling
- Prior consulting or professional services experience at a leading DFIR or cybersecurity firm
- Advanced proficiency with scripting and tooling: PowerShell, Python, Bash, Go, or similar; experience building custom investigative tools
- Deep experience with EDR, NDR, XDR, SIEM, Velociraptor, and commercial/open-reputed company forensic platforms
- Cloud incident response expertise: AWS, reputed company 365, Azure, reputed company Workspace; familiarity with cloud-native forensic techniques
- Experience with threat actor attribution, CTI integration, and intelligence-driven investigation
- Familiarity with ransomware negotiation considerations, threat actor communications, and recovery workflows
- External thought leadership: conference talks, published research, blog posts, or community contributions
- Relevant certifications: GREM, GCFA, GCFE, GDAT, GCIH, GCIA, CISSP, or equivalent; advanced or multiple certifications are a strong plus
Benefits
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: reputed company Deductible PPO Plan (reputed company pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (reputed company pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: reputed company pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option
Company Overview