1

Dfir Jobs in Oregon (NOW HIRING)

Perform forensic analysis using industry-standard forensic tools and open-source DFIR utilities. * Assist with forensic investigations involving endpoints, servers, malware, and cyber incidents.

Dfir information

See Oregon salary details

$35.4K

$145.6K

$184K

How much do dfir jobs pay per year?

As of Aug 3, 2026, the average yearly pay for dfir in Oregon is $145,636.00, according to ZipRecruiter salary data. Most workers in this role earn between $117,400.00 and $182,900.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in the DFIR position?

To thrive as a DFIR (Digital Forensics and Incident Response) professional, you need expertise in computer forensics, incident response methodologies, and network security, typically supported by a related degree or cybersecurity certifications like GCFA, GCFE, or CEH. Familiarity with forensic imaging tools (e.g., EnCase, FTK, X-Ways), SIEM platforms, and scripting languages is crucial for investigating and addressing security incidents. Analytical thinking, problem-solving, and strong communication skills set individuals apart in this position. These capabilities are essential for accurately identifying, analyzing, and mitigating digital threats in high-pressure environments.

What are some common challenges faced by DFIR professionals in their daily work?

DFIR professionals often handle cases involving complex cyberattacks, requiring them to quickly analyze large volumes of digital evidence and determine the scope of incidents. Challenges can include working under tight time constraints, managing sensitive information, and staying updated with rapidly evolving attack techniques and security technologies. Teamwork and collaboration with other IT and security personnel are frequent, as incident response is rarely a solo effort. Success in this field typically relies on a balance of technical expertise, methodical investigation, and the ability to adapt to new threats and technologies on a daily basis.

What is a DFIR?

A DFIR (Digital Forensics and Incident Response) job involves investigating cybersecurity incidents, analyzing digital evidence, and responding to security breaches. Professionals in this field use forensic tools to recover data, trace attack origins, and mitigate cyber threats. DFIR experts work in law enforcement, private security firms, and corporate cybersecurity teams. Their responsibilities include malware analysis, log analysis, and ensuring systems are secured against future attacks. Strong technical skills in digital forensics, networking, and security best practices are essential for success in this field.

What are the most commonly searched types of Dfir jobs in Oregon? The most popular types of Dfir jobs in Oregon are:
What are popular job titles related to Dfir jobs in Oregon? For Dfir jobs in Oregon, the most frequently searched job titles are:
Infographic showing various Dfir job openings in Oregon as of July 2026, with employment types broken down into 71% Full Time, and 29% Part Time. Highlights an 74% In-person, and 26% Remote job distribution, with an average salary of $145,636 per year, or $70 per hour.

Cyber Forensics Analyst

ECS

Portland, OR • On-site

Full-time

Re-posted 6 days ago


Job description

ECS is seeking a Cyber Forensics Analyst to work in our Portland, OR office. Note: This position is contingent upon contract award.
The Forensics Analyst Mid performs hands-on forensic analysis and malware investigation activities in support of SOC security investigations, incident response, routine memory checks, and advanced threat hunting. This role uses industry-standard forensic tools and strong investigative skills to collect, analyze, and document technical evidence.
The ideal candidate has solid cybersecurity experience, strong written communication skills, and the ability to operate resourcefully and independently while coordinating with SOC teams, data centers, and senior forensic personnel during investigations.
Key Responsibilities
Digital Forensics and Investigation
  • Perform forensic analysis using industry-standard forensic tools and open-source DFIR utilities.
  • Assist with forensic investigations involving endpoints, servers, malware, and cyber incidents.
  • Analyze Windows Registry, Windows System Calls, Linux artifacts, file system data, logs, and memory artifacts.
  • Create findings and technical notes that support investigative conclusions and remediation actions.

Malware Analysis and IOC Development
  • Analyze malware in a lab environment using standard malware analysis techniques.
  • Create IOCs based on forensic and malware findings for sharing with SOC and security teams.
  • Support Java code de-obfuscation and technical analysis activities within the analyst skill level.
  • Escalate complex malware or reverse-engineering requirements to senior analysts or the FMAT Lead.

SOC and Incident Response Support
  • Assist the SOC with security investigations and incident response activities.
  • Conduct routine memory checks on Linux and Windows servers as directed.
  • Support proactive malware analysis, incident response, and advanced threat hunting activities.
  • Communicate with different teams and data centers during investigations.

Reporting and Collaboration
  • Create clear investigation reports, forensic summaries, and supporting documentation.
  • Communicate findings effectively to SOC analysts, incident responders, data center teams, and leadership.
  • Apply strong investigative, research, and problem-solving skills to ambiguous technical issues.
  • Contribute to repeatable forensic procedures, knowledge sharing, and continuous process improvement.

  • U.S. Citizenship with ability to obtain and maintain a DOE "L" clearance after start.
  • 5 to 8 years of experience in cybersecurity, digital forensics, incident response, or related cyber investigation work.
  • Experience performing forensic analysis using industry-standard forensic tools and open-source tools.
  • Familiarity with Windows Registry, Windows System Calls, Linux operating systems, and Java code de-obfuscation.
  • Hands-on experience with Volatility or other memory forensics tools, FTK, and Wireshark.
  • Ability to create IOCs based on forensic analysis and share them with other security teams.
  • Ability to analyze malware in a lab environment using standard malware analysis techniques.
  • Experience performing or supporting forensic investigations and incident response activities.
  • Excellent written communication, resourcefulness, investigative ability, research skills, and problem-solving skills.