As a DFIR team member, you will analyze and respond to cyber incidents, perform digital forensics investigations, and help clients mitigate cyber threats in cloud environments.
Cye's DFIR team is responsible for responding to our clients' cyber incidents and crises.
Our group is expanding. If you see yourself in the front line of the cybersecurity domain as a digital forensic and incident response (DFIR) talent, your place is with us. As a DFIR team member, you will participate in hands-on security research and investigations, helping our customers understand and mitigate cyber threats and attacks.
Responsibilities
- Perform incident response lifecycle and real-time activities, including detection and analysis, containment and eradication, and recovery
- Perform incident response in a cloud environment (Azure, AWS etc.).
- Perform digital forensics investigations
- Research and analyze tactics, techniques, and procedures (TTPs) used by malicious actors
- Perform hunt-evil and find-evil activities for proactively detecting attacks
- Work closely with our in-house red team, CTI, and cyber architect teams
- Work closely with worldwide companies, CISOs, and technology experts
Qualifications
- Must be based in the Central or Eastern regions of the US
- 1-2 years of experience as a DFIR team member
- Experience with performing digital forensics in a cloud environment
- Experience with performing digital forensics of Windows-based and/or Linux-based platforms, network forensics, and analysis
- Thorough understanding of threat hunting models, as well as cyber threat intelligence, including TTP and IoCs extraction and mapping
- Experience with research and data analysis of large DBs via Splunk, Elasticsearch, SQL, or VQL
- Strong understanding of targeted attacks; able to create customized tactical remediation plans
- Good written and verbal English communication skills
Cye helps security and risk leaders gain a clear, defensible view of their cyber exposure, grounded in financial impact and real-world attack paths. By continuously quantifying exposure and validating it in context, organizations can establish a strong baseline, prioritize decisions with confidence, and track measurable reduction over time.
Similar Jobs
Security • Cybersecurity
Support a federal customer’s ICS/OT cybersecurity and threat intelligence needs onsite in Norfolk, Virginia. Conduct threat research, analysis, hunting, attack-surface analysis, threat modeling, incident-response support, and cybersecurity exercises. Produce operational and strategic intelligence reports, briefings, and guidance by integrating classified and unclassified intelligence. Collaborate with customer security and intelligence teams and internal Dragos groups.
Top Skills:
DfirIcs/OtMalware RepositoriesNetflowOsintSIEMSynapseThreat HuntingThreat Modeling
Information Technology • Software • Cybersecurity
Lead digital forensics and incident response investigations across Windows, macOS, Linux, cloud, and SaaS environments. Investigate ransomware, nation-state threats, account takeovers, identity abuse, and multi-cloud intrusions across AWS, GCP, and Azure. Analyze endpoint, network, identity, and cloud audit data while maintaining rigorous evidentiary standards. Advise on investigative methodology, threat intelligence, and incident response services, and help design LLM-based tooling to accelerate triage, timeline creation, and reporting.
Top Skills:
Ai-Assisted ToolingAmazon GuarddutyAWSAzureCloudtrailEntra IdGCPLinuxLlmsmacOSMicrosoft 365Vpc Flow LogsWindows
Cloud • eCommerce • Information Technology • Retail • Software
Lead SOC detection, triage, and incident response; own escalated investigations and threat hunting; improve detections and automation; coach analysts; collaborate with exposure management, security engineering, and cloud teams; participate in on-call rotation and drive thorough incident documentation and closure.
Top Skills:
DfirEdrMitre Att&CkSIEM
What you need to know about the Chicago Tech Scene
With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.
Key Facts About Chicago Tech
- Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
- Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
- Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
- Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory



