International Contract Bench, Incident Response (DFIR)
Skills
About this role
Accountabilities • Perform incident response and digital forensic investigations involving active threat activity and security breaches.
• Analyze live response data and forensic artifacts to identify malicious activity, determine attack methods, and support investigations. • Investigate Windows, macOS, and Linux environments using appropriate forensic techniques and tooling. • Analyze business email compromise (BEC), account takeover, and other identity-related incidents. • Conduct network analysis to identify suspicious activity, attacker behavior, and relevant indicators of compromise. • Support investigations across cloud-native environments, including AWS, GCP, Azure, and SaaS applications. • Apply threat intelligence and current knowledge of adversary techniques to investigative work. • Contribute high-quality analysis to cases involving threats such as ransomware and sophisticated or nation-state activity. • Share investigative perspectives, technical expertise, and feedback that help strengthen and evolve the incident response practice. • Take on incident response assignments for a minimum of several hours per week, according to your availability and the needs of active investigations.
Requirements:
• Professional experience responding to cyber threat activity as an Incident Response consultant, SOC analyst, or in a closely related role. • Strong understanding of Windows, macOS, and Linux fundamentals and their relevant forensic artifacts. • Experience with digital forensics, business email compromise investigations, and network analysis. • Existing knowledge of cloud-native investigations across AWS, GCP, and Azure, or a strong willingness and ability to develop expertise in these areas. • Strong investigative mindset with a consistent focus on accuracy, evidence quality, and thorough analysis. • Ability to distinguish legitimate user activity from threat actor behavior based on technical evidence and investigative context. • Strong curiosity and interest in threat intelligence, emerging attack techniques, and evolving cyber threats. • Ability to work independently while contributing effectively to an experienced incident response team. • Willingness to bring your perspective and technical voice to help shape investigative practices. • Availability of at least a few hours per week to support incident response work. • Ability to balance contract incident response work with existing professional commitments, where permitted by your current employer.
Benefits:
• Flexible contract-based engagement designed to accommodate existing professional and personal commitments. • Opportunity to work on live incident response investigations without committing to a traditional full-time on-call schedule. • Exposure to complex investigations involving ransomware, account compromise, cloud environments, and sophisticated threat activity. • Opportunity to work alongside an experienced team of incident response and digital forensics professionals. • Continued hands-on exposure to emerging threats, investigative techniques, and cloud-native forensics. • Flexible workload that allows you to take on assignments according to your availability and the needs of active cases.