Description
SentinelOne is hiring a DFIR Analyst to serve as technical lead on small- to medium-sized breach response investigations for its 24x7x365 follow-the-sun team. The role owns evidence handling, documentation, case strategy, containment guidance, remediation, reporting quality, handovers, and technical escalations while partnering with an Engagement Manager. Responsibilities include EDR-driven incident response, endpoint, network, cloud, and SaaS forensics, threat hunting, malware analysis, scripting, stakeholder communication, and rotating weekend and holiday on-call support. The role requires a bachelor's or master's degree or equivalent practical self-study, at least four years of relevant experience, and expertise with forensic tools, EDR/XDR, SIEMs, cloud environments, and scripting.
