1

Dfir Analyst Jobs (NOW HIRING)

CSIRT Analyst

Buffalo, NY

$111K - $125K/yr

You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly ... analysis of extracted artifacts and professional post-incident report writing * A bachelor or ...

CSIRT Analyst

Buffalo, NY · On-site

$111K - $125K/yr

You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly ... analysis of extracted artifacts and professional post-incident report writing * A bachelor or ...

$151K - $208K/yr

Job Summary Job Summary The Principal Consultant, Cloud DFIR, Reactive Services is a senior ... Analyze cloud telemetry, including audit logs, IAM activity, network traffic, storage access ...

CSIRT Analyst

Buffalo, NY · On-site

$80 - $120/hr

You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly ... forensic analysis of extracted artifacts and professional post‑incident report writing * A ...

New

You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly ... analysis of extracted artifacts and professional post-incident report writing * A bachelor or ...

You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly ... analysis of extracted artifacts and professional post-incident report writing * A bachelor or ...

Senior Cyber Lead

Linthicum Heights, MD · On-site

$175K - $225K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... analysis, cyber defense operations, and mission-critical DFIR activities. Responsibilities: * Lead cyber operations, digital forensics, incident response, intrusion analysis, and malware analysis ...

Showing results 21-40

Dfir Analyst information

See salary details

$31K

$73.3K

$130K

How much do dfir analyst jobs pay per year?

As of Aug 19, 2026, the average yearly pay for dfir analyst in the United States is $73,261.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,500.00 and $87,000.00 per year, depending on experience, location, and employer.

What is a DFIR analyst?

A DFIR Analyst, or Digital Forensics and Incident Response Analyst, is a cybersecurity professional who investigates and responds to security incidents, such as data breaches or cyberattacks. Their role involves collecting, analyzing, and preserving digital evidence, identifying the scope and impact of incidents, and recommending steps to mitigate future risks. DFIR Analysts utilize specialized tools and techniques to track cyber threats, recover compromised data, and support legal or regulatory actions as needed. They play a crucial role in helping organizations understand and recover from cybersecurity incidents.

What are some common challenges faced by DFIR analysts during incident response investigations?

DFIR Analysts often encounter challenges such as analyzing large volumes of data under tight time constraints, ensuring evidence integrity during collection, and keeping up with rapidly evolving cyber threats. Working across multiple systems and platforms requires strong attention to detail and adaptability. Collaboration with IT, legal, and management teams is essential, and communicating complex technical findings in an understandable way can also be demanding. These challenges make the role dynamic and require continuous learning and effective teamwork.

What are the key skills and qualifications needed to thrive as a DFIR analyst, and why are they important?

To thrive as a DFIR Analyst, you need a solid understanding of computer forensics, incident response procedures, and network security, typically supported by a degree in cybersecurity or computer science and certifications like GIAC or EnCE. Familiarity with forensic tools (e.g., EnCase, FTK, X-Ways), SIEM platforms, and malware analysis systems is crucial. Strong analytical thinking, attention to detail, and effective communication help you excel when investigating incidents and presenting findings. These skills are essential for accurately identifying, mitigating, and reporting cyber threats to protect organizational assets.

What is the difference between Dfir Analyst vs Cybersecurity Analyst?

AspectDfir AnalystCybersecurity Analyst
Required CertificationsGCFA, GCFE, EnCECISSP, Security+, CEH
Work EnvironmentForensic labs, incident response teamsSecurity operations centers, threat analysis teams
Industry UsageLegal, law enforcement, corporate incident responseIT security, risk management, threat detection

While both roles focus on security and incident handling, Dfir Analysts specialize in digital forensics and evidence collection, often working in legal or law enforcement contexts. Cybersecurity Analysts focus on protecting systems proactively, monitoring threats, and preventing attacks. Both roles require certifications like Security+ or EnCE, but their daily tasks and environments differ significantly.

More about Dfir Analyst jobs
Infographic showing various Dfir Analyst job openings in the United States as of August 2026, with employment types broken down into 85% Full Time, and 15% Contract. Highlights an 61% In-person, 8% Hybrid, and 31% Remote job distribution, with an average salary of $73,261 per year, or $35.2 per hour.

$111K - $125K/yr

Full-time

Re-posted 15 days ago


Job description

Overview

Do you have a passion for Cyber Security, especially advanced Managed Detection & Response (MDR)? Does Incident Response, Digital Forensics, Threat Hunting, Threat Intelligence and everything related to Cyber Security feel like second nature to you? Are you a Cyber Defender at heart, driven to strengthen the blue team and help organizations that are under attack? If you answered yes to all of these questions, you might be the perfect fit for our CSIRT Analyst role!

  • You handle security alerts/incidents that have been escalated by the SOC Analysts (Tier 2)
  • You will handle security alerts and incidents together with your team
  • You conduct DFIR assignments, including DFIR readiness assessments
  • You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
  • You will perform compromise assessments to identify potential compromises and their scope
  • You collect Threat Intelligence (IOCs and TTPs)
  • You will contribute to Detection Engineering in SIEM, xDR.
  • Together with the Red Team you will do Purple Teaming exercises to test and improve defenses
  • You contribute to the creation of playbooks in SOAR
  • You will co-write processes and procedures related to DFIR, Threat Intelligence, Threat Hunting.
  • You will be part of our Incident Response on call service.

What you need to succeed:

  • At least 3-5 years of experience in a similar position.
  • Significant hands-on experience in disk, memory and log acquisition in a forensically sound manner, parsing and deep forensic analysis of extracted artifacts and professional post-incident report writing
  • A bachelor or master degree or equivalent through experience.
  • A hands-on and proactive mindset with a 'can do' mentality.
  • Experience and/or interest in working with the following MDR tools: EDR (CrowdStrike Falcon, MS Defender for Endpoint, Sentinel One, ...), NDR (Vectra, Darktrace, ...), xDR (CrowdStrike Identity Protection, MS Defender for Office/Clouds Apps/Identity/...).
  • Knowledge of Security Monitoring with SIEM technologies.A passion about the following security capabilities: Security Monitoring, Digital Forensics, Incident Response, Threat Intelligence, Threat Hunting.

Computer Task Group logo

About Computer Task Group

Sourced by ZipRecruiter

We know that achieving our mission begins and ends with our people—and by people we mean you. Regardless of individual roles or responsibilities, regardless of industry or subject matter expertise, our lives happen in relation to other people—our colleagues, clients, and partners. CTG cultivates a workplace that attracts and develops the best people. Being Great Place to Work-CertifiedTM not only supports our Vision but also validates the rewarding workplace culture that has made CTG a leading IT and digital solutions and services company for more than 55 years.

Company size

1,001 - 5,000 Employees

Headquarters location

Buffalo, NY, US

Year founded

1966

Social media