T
Tokio Marine HCC
Posted 53 days agoVerified live 2d ago

DFIR Consultant

Brief overview

Remote
UndergradOr in progress
$87k–$131k/yrStated range
2+ yrsMinimum
Digital ForensicsIncident ResponseSecurity OperationsEndpoint, Server, and Cloud Log AnalysisEvidence HandlingInvestigative Report WritingCISSPCISMGCFEGCFAGREMGCIH

Job description

Summary

Tokio Marine HCC, through Vector3, Inc., is an incident response firm supporting TMHCC Cyber and Professional Lines Group and specializing in business email compromise and ransomware incidents. The DFIR Consultant will investigate client incidents from initial triage through evidence preservation, analysis, and reporting, while communicating findings and supporting continuous improvement of DFIR operations.

Responsibilities

  • Perform triage, acquisition, preservation, and analysis of endpoint, server, cloud, and log evidence to determine scope, impact, and root cause
  • Develop accurate timelines, identify affected assets and accounts, and document investigative findings in a clear and defensible manner
  • Support analysis of malware, suspicious scripts, persistence mechanisms, credential theft, lateral movement, and data theft activity
  • Use repeatable methods and validated workflows to ensure evidence integrity and investigation quality
  • Communicate professionally with internal stakeholders, clients, insurers, legal counsel, and other approved parties during active matters
  • Prepare concise updates, investigation notes, and report content that translate technical detail into actionable business and response guidance
  • Support status calls, evidence requests, and coordination of next steps across involved teams
  • Contribute to playbooks, templates, evidence handling procedures, and knowledge articles that improve team efficiency and consistency
  • Identify repeatable investigative tasks that can be standardized, automated, or improved for scale
  • Support after-action reviews and lessons learned to strengthen the DFIR practice and client outcomes
  • Contribute to the development of both short-term and long-term plans for designated area of the organization
  • Apply strong technical analysis skills to digital forensic evidence, incident data, and client environments
  • Write, or is a major contributor to, investigative reports and documentation
  • Work accurately under time pressure while maintaining defensible methods and attention to detail
  • Develop innovative ways to improve financials and increase operational efficiency
  • Comply with all corporate policies and procedures
  • Identify control objectives for the designated function and help implement cost effective controls designed to meet those objectives

Skills

  • Minimum 4 Year / bachelor's degree in cyber security, Computer Science, Information Technology related degree
  • 2+ years of professional experience in digital forensics, incident response, security operations, or related investigative work
  • Experience performing endpoint, server, and cloud log analysis in support of cyber incidents
  • Experience with common DFIR tools, evidence handling, and report writing
  • Ability to manage multiple active matters while maintaining quality and deadlines
  • Excellent communication skills to clearly and concisely communicate complex technical concepts to stakeholders
  • Preferred advanced degrees or certifications (CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE) are a plus

Qualifications

Must Haves

  • Minimum 4 Year / bachelor's degree in cyber security, Computer Science, Information Technology related degree
  • 2+ years of professional experience in digital forensics, incident response, security operations, or related investigative work
  • Experience performing endpoint, server, and cloud log analysis in support of cyber incidents
  • Experience with common DFIR tools, evidence handling, and report writing
  • Ability to manage multiple active matters while maintaining quality and deadlines
  • Excellent communication skills to clearly and concisely communicate complex technical concepts to stakeholders

Nice to Haves

  • Preferred advanced degrees or certifications (CISSP, CISM, GCFE, GCFA, GREM, GBFA, GCIH, CFCE, CCE) are a plus

Benefits

  • Competitive salary and employee benefit package
  • Strong learning culture
  • Growth perspectives
  • 6% 401K match
  • 20 days of PTO and 2 Floating Days
  • Paid parental leave
  • An opportunity to love what you do

More jobs like this