Principal DFIR Consultant

MOXFIVE
$230,000 - $300,000

About The Position

MOXFIVE is seeking to expand its IR Consulting Team with individuals driven to protect clients, eliminate threat actors, and build the next era of digital forensics and incident response for the modern enterprise. This includes contributing to the development of an AI-driven, LLM-based investigative platform. The role involves investigating adversaries across a client's entire digital footprint, including endpoints, applications, cloud workloads, code repositories, and data stores across public clouds. The company emphasizes a faster, nimbler approach to DFIR, leveraging AI tooling to enhance consultant efficiency without compromising rigor.

Requirements

  • Experience responding to threat activity as an IR consultant or SOC analyst.
  • Strong understanding of Windows/Mac/Linux fundamentals, forensic artifacts, and network analysis.
  • Existing knowledge or passion to learn cloud-native investigations across AWS, GCP, and Azure.
  • Familiarity with core log sources like CloudTrail, VPC Flow Logs, GCP Admin Activity/Data Access logs, and Entra ID/M365 audit logs.
  • Curiosity about how LLMs and AI-assisted tooling can accelerate investigation and reporting without compromising forensic rigor.
  • Interest in helping shape an internal LLM-based investigative platform built to accelerate future casework.
  • An unwavering emphasis on investigation at the highest level of quality.
  • Keen sense for distinguishing legitimate users from threat actor activity.
  • Comfort investigating cloud-native threats such as rogue service principals or suspicious Workload Identity Federation grants.
  • Understanding of CloudTrail and GuardDuty findings in AWS, Admin Activity and Data Access logs in GCP, and sign-in and audit logs in Entra ID.

Nice To Haves

  • Experience building LLM-based investigative platforms.

Responsibilities

  • Investigate adversaries across a client's entire digital footprint, including endpoints, applications, cloud workloads, code repositories, and data stores across public clouds.
  • Support and lead meaningful cases across traditional enterprise and cloud-native environments, including multi-cloud intrusions spanning AWS, GCP, and Azure.
  • Investigate modern threats across Azure, GCP, AWS, and SaaS Apps.
  • Utilize AI and LLM tooling to accelerate investigation and reporting, such as triaging logs for anomalous patterns, building timeline narratives, and spotting anomalies in cloud audit logs.
  • Contribute to the development of an internal LLM-based investigative platform by translating real-world investigation knowledge into logic, prompts, and guardrails.
  • Shape the company's technology stack, investigative methodology, and service offerings.
  • Ensure the output of AI-assisted tooling meets the same evidentiary standard as manual analysis.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service