The RoleThis contractor position spans two disciplines: leading incident response operations — from initial triage and live endpoint collection through containment, eradication and recovery — and conducting in-depth digital forensic analysis of Windows, Linux and macOS systems, memory images and network traffic, while coordinating client communications and regulatory reporting.
Skills & Experience Candidates should be proficient with forensic collection tools such as KAPE, Velociraptor, UAC and CyLR, and analysis platforms including Volatility and MemProcFS.
Experience with EDR-based IR, Active Directory attack techniques (Kerberoasting, golden/silver tickets), IOC development (YARA, Sigma), and knowledge of NIS2 and relevant cybersecurity legislation is expected.
Who It Suits
This role suits an experienced DFIR skilled comfortable operating independently as a freelancer or contractor, who can lead war-room incidents, communicate with executive and legal stakeholders, and perform deep forensic analysis — ideally with exposure to regulated environments and multi-client consulting engagements.