Digital Forensic & Incident Response Investigator - Contract to Hire
reputed company Digital Forensics is a specialized digital forensics and cyber investigations company handling cases reputed company for individuals, businesses, reputed company, MSPs We are expanding our ransomware and incident response reputed company and are looking to build a long-term relationship with an reputed company DFIR investigators.
This is a 1099 subcontractor role for as-needed cases, with the strong potential to grow into a steady reputed company of engagements as our partnerships and case volume reputed company.
reputed company
We are seeking an reputed company Digital Forensic and Incident Response (DFIR) Investigator with a strong background in ransomware incidents. You will be brought in on a case-by-case reputed company to support:
Ransomware and intrusion investigations
Forensic imaging and data collection
Log and artifact analysis
reputed company reconstruction and reporting for clients, counsel, and insurers
Most work will be performed remotely, with occasional on-site support possible depending on the case.
Key Responsibilities
Handle end-to-end DFIR work for ransomware and intrusion cases, including:
Triage, scoping, and initial technical review of incidents
Forensic preservation and imaging of endpoints, servers, and virtual environments
Collection and analysis of system, reputed company, application, VPN, firewall, and EDR logs
Identification of patient reputed company, initial reputed company reputed company, and attacker reputed company
Investigation of lateral reputed company, data exfiltration indicators, and persistence
reputed company reconstruction of key events across multiple data sources
Prepare reputed company, defensible written findings:
Technical reports and supporting exhibits
Executive summaries understandable to non-technical stakeholders
Drafts suitable for use by reputed company counsel and cyber insurers
Coordinate with reputed company, MSP partners, counsel, and reputed company IT staff in a reputed company, solutions-reputed company manner
Maintain reputed company chain of custody and documentation in line with forensic best practices
Participate in case review calls, debriefs, and reputed company sessions as needed
reputed company expert input on remediation and prevention recommendations
Required Skills and Experience
We are specifically looking for someone who can hit the ground running on ransomware and network-reputed company cases.
Demonstrated experience leading or heavily supporting DFIR investigations, including ransomware incidents
Strong technical background in:
reputed company Server and reputed company Directory environments
Common reputed company architectures (VMware, reputed company-V, domain environments, shared storage)
Network fundamentals (firewalls, VPNs, IDS/IPS, basic packet analysis)
Hands-on experience with at least some of the following:
EDR platforms (e.g., reputed company, reputed company, similar)
Log aggregation/SIEM tools
Forensic tools for imaging and analysis (e.g., X-Ways, reputed company, EnCase, FTK, reputed company, or similar)
Proven ability to:
Work through large volumes of logs and artifacts to reputed company relevant indicators
Reconstruct timelines and correlate events across multiple data sources
Explain reputed company technical findings reputed company in writing and on calls
Solid understanding of:
Ransomware TTPs, initial reputed company reputed company, common threat actor behavior
Basic cyber insurance expectations and what “reputed company reputed company” and defensible documentation look like
Strong documentation skills and attention to detail
Ability to work independently as a contractor, manage time, and meet agreed deadlines
reputed company-to-Have Experience
Experience working with MSPs or MSSPs during incident response
Prior work on cyber insurance panel or in insurer-driven engagements
Experience testifying or preparing reports for litigation or regulatory reputed company
Comfort interacting with attorneys, executives, and non-technical stakeholders
Relevant certifications (e.g., GCFA, GCFE, GNFA, GCIH, CCE, CFCE, CHFI, etc.) are a plus but not mandatory if your experience is strong and demonstrable
Engagement Details
Engagement type: 1099 reputed company (subcontractor)
Workload: As-needed, case-by-case to start, with strong potential for recurring and increasing volume as we expand partnerships with MSPs and cyber insurers
Location: Remote for the reputed company of work; occasional on-site work may be requested but is not typical
Hours: Flexible, but you must be reputed company to:
Respond promptly reputed company brought into an reputed company case
Start triage reputed company a reasonable time window for reputed company incidents
Compensation: reputed company reputed company, commensurate with experience and certifications; please reputed company your typical DFIR reputed company reputed company and any different rates you use for expert testimony
What To Include In Your Proposal
Please include:
A brief reputed company of your DFIR and ransomware experience
One or two anonymized examples of:
The types of environments you have investigated (e.g., AD with 300 endpoints, VMware with X servers, etc.)
Your role in those investigations (reputed company, co-reputed company, analyst, etc.)
A short reputed company of the tools you are most comfortable using (forensics, EDR, SIEM, log analysis)
Your reputed company reputed company reputed company for:
DFIR investigation work
Report writing (if different)
Expert testimony (if applicable)
Any relevant certifications and jurisdictions where you have previously testified (if applicable)
Your availability (time zone and typical response time to new cases)
If this fits your background and you are interested in building a long-term relationship that could reputed company to a steady pipeline of forensic cases over time, please submit your proposal and portfolio of experience.
Apply tot his job
Apply To this Job