DFIR Analyst

SentinelOne
$108,000 - $120,000Remote

About The Position

As a DFIR Analyst, you will be tasked with serving as technical lead on small to medium-sized breach response investigations for SentinelOne's 24x7x365, follow-the-sun DFIR team. You'll own case-level evidence and documentation quality end-to-end, partnering closely with an Engagement Manager on scoping, case strategy, and customer communications, and bringing strong, well-rounded technical depth across threat hunting and endpoint, network, and cloud forensics.

Requirements

  • Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field (or equivalent practical self-study).
  • 4+ years of hands-on experience in digital forensics, incident response, or threat hunting, ideally in a consulting or services delivery environment.
  • Demonstrated experience serving as a lead or technical contributor on complex breach response engagements, capable of working independently with minimal guidance.
  • Comfort analyzing Windows, Linux, and macOS environments.
  • Expert-level experience with forensic investigative tools such as X-Ways Forensics, Axiom, and FTK.
  • Strong experience with EDR/XDR platforms (SentinelOne preferred) and SIEMs.
  • Strong understanding of network protocols, network security architecture, and network-based forensic analysis.
  • Working knowledge of cloud incident response methodology across at least one major provider (AWS, Azure, or GCP).
  • Experience conducting dynamic malware analysis and solid understanding of the reverse engineering process.
  • Experience conducting endpoint-based threat hunting (compromise assessments).
  • Scripting ability (Python preferred), with experience automating investigative or analysis tasks.
  • Demonstrated ability to write clear, evidence-backed findings and reason through ambiguous or incomplete data in writing.
  • Comfort communicating findings to a range of stakeholders, including customer technical teams, executives, and legal counsel.
  • An evident self-starter with intellectual curiosity and the ability to adapt to change.

Responsibilities

  • Serve as technical lead on DFIR engagements, directing analytical focus and partnering with the Engagement Manager to align technical work with scope and client expectations.
  • Support case intake by gathering initial technical details and assessing scope.
  • Conduct EDR-driven incident response and vendor-agnostic advanced forensic analysis spanning endpoint, network, cloud, and SaaS environments (including ransomware, business email compromise, identity compromise, and other common incident types).
  • Develop tactical containment guidance and remediation recommendations tailored to each engagement's specific attack pattern.
  • Contribute observed attacker techniques and indicators to the team's shared knowledge base.
  • Acquire and preserve forensic evidence from endpoint, network, and cloud sources following standard chain-of-custody procedures, with clear, thorough case documentation throughout each investigation.
  • Support the preparation and delivery of interim status updates and deliverables.
  • Own evidence handling, documentation standards, and the accuracy and quality of formal investigative reports for assigned engagements, ensuring findings are defensible, well-supported, and peer-reviewed before reaching a customer, breach counsel, or other stakeholder.
  • Lead case handovers for assigned engagements, ensuring a complete, clear transfer of status when work moves across regions.
  • Mentor Analysts on technical methodology, evidence handling, and investigative best practices.
  • Manage triage and analysis in high-pressure, large-scale incidents, maintaining composure and clear decision-making.
  • Build or improve scripts, tooling, and internal processes — including AI-assisted approaches where useful — to streamline recurring forensic, analysis, and reporting workflows.
  • Escalate scope, resourcing, or customer relationship concerns to the EM promptly, while owning technical escalations directly.
  • Track hours for investigations accurately and in a timely fashion.
  • Participate in a rotating on-call schedule for weekends and holidays, to support active incident response.
  • Maintain awareness of emerging threats, attacker techniques, and evolving cybersecurity trends.

Benefits

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave
  • Grandparent leave
  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary benefits (hospital, accident, critical illness)
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance
  • Home office allowance
  • Mobile phone reimbursement
  • Wellness coach
  • Wellness/gym reimbursement
  • Fertility coverage
  • Adoption & surrogacy reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service