DFIR Analyst

SentinelOne

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Salary
$108,000–$120,000 / yr
Posted
4 days ago
Freshness
Confirmed live today

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $140k
This role $114k
$99k most similar roles pay here $178k

This role pays less than 72% of similar roles. Most pay $110,758–$170,000 — the shaded band above. At the midpoint, this role pays about $114k versus about $140k for comparable roles.

Based on 240 similar postings.

Employer

About SentinelOne

SentinelOne is a cybersecurity company that provides an AI-powered extended detection and response (XDR) platform. Its Singularity platform delivers autonomous endpoint, cloud, and identity protection for enterprises.

SentinelOne currently has 9 open roles on FindRole.

Listed pay typically runs $132,000–$160,000 across 5 roles with salary data.

Most-posted roles

View all roles at SentinelOne

At a glance

TL;DR · DFIR Analyst

As a DFIR Analyst, you will serve as the technical lead on small to medium-sized breach response investigations within a follow-the-sun team. You will own case-level evidence and documentation end-to-end while partnering with Engagement Managers on strategy and client communications. Your daily responsibilities include conducting EDR-driven incident response, performing advanced forensic analysis across endpoint, network, cloud, and SaaS environments, and developing tactical containment guidance for various attack patterns like ransomware or identity compromise. You will also mentor other analysts and build scripts to automate reporting workflows. Required expertise includes Windows, Linux, and macOS systems; tools such as X-Ways Forensics, Axiom, FTK, and SIEMs; and cloud incident response across AWS, Azure, or GCP. Technical skills include Python scripting, dynamic malware analysis, reverse engineering, and threat hunting in complex environments.

What you'll do

  • Serve as technical lead on breach response investigations to direct analytical focus and align work with client expectations.
  • Conduct EDR-driven incident response and forensic analysis across endpoint, network, cloud, and SaaS environments.
  • Develop tactical containment guidance and remediation recommendations tailored to specific attack patterns.
  • Acquire and preserve forensic evidence while maintaining strict chain-of-custody procedures and documentation standards.
  • Produce high-quality investigative reports and status updates for customers, legal counsel, and other stakeholders.
  • Mentor junior analysts on technical methodology, evidence handling, and investigation best practices.
  • Develop scripts and tools to automate recurring forensic analysis and reporting workflows.
  • Manage triage and analysis during high-pressure, large-scale incidents while maintaining clear decision-making.

What we're looking for

  • Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field (or equivalent practical self-study).
  • 4+ years of hands-on experience in digital forensics, incident response, or threat hunting.
  • Demonstrated experience serving as a lead or technical contributor on complex breach response engagements.
  • Expert-level experience with forensic investigative tools such as X-Ways Forensics, Axiom, and FTK.
  • Strong experience with EDR/XDR platforms (SentinelOne preferred) and SIEMs.
  • Working knowledge of cloud incident response methodology across at least one major provider (AWS, Azure, or GCP).
  • Experience conducting dynamic malware analysis and a solid understanding of the reverse engineering process.
  • Scripting ability (Python preferred) to automate investigative or analysis tasks.

More like this

Similar roles

Cyber Defense Response Analyst II

CME Group

Chicago, IL 18 days ago $93,900$156,500
Digital Forensics Incident Response Malware Analysis Python Pandas REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg SIEM

CISO Cybersecurity Forensic Analyst

IBM

11 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows Mac
3+ yrs exp

CISO Cybersecurity Forensic Analyst

IBM

29 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows
3+ yrs exp

CISO Cybersecurity Forensic Analyst

IBM

29 days ago
Digital Forensics Incident Response SIEM EDR Crowdstrike Microsoft Defender for Endpoint Python PowerShell EnCase FTK Autopsy X-Ways Axiom ELK SIFT Plaso IBM Cloud AWS Azure Linux Windows
3+ yrs exp

Staff Analyst, Investor Analytics

Upstart

Remote (Canada) 5 days ago $157,000$217,500
Python SQL Databricks Redshift DBT Tableau PowerBI Looker Claude Code Codex Machine Learning Data Pipelines Financial Modeling Data Visualization
5+ yrs exp Remote

Analyst II, CAF Technical Support and Reporting

Carmax

Kennesaw, GA 42 days ago $68,300$102,500
SQL Microsoft SQL Server Teradata SQL Transmitter Dimensional Modeling Data Migration Unit Testing Performance Testing Root Cause Analysis Service-Now Scripting Data Protection Security Compliance
1+ yrs exp Hybrid