> Markdown version of [/jobs/ext/2939587-descriptiondfir-digital-forensics-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/2939587-descriptiondfir-digital-forensics-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DescriptionDFIR / Digital Forensics & Incident Response Analyst - **Company:** Magnet, LLC - **Location:** United States - **Contract:** Temporary contract - **Skills:** Microsoft Windows, Network Analysis, Computer Networks, Digital Forensics, File Systems, Python (Programming Language), Linux Security Modules, Windows PowerShell, Security Information and Event Management, Wireshark, EndPointSecurity, Scripting, Mitre Att&ck, QRadar, Malware, Microsoft Sentinel, Encase, Splunk, SentinelOne Expertise, Vulnerability Analysis - **Published:** September 16, 2026 - **Apply:** https://www.thejobnetwork.com/job/df0adad1-0fe4-47a2-a9b4-c48f502dfa8a/dfir-digital-forensics-incident-response-analyst-dt-remote ## About the Role * Proven experience in Digital Forensics and Incident Response (DFIR). * Hands-on experience investigating cybersecurity incidents and compromised systems. * Strong endpoint and server forensic analysis skills. * Experience collecting, preserving, and analyzing digital evidence. * Strong understanding of network traffic, endpoint telemetry, malware behavior, and attack techniques. * Experience identifying IOCs, attack vectors, and persistence mechanisms. * Ability to perform incident timeline development and root-cause analysis. * Experience supporting incident containment, eradication, and recovery. * Strong analytical, documentation, and communication skills. * Ability to work independently in a remote environment. ## Description We are seeking a skilled DFIR / Digital Forensics & Incident Response Analyst to investigate and respond to cybersecurity incidents from initial detection through containment, eradication, and recovery. The role combines digital forensic investigation, incident response, endpoint analysis, threat investigation, and root-cause analysis. The ideal candidate will have hands-on experience investigating compromised endpoints and servers, analyzing security telemetry, identifying attacker activity, and coordinating remediation efforts. Key Responsibilities * Investigate cybersecurity incidents from initial detection through remediation. * Perform forensic analysis of endpoints, servers, and compromised systems. * Collect, preserve, and analyze digital evidence using established forensic procedures. * Analyze: + Security and system logs + Network traffic + Malware and malicious artifacts + Endpoint activity + Memory + Filesystem and system artifacts * Identify attack vectors, persistence mechanisms, indicators of compromise (IOCs), and attacker activity. * Develop detailed incident timelines to reconstruct security events. * Perform root-cause analysis and determine the scope and impact of incidents. * Support threat hunting and investigative activities. * Coordinate containment, eradication, and recovery activities with security and infrastructure teams. * Document investigative procedures, findings, timelines, and remediation recommendations. * Communicate technical findings and incident status to relevant stakeholders. Required Technical Skills SIEM & Security Analytics * Splunk * Microsoft Sentinel * IBM QRadar Endpoint Detection & Response * CrowdStrike * Microsoft Defender * SentinelOne Digital Forensics & Network Analysis * Wireshark * Volatility * FTK * EnCase * Magnet AXIOM Security Frameworks & Scripting * MITRE ATT&CK * Python * PowerShell * Windows and Linux security/forensics ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) ## Related Articles - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 162: AI careers, MCP, AWS best practices & floppy sweaters](https://www.wearedevelopers.com/magazine/571-dev-digest-162-ai-careers-mcp-aws-best-practices-floppy-sweaters) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)