Lead Consultant (1099): IR/Forensics Practice

Lumifi Cyber, Inc.
Arlington, VA, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Computer Networks Linux Intrusion Detection Systems Network Forensics

Job description

The Lead Consultant will be part of the Incident Response and Forensics practice, whose services include emergency incident response as well as incident preparation services. The Lead Consultant will act as an Incident Commander on customer incidents, perform forensic investigation activities during suspected security events, manage customer recovery, and provide expert incident response reports. Skills include resolving highly complex intrusion scenarios using host, cloud, network, log, IDS and device analysis and forensics. As a Lead Consultant you will respond to, analyze, diagnose, and report on attack events as well as recommend counter measures to attacks and other malicious activity. Lead Consultants must also be able to develop IR Plans and Playbooks and run IR Tabletop Exercises.

Duties and Requirements

  • Available 24/7 for incoming IR work, based on an on-call rotation of 2 weeks on, 4 weeks off on-call rotation
  • Mostly remote work but some infrequent emergency travel is required
  • Able to act as an Incident Commander for customers, lead a response and recovery effort on their behalf
  • Assist and lead in the creation of IR Plan and Playbook Development
  • Develop policies and procedures to investigate malware incidents for the entire computer network
  • Assists in the development and delivery of malware security awareness products and briefings
  • Lead in IR Tabletop Exercises

Good to have:

  • CISSP/CISM
  • GIAC Certified Forensic Examiner (GCFE), GIAC Experienced Forensics Examiner (GX-FE), GIAC Enterprise Incident Response (GEIR), GIAC Cloud Forensics Responder (GCFR), GIAC Certified Forensic Analyst (GCFA), GIAC Network Forensic Analyst (GNFA), GIAC Certified Incident Handler Certification (GCIH), GIAC Response and Industrial Defense (GRID), GIAC Experienced Forensics Analyst (GX-FA), GIAC Linux Incident Responder (GLIR)
  • Experience with standards framework assessments

Requirements

Do you have experience in Technical report writing?, * 5+ years of experience in incident response and forensic investigations

  • Experienced in disk, M365, cloud and network investigations and forensics, required
  • Proficient at IR/Forensics and TTE After-Action Report writing, required
  • Strong analytical and problem-solving skills with the ability to tackle complex challenges.
  • Effective communication skills, both written and verbal, to document and share knowledge.
  • Ability to adapt and thrive in a fast-paced, evolving technical landscape.
  • Proven ability to problem-solve and think critically in a fast-paced environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

1:18 min

Evaluating distributed computation networks for AI model execution

Idan Gazit · Coffee With Developers

14:14 min

Addressing audience inquiries on analytical implementation and career growth

Julian Joseph · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all