Source Job

$145,000–$155,000/yr
US

  • Participate in all Incident Response activities with deep expertise in Forensic Analysis, including malware detection and reverse engineering.
  • Manage digital evidence chain of custody and perform forensic analysis across networks, hosts, and cloud environments.
  • Collaborate with security leadership to convert forensic insights into detection rules and support threat hunting operations.

Incident Response Malware Analysis

17 jobs similar to Forensics / Incident Response SME

Jobs ranked by similarity.

Unlimited PTO

  • Lead and execute complex digital forensics and incident response investigations across a range of engagement types.
  • Deliver high-quality analysis, client communication, and tailored deliverables for both technical and managerial audiences.
  • Collaborate with peers to improve methodologies, tooling, and automation to respond to emerging threats.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services to help organizations make better decisions and minimize risk. With over 1,300 employees and a focus on collaboration and mentorship, the company serves Fortune 500 companies and government agencies.

$96,798–$125,268/yr
Canada

  • Monitor security events and provide technical analysis on alerts
  • Lead information security incidents as Incident Commander, developing response strategies and coordinating across teams
  • Champion Samsara's cultural principles while delivering security guidance for incident response and insider threat initiatives

Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations to harness IoT data for actionable insights and improved operations. They are a recently public company with a culture that encourages rapid career development and a focus on digitizing large sectors of the global economy.

Australia 12w maternity 12w paternity

  • Triage and investigate intrusions, analyze logs and forensic artifacts to determine root causes.
  • Perform dynamic malware analysis and refine detection capabilities to address emerging threats.
  • Collaborate with product and engineering teams to evolve human-led agentic workflows.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, making enterprise-grade security accessible to businesses of all sizes. They secure over 5 million endpoints and 14 million identities worldwide with a remote-first team and a 24/7 human-led Security Operations Center.

$80,000–$85,000/yr
US

  • Monitor, analyze, and respond to complex security incidents, guiding Level 1 engineers and contributing to the organization's security posture.
  • Conduct in-depth forensic analysis, manage vulnerabilities, and optimize security tools such as SIEM, IDS/IPS, and endpoint protection.
  • Collaborate with IT and security teams, participate in on-call support, and stay updated on the latest cybersecurity threats and best practices.

CTS delivers comprehensive IT solutions for mission-driven organizations, with deep expertise in nonprofits and education. The company is headquartered in Brooklyn, NY with 90+ employees across the US and several other countries, fostering a culture of growth and innovation.

$182,000–$182,000/yr
United States

  • Lead deep-dive analysis of ICS-related malware and firmware, developing novel detection methods and Yara signatures.
  • Write persuasive customer-facing technical reports that translate complex malware findings into clear operational impact.
  • Collaborate across teams with hunters, intelligence analysts, and detection engineers to drive malware-related threat research.

Dragos is the global leader in xOT cybersecurity, combining technology, threat intelligence, and expert services. They have a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust.

US Unlimited PTO

  • Lead investigation and response for security incidents, suspicious activity, and emerging threats.
  • Design, implement, and improve security monitoring, detection, and response capabilities across AWS.
  • Develop detection rules, conduct post-incident reviews, and partner with teams to strengthen security controls.

CoLab is an AI platform that helps mechanical engineering teams bring life-changing products to market faster by driving stronger engineering decisions. Founded in 2019 and based in St. John's, Newfoundland, CoLab has grown rapidly, earning recognition on Deloitte's Fast 50 and Fast 500 lists.

US

  • Lead enterprise-wide response to high-risk cybersecurity incidents as Cyber Incident Commander, directing cross-functional efforts and driving containment to resolution.
  • Provide executive incident leadership by delivering updates to senior leaders and supporting decision-making during incidents.
  • Strengthen the incident response program through post-incident reviews, root cause analysis, and continuous improvements to response plans and playbooks.

Experian is a global data and technology company that powers opportunities for people and businesses across financial services, healthcare, automotive, and more. The company has a team of 25,200 employees in 32 countries and is known for its award-winning, people-first culture.

US

  • Conduct deep technical research into malware, firmware, and adversary tools targeting industrial environments.
  • Develop YARA signatures and detection strategies to protect critical infrastructure.
  • Collaborate with analysts and engineers to transform research into actionable defenses.

The company defends critical infrastructure from advanced cyber threats. It operates with a remote-first, mission-driven culture focused on innovation and transparency.

$75,600–$97,200/yr
Ireland

  • Triage, investigate, and respond to alerts from the Huntress platform daily.
  • Perform tactical review of EDR telemetry, log sources, and forensic artifacts to determine root causes and provide remediations.
  • Contribute to detection engineering and collaborate with a passionate team dedicated to protecting companies from cyber-attacks.

Huntress is a cybersecurity company founded in 2015 by former NSA cyber operators, providing enterprise-grade cybersecurity to businesses of all sizes. They secure over 5M endpoints and 14M identities worldwide with a 24/7 human-led SOC and a remote-first culture.

Canada

  • Develop processes, tooling and automation to scale incident management response and mitigate risks.
  • Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
  • Maintain security logging platform and stay updated on threats to improve detection mechanisms.

ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.

$113,800–$139,000/yr
US

  • Monitor, investigate, and respond to security alerts from SIEM, EDR/XDR, IDS/IPS, firewall, cloud, identity, and endpoint security platforms.
  • Perform incident response and threat hunting activities, including alert triage, root cause analysis, containment, and documentation.
  • Analyze endpoint, authentication, firewall, VPN, cloud, and network activity to identify indicators of compromise and suspicious behavior.

Clear Capital is a national real estate analytics, data solutions, and valuation technology company that builds confidence in real estate decisions. The company values integrity, kindness, grit, empathy, attention to detail, and raising the bar.

US

  • Provide technical leadership and assist sales teams by presenting products and managing trials.
  • Conduct file analysis, malware analysis, and reverse engineering for enterprise clients.
  • Maintain relationships with technical staff and complete RFPs and security questionnaires.

ReversingLabs develops cyber threat detection and mitigation tools that address advanced persistent threats and polymorphic malware. The company has an international team and fosters a collaborative, growth-oriented culture.

$153,000–$214,000/yr
US Canada

  • Lead end-to-end response to product security incidents, from discovery to disclosure.
  • Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
  • Drive coordinated vulnerability disclosure and partner with external security researchers.

1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.

US

  • Teach digital forensics and cyber investigation courses through project-based online instruction.
  • Guide students in digital evidence collection, examination, analysis, and reporting.
  • Provide timely feedback and help students connect technical concepts to real-world investigative scenarios.

The partner company is a higher education institution offering online cybersecurity programs. It serves a diverse, globally distributed student population with flexible learning needs.

$205,000–$215,000/yr
US Unlimited PTO

  • Architect the SOC strategy and roadmap, defining threat intelligence operations, detection frameworks, and defensive maturity metrics.
  • Build and tune detection logic across cloud stacks, identity layers, and endpoints, rejecting noise to accelerate incident response velocity.
  • Own incident command, leading containment and recovery operations while driving engineering change through rigorous post-mortems.

Second Front Systems is a public-benefit software company that accelerates secure software development and deployment for government and regulated networks. Founded by national security veterans, the company is a high-growth startup backed by top-tier venture capital with a culture of accountability and technical craft.

Global

  • Monitor, triage, and investigate security incidents across Kraken's infrastructure and client instances.
  • Develop and automate detection capabilities and incident response processes.
  • Collaborate with engineering and product teams to improve security posture and respond to incidents.

We power some of the most innovative global developments in energy by creating technology that redefines utilities. We are a growing global team committed to improving the lives of one billion humans within the decade.

Mexico

  • Lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments.
  • Partner with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents and communicate risk.
  • Support continuous improvement through automation, AI-assisted security workflows, and detection tuning.

Oportun is a mission-driven financial services company that empowers members with intelligent borrowing, savings, and budgeting capabilities. Since inception, it has provided over $21.3 billion in responsible credit and fosters a diverse, equitable, and inclusive culture.