594,989open jobs
29,557companies
85,641added this week
Browse all
Salary
$230k – $300k per year
Location
Remote (United States)
Seniority
Principal
Employment
Full-Time
Overview
Company
Impact
Profile match

Who We Are

If you feel like Incident Response and Recovery hasn't changed in the past 10 years, you're not alone. Business operations aren't just on endpoints anymore. It's behind applications in Okta tiles, auto-scaling workloads, code repos, and sprawling data stores across one or many public clouds. At MOXFIVE, we're focused on eradicating adversaries across our client's entire digital footprint, and that demands a faster, nimbler approach to DFIR, one where AI-driven tooling helps our consultants investigate faster without cutting corners on rigor.

We're looking to expand our IR Consulting Team with individuals driven to protect clients, eliminate threat actors, and build the next era of digital forensics and incident response for the modern enterprise, including the LLM-based investigative platform we're building to get them there.

Who You Are

You know that $I30 isn't referring to your local interstate, and that the easiest way to get on your bad side is to be handed a timestamp that isn't in UTC. You've got a "Tools" folder sitting on your workstation somewhere with your favorite forensic scripts at the ready to tear into the next piece of suspicious activity you see. And speaking of suspicious activity, you've honed a keen sense for knowing the difference between legitimate users and threat actor activity because you've seen them in action. Hundreds of times.

Windows environment investigations feel like the back of your hand at this point, and you've been starting to expand your knowledge on cloud-native forensics. Account takeovers are the new malware after all, and investigating the latest threats across Azure, GCP, AWS, and SaaS Apps is the growing frontier you've been looking to sink your teeth into. You know your way around CloudTrail and GuardDuty findings in AWS, Admin Activity and Data Access logs in GCP, and sign-in and audit logs in Entra ID, and you're just as comfortable chasing a rogue service principal or a suspicious Workload Identity Federation grant as you are pulling apart a $MFT.

You've also got an eye toward where the work is heading. You're not afraid to put LLMs and AI tooling to work as part of the investigative process, whether that's rapidly triaging thousands of authentication logs for anomalous patterns, building timeline narratives faster without sacrificing accuracy, or using AI-assisted tooling to spot the needle in a haystack of cloud audit logs. You know these tools augment a sharp analyst, they don't replace one, and you hold the output to the same evidentiary standard you'd hold your own analysis to. And you don't just want to be a consumer of that tooling. You want a hand in building it, translating what you know about how a real investigation actually unfolds into the logic, prompts, and guardrails of an LLM-based investigative platform that can eventually help the next analyst move faster than you did.

You're insatiably curious, addicted to threat intel, and a builder at heart. Ultimately, you're looking for the right opportunity that uses your technical chops to find and eliminate meaningful adversaries while putting your stamp on a better approach to traditional DFIR consulting.

Why You Matter

You'll be joining a seasoned team of high performing incident response consultants that are the tip of the spear for all forensic activity at MOXFIVE. From ransomware to nation-state threats, you'll be supporting and leading meaningful cases across traditional enterprise and cloud-native environments, including multi-cloud intrusions spanning AWS, GCP, and Azure where the adversary is living off cloud-native identity and API abuse rather than dropping malware on disk. Your voice has significant weight in shaping our technology stack, investigative methodology, and service offerings as we continue to scale, including how we responsibly build LLM-driven capabilities into the investigative workflow itself. You won't just be a user of that platform. Your casework, your instincts for what matters in an investigation, and your judgment calls in the field will directly shape how it's built, so that the methodology baked into the tooling reflects the same rigor you bring to a report.

What You'll Bring

  • Experience responding to threat activity as an IR consultant or SOC analyst

  • Strong understanding of Windows/Mac/Linux fundamentals, forensic artifacts, and network analysis

  • Existing knowledge or passion to learn cloud-native investigations across AWS, GCP, and Azure, including familiarity with core log sources like CloudTrail, VPC Flow Logs, GCP Admin Activity/Data Access logs, and Entra ID/M365 audit logs

  • Curiosity about how LLMs and AI-assisted tooling can accelerate investigation and reporting without compromising forensic rigor, and interest in helping shape an internal LLM-based investigative platform built to accelerate future casework

  • An unwavering emphasis on investigation at the highest level of quality

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
594,989 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
In office • 5+ years exp
JavaScript
Java
TypeScript
SQL
Node JS
Java
Spring Boot
Node JS
Nest.JS
AI/ML
Copilot
Claude Code
Model Context Protocol
Prompt Engineering
OpenAI Codex
Frontend
Angular
React.js
DevOps
Azure
CI/CD
Git
AWS
Management
Agile
Apply
In office • Contractor • 7+ years exp
JavaScript
C#
C#
ASP.NET Core
WPF
Frontend
npm
Mobile
MVVM
DevOps
Azure
Git
AWS
Apply
Fullstack Developer 11 hours ago
$26k – $61k per year (Estimated) • In office • 5+ years exp • Bengaluru
JavaScript
TypeScript
SQL
C#
C#
.NET
Databases
Azure Cosmos DB
Frontend
Redux
Webpack
Angular
React.js
Vite
Mobile
React Native
Clean Architecture
Dependency Injection
State Management
DevOps
Rest API
Azure DevOps
GitHub Actions
OpenTelemetry
Prometheus
Azure
CI/CD
Git
Docker
Kubernetes
Azure AKS
Management
Agile
Apply
.NET Developer 1 day ago
$26k – $61k per year (Estimated) • In office • 5+ years exp • Bengaluru
JavaScript
TypeScript
SQL
C#
C#
.NET
Databases
Azure Cosmos DB
Frontend
Redux
Webpack
React.js
Vite
Mobile
React Native
Clean Architecture
Dependency Injection
State Management
DevOps
Rest API
Azure DevOps
GitHub Actions
OpenTelemetry
Prometheus
Azure
CI/CD
Git
Docker
Kubernetes
Azure AKS
Management
Agile
Apply
$135k – $153k per year • In office • 5+ years exp • Bachelor's Degree
Python
SQL
AI/ML
AI Agents
LLM Guardrails
DevOps
Terraform
CloudFormation
CI/CD
AWS
Management
Agile
Apply
$100k – $120k per year • Remote • Full-Time
AI/ML
Haystack
LLM
LLM Guardrails
DevOps
GCP
Azure
AWS
Cybersecurity
Okta
Microsoft Entra ID
Apply
$160k – $180k per year • Remote • Full-Time • 8+ years exp
Cybersecurity
Crowdstrike
MITRE ATT&CK
NIST CSF
Apply
$150k – $170k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
Web3
Rollup
Marketing
Salesforce
Apply
$180k – $220k per year • Remote • Full-Time • 5+ years exp
AI/ML
Together AI
RunPod
DevOps
Terraform
GitHub Actions
New Relic
OpenTofu
Terragrunt
Datadog
CI/CD
AWS
Docker
Kubernetes
Grafana
Platform Engineering
kubectl
AWS Lambda
Honeycomb
IAM
Cybersecurity
Crowdstrike
Zero Trust
Least Privilege
Apply
$95k – $150k per year • Remote • Full-Time • 10+ years exp
DevOps
GCP
VMWare
Azure
AWS
Hyper-V
Apply
See all jobs
This is one of many
594,989 more open roles from verified company boards, updated every day.