406,377open jobs
14,133companies
78,486added this week
Browse all
Salary
$145k – $155k per year
Location
Remote (United States)
Seniority
Staff · 8+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is a Belgian recruitment platform built entirely around remote and flexible work, aggregating openings from thousands of employers that allow work from outside an office. Its matching engine ranks roles against a candidate's skills, seniority and stated preferences on location and flexibility, rather than leaving people to filter a keyword search, and it verifies how genuinely remote each posting is. The company also runs an AI screening layer that shortlists applicants for employers, and publishes research and guidance on distributed work practices alongside the job marketplace itself.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Forensics / Incident Response SME based in United States.

This is a senior cybersecurity role combining hands-on incident response with advanced digital forensics expertise.

You’ll help protect critical government environments by investigating sophisticated threats, analyzing evidence, and managing complex security incidents.

The role spans enterprise infrastructure, cloud environments, endpoints, networks, and digital media across a broad technology landscape.

You’ll work closely with SOC, security, engineering, and leadership teams to transform forensic findings into actionable detections and remediation strategies.

You’ll also contribute to threat hunting, malware analysis, tabletop exercises, security assessments, and continuous improvement of incident response capabilities.

The position offers significant autonomy in a fast-moving environment where you’ll solve complex security challenges and help shape evolving cybersecurity practices.

This is an ideal opportunity for an experienced DFIR professional who combines deep technical expertise with strong investigative judgment and operational discipline.

Accountabilities:

    • Serve as a senior subject matter expert across Incident Response and Digital Forensics, supporting both real-time incident handling and in-depth forensic investigations.
    • Participate in rotating on-call coverage and provide incident management and forensic support, including during off-hours when required.
    • Lead and support investigations involving security incidents, breaches, compromises, malware, lateral movement, data collection, and potential exfiltration.
    • Perform forensic analysis across enterprise networks, hosts, digital media, operating systems, mobile devices, and cloud environments, including AWS and SaaS, PaaS, and IaaS platforms.
    • Conduct live incident response, volatile evidence collection, forensic imaging, filesystem analysis, Windows registry analysis, file-system timeline reconstruction, and advanced network and protocol analysis.
    • Analyze malware behavior and characteristics, perform reverse engineering, and apply memory-forensics techniques to identify and understand threats.
    • Maintain and optimize malware and forensic analysis laboratory environments and ensure forensic processes follow established standards and procedures.
    • Maintain digital evidence chain of custody in accordance with organizational policies, industry standards, and applicable legal requirements.
    • Process and triage security alerts from endpoint security tools, SIEM platforms, email security solutions, threat intelligence sources, and other monitoring systems.
    • Evaluate security events, determine appropriate prioritization, and guide response activities based on incident severity and potential impact.
    • Develop, maintain, and improve security policies, instructions, standards, SOPs, and procedures related to incident response and forensic operations.
    • Prepare detailed technical reports documenting investigative methodology, evidence, findings, conclusions, and recommended actions.
    • Work with security and SOC leadership to convert intelligence and forensic findings into effective detection rules and improvements to enterprise security tooling.
    • Collaborate with incident response teams to rapidly develop and refine detections and support remediation activities.
    • Participate in threat hunting, threat intelligence operations, customer security assessments, tabletop exercises, lessons-learned activities, and ad-hoc investigations.
    • Produce and review performance metrics and contribute to the continuous improvement of DFIR capabilities and operational processes.
    • Requirements

      • 8+ years of specialized experience in incident response, advanced persistent threat management, digital forensics, and evidentiary data handling, including recent experience within the past four years.
      • Demonstrated experience conducting incident response, forensic investigations, and post-mortem analysis in cloud environments, preferably AWS.
      • Hands-on mobile device forensics experience and familiarity with Windows, macOS, iOS, Android, Linux/Unix, and other enterprise environments.
      • Strong expertise in malware analysis, behavioral analysis, malware characteristics, and reverse engineering using x86/x64 assembly.
      • Demonstrated ability to conduct Windows memory forensics and analyze malicious activity.
      • Experience with SIFT, REMnux, or comparable forensic and malware-analysis frameworks.
      • Strong knowledge of forensic imaging, filesystem media analysis, advanced Windows Registry analysis, timeline analysis, volatile evidence collection, and network event/protocol analysis.
      • Experience presenting and reporting forensic evidence and technical findings to security, technical, and leadership audiences.
      • Expert understanding of incident response processes, investigation methodologies, evidence handling, and DFIR best practices.
      • Experience developing, implementing, and following standard operating procedures and security response processes.
      • Proven ability to triage security alerts from multiple sources and prioritize incidents based on risk, severity, and available intelligence.
      • Experience supporting threat hunting and threat intelligence operations.
      • Strong analytical, investigative, problem-solving, and communication skills, with the ability to work independently in complex and evolving environments.
      • Ability to collaborate effectively with SOC teams, security leadership, engineers, and other stakeholders while providing authoritative technical guidance.
      • Strongly preferred certifications include GCFE, GCFA, CCE, ACE, EnCE, MCFE, MCGE, AWS Solutions Architect, GCIH, GCIA, GNFA, GCED, GREM, CSIH, and CFCE.
      • A strong commitment to continuous learning and staying current with emerging threats, forensic technologies, cloud security, and incident response techniques.
      • Benefits

        • Fully remote work opportunity within the United States.
        • Competitive annual salary range of $145,000-$155,000, with final compensation determined by factors such as experience, skills, education, geographic location, achievements, and security clearance.
        • Medical, dental, and vision coverage with 99% of employee premiums covered.
        • Employer contribution covering 25% of health coverage costs for family and dependents.
        • 100% employer-paid short-term disability and life insurance for full-time employees.
        • 100% employer-paid professional certifications.
        • 401(k) retirement plan with company matching of up to 4%.
        • Paid time off and paid federal holidays.
        • Wellness and fitness program.
        • Online education and professional development through an internal training portal.
        • Flexible Spending Account options for medical expenses, dependent care, transit, and parking.
        • Employee referral bonus opportunities.
        • A collaborative, employee-focused environment with opportunities for professional growth and continuous technical development.
        • Remote-work flexibility supported by clear expectations around availability, performance, security, and collaboration.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
406,377 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$30k – $79k per year (Estimated) • In office • Full-Time • 8+ years exp • Bengaluru
JavaScript
PHP
PHP
Magento
Databases
ElasticSearch
OpenSearch
Redis
Frontend
GraphQL
Next.js
React.js
Vue.js
Mobile
Dependency Injection
DevOps
AWS
Azure
CI/CD
Cloudflare
Docker
Fastly
Git
Incident Management
Kubernetes
Cybersecurity
PCI DSS
Management
ServiceNow
Apply
$100k – $195k per year (Estimated) • In office • Full-Time • United States
DevOps
Amazon CloudWatch
Amazon EC2
Amazon ECS
Amazon EKS
Amazon S3
AWS
AWS Lambda
FinOps
IAM
Incident Management
Kubernetes
Apply
$29k – $69k per year (Estimated) • In office • Full-Time • 3+ years exp • Master's Degree • Bengaluru
Go
JavaScript
Node JS
Python
TypeScript
AI/ML
AI Agents
Fine-tuning
LangChain
LangGraph
LLM Guardrails
Model Context Protocol
NLP
OpenAI
Prompt Engineering
PyTorch
RAG
Reinforcement Learning
TensorFlow
DevOps
AWS
Docker
GCP
Kubernetes
Apply
$26k – $65k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Pune
PowerShell
Python
AI/ML
AI Agents
LLM
LLM Guardrails
Model Context Protocol
DevOps
AWS
Azure
CI/CD
GCP
Git
Rest API
Splunk
Cybersecurity
Crowdstrike
Microsoft Entra ID
Microsoft Sentinel
MITRE ATT&CK
Okta
SentinelOne
Apply
$128k – $204k per year • Equity • In office • Full-Time • 8+ years exp • Alpharetta • Columbus • Frisco • Omaha • Sunnyvale
DevOps
AWS
Azure
GCP
Kubernetes
Cybersecurity
Snort
Suricata
Tcpdump
Wireshark
Zero Trust
Apply
$94k – $175k per year • Remote • Full-Time • 2+ years exp • Bachelor's Degree
Bash
PowerShell
Python
DevOps
AWS
Azure
GCP
Cybersecurity
CVSS
Nessus
OpenVAS
Qualys Cloud Platform
Apply
$126k – $257k per year (Estimated) • Remote/Hybrid • Full-Time • Master's Degree
Python
TypeScript
JavaScript
AI/ML
LLM
Pandas
Polars
Spark
Frontend
React.js
Apply
$90k – $215k per year (Estimated) • Remote • Full-Time • 6+ years exp
AI/ML
AI Agents
Apply
$39k – $110k per year (Estimated) • Remote • Full-Time
JavaScript
TypeScript
Node JS
Java
Node JS
Electron
Java
Quarkus
Spring Boot
Databases
DynamoDB
PostgreSQL
RabbitMQ
Redis
Mobile
Clean Architecture
JUnit
MVC
DevOps
Amazon EKS
AWS
Azure
Azure DevOps
CI/CD
Git
Gitflow
GitLab
Kubernetes
QA
Swagger
Apply
$25k – $57k per year (Estimated) • Remote • Full-Time • 1+ year exp
Apply
See all jobs
This is one of many
406,377 more open roles from verified company boards, updated every day.