Senior DFIR Analyst

SentinelOne

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Salary
$108,000–$130,000 / yr
Posted
3 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $144k
This role $119k
$101k most similar roles pay here $178k

This role pays less than 75% of similar roles. Most pay $118,450–$170,462 — the shaded band above. At the midpoint, this role pays about $119k versus about $144k for comparable roles.

Based on 240 similar postings.

Employer

About SentinelOne

SentinelOne is a cybersecurity company that provides an AI-powered extended detection and response (XDR) platform. Its Singularity platform delivers autonomous endpoint, cloud, and identity protection for enterprises.

SentinelOne currently has 11 open roles on FindRole.

Listed pay typically runs $132,000–$160,000 across 7 roles with salary data.

Most-posted roles

View all roles at SentinelOne

At a glance

TL;DR · Senior DFIR Analyst

As a Sr. DFIR Analyst, you will serve as a technical lead on small to medium-sized breach response investigations within a follow-the-sun team. You will manage case-level evidence and documentation quality end-to-end while partnering with engagement managers on strategy and client communications. Your daily responsibilities include conducting EDR-driven incident response, performing advanced forensic analysis across endpoint, network, cloud, and SaaS environments, and developing tactical containment guidance for various attack patterns like ransomware or identity compromise. You will utilize tools such as X-Ways Forensics, Axiom, FTK, and SIEMs while leveraging Python to automate workflows. The role requires expertise in Windows, Linux, and macOS systems, along with experience in dynamic malware analysis and cloud incident response across AWS, Azure, or GCP to solve complex security challenges for global clients.

What you'll do

  • Serve as technical lead on breach response investigations to direct analytical focus and align work with client expectations.
  • Conduct EDR-driven incident response and advanced forensic analysis across endpoint, network, cloud, and SaaS environments.
  • Develop tactical containment guidance and remediation recommendations tailored to specific attack patterns.
  • Acquire and preserve forensic evidence while maintaining strict chain-of-custody procedures and documentation standards.
  • Produce high-quality investigative reports and interim status updates for customers, legal counsel, and other stakeholders.
  • Mentor junior analysts on technical methodology, evidence handling, and investigation best practices.
  • Build or improve scripts, tools, and AI-assisted processes to streamline forensic workflows.
  • Manage triage and analysis during high-pressure, large-scale incidents while maintaining clear decision-making.

What we're looking for

  • Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field (or equivalent practical self-study).
  • 4+ years of hands-on experience in digital forensics, incident response, or threat hunting.
  • Demonstrated experience serving as a lead or technical contributor on complex breach response engagements.
  • Expert-level experience with forensic investigative tools such as X-Ways Forensics, Axiom, and FTK.
  • Strong experience with EDR/XDR platforms (SentinelOne preferred) and SIEMs.
  • Working knowledge of cloud incident response methodology across at least one major provider (AWS, Azure, or GCP).
  • Experience conducting dynamic malware analysis and a solid understanding of the reverse engineering process.
  • Scripting ability (Python preferred) to automate investigative or analysis tasks.

More like this

Similar roles

DFIR Analyst

SentinelOne

7 days ago $108,000$120,000
DFIR EDR XDR SIEM Python AWS Azure GCP X-Ways Forensics Axiom FTK Malware Analysis Reverse Engineering Windows Linux macOS Network Security Threat Hunting SaaS
4+ yrs exp

Cyber Defense Response Analyst II

CME Group

Chicago, IL 21 days ago $93,900$156,500
Digital Forensics Incident Response Malware Analysis Python Pandas REST APIs AWS GCP Azure Q Radar Sentinel Splunk Chronicle ArcSight KAPE EnCase Cellebrite FTK Magnet Axiom Autopsy Ghidra Ida Pro PEStudio x64dbg SIEM

Security Operations Analyst

Anduril Industries

Seattle, WA 27 days ago $129,000$171,000
Python SIEM SPL KQL SQL AWS Azure GCP Detection-as-Code Incident Response Threat Hunting Log Analysis Data Lake Windows Linux MacOS Digital Forensics Reverse Engineering

Security Operations Analyst

Anduril Industries

Washington, DC 27 days ago $129,000$171,000
Python SIEM SPL KQL SQL AWS Azure GCP Detection-as-Code Incident Response Threat Hunting Data Lake Linux Windows MacOS Digital Forensics Reverse Engineering Cloud Infrastructure

Security Operations Analyst

Anduril Industries

Boston, MA 27 days ago $129,000$171,000
Python SIEM SPL KQL SQL AWS Azure GCP Detection-as-Code Incident Response Threat Hunting Data Lake Linux Windows MacOS Digital Forensics Reverse Engineering

Security Operations Analyst

Anduril Industries

Costa Mesa, CA 27 days ago $129,000$171,000
Python SIEM SPL KQL SQL AWS Azure GCP Detection-as-Code Incident Response Threat Hunting Data Lake Linux Windows MacOS Digital Forensics Reverse Engineering