International Contract Bench, Incident Response (DFIR)
Core
Support high-impact digital investigations involving sophisticated cyber threats, ransomware, and nation-state activity by analyzing live response data and forensic artifacts across endpoint, network, and cloud environments.
Role type
Contract Incident Response (DFIR) Specialist
Builds
Forensic analysis and threat intelligence reports for active security incidents
Domain
Cybersecurity / Digital Forensics / Incident Response
Deliverable
client delivery
Required skills
Digital forensics, network analysis, endpoint forensics (Windows/macOS/Linux), cloud-native investigation (AWS/GCP/Azure), threat intelligence, business email compromise (BEC) analysis
Preferred skills
Experience with sophisticated or nation-state threat activity, ability to distinguish legitimate user activity from threat actor behavior
Technologies
Windows, macOS, Linux, AWS, GCP, Azure, SaaS applications
Responsibilities
Perform incident response and digital forensic investigations involving active threat activity; Analyze live response data and forensic artifacts to identify malicious activity; Investigate Windows, macOS, and Linux environments; Analyze business email compromise and account takeover incidents; Conduct network analysis to identify suspicious activity; Support investigations across cloud-native environments
Seniority
Mid-Senior, hands-on IC