Principal Consultant, Cloud DFIR, Reactive Services

Palo Alto Networks
Harrisburg, PA, United States
28 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$151,000.0 - $208,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Artificial Intelligence Amazon Web Services Apple Mac Systems Audit Trail Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Computer Networks Computer Forensics
+14 more
Linux Digital Forensics Identity and Access Management Internet Security Information Systems Security Architecture Professional Microsoft Software Azure Active Directory Cloud Services Data Logging Google Cloud Mitre Att&ck Malware HybridCloud Kubernetes

Job description

The Principal Consultant, Cloud DFIR, Reactive Services is a senior individual contributor within Unit 42 responsible for leading cloud-focused incident response and digital forensics investigations across AWS, Azure, GCP, and hybrid enterprise environments.

In this role, you will serve as a technical lead on active incidents, partnering with Consulting Directors and clients to investigate security breaches, determine scope and impact, contain threats, and guide recovery efforts. You will perform advanced cloud forensic analysis, identify attacker activity, and provide actionable remediation recommendations during high-severity cybersecurity events., * Lead cloud-focused incident response and digital forensics engagements.

  • Investigate attacks involving cloud infrastructure, identity compromise, ransomware, data theft, and unauthorized access.
  • Analyze cloud telemetry, including audit logs, IAM activity, network traffic, storage access, containers, and endpoint data.
  • Conduct forensic acquisition and analysis across cloud, hybrid, and enterprise environments.
  • Serve as a technical lead during active investigations, guiding strategy and client communications.
  • Deliver clear findings, executive-ready reporting, and remediation guidance.
  • Support development of cloud investigation methodologies, playbooks, and tooling.
  • Mentor team members and contribute to knowledge sharing across Unit 42.

Requirements

  • 6-8+ years of experience in DFIR, incident response, cloud security, or related cybersecurity disciplines.
  • 3+ years of hands-on experience securing, operating, or investigating AWS, Azure, or GCP environments.
  • Experience leading investigations involving cloud breaches, ransomware, advanced intrusions, or data compromise incidents.
  • Strong understanding of cloud architecture, IAM, networking, logging, and security controls.
  • Experience analyzing cloud-native telemetry such as AWS CloudTrail, Azure Activity Logs, Microsoft Entra ID, or Google Cloud Audit Logs.
  • Hands-on experience with industry-standard DFIR and investigative tools.
  • Experience investigating Windows, Linux, macOS, cloud workloads, and hybrid environments.
  • Strong client-facing communication and consulting skills., * Experience responding to enterprise-scale cloud security incidents.
  • Knowledge of cloud security platforms such as AWS Security Hub, GuardDuty, Microsoft Defender, Sentinel, or Google Security Command Center.
  • Experience investigating containerized or Kubernetes environments.
  • Knowledge of MITRE ATT&CK and modern cloud threat actor tradecraft.
  • Consulting, MDR, or professional services experience.
  • Certifications such as GCFA, GCIH, CISSP, AWS Security Specialty, Azure Security Engineer, or equivalent.
  • Ability to travel up to 20% as required for client engagements., Amazon Web Services (AWS), Analysis Skills, Artificial Intelligence (AI), CISSP - Certified Information Systems Security Professional, Cloud Architecture, Cloud Computing, Computer Forensics, Computer Security, Consulting, Customer Relations, Develop Methodologies, Employee Benefits, Forensic Science, GCFA - GIAC Certified Forensic Analyst, GCIH - GIAC Certified Incident Handler, GCP (Good Clinical Practices), Hybrid Cloud, Incident Response, Industry Standards, Internet Security, Leadership, Leading Edge Technology, Linux Operating System, Mac Operating System, Machine Tool, Mentoring, Microsoft Product Family, Microsoft Windows Azure, Microsoft Windows Operating System, Problem Solving Skills, Professional Services, Ransomware, Security Attacks, Security Infrastructure, Technical Leadership, Telemetry, Willing to Travel

Benefits & conditions

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here.

$151,000.00 - $208,000.00/yr

Our Commitment

We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.

About the company

At Palo Alto Networks®, we’re united by a shared mission-to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.

Who We Are

In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!

This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all