Description
SentinelOne is hiring a DFIR Analyst to deliver rapid, evidence-based breach response for global enterprises facing active cyber threats. The role performs endpoint, network, cloud, and SaaS forensic analysis, threat hunting, malware and memory analysis, evidence acquisition, incident containment, documentation, reporting, and handovers across incidents such as ransomware, business email compromise, identity compromise, zero-day exploitation, APT activity, and cloud/SaaS breaches. The position requires a bachelor's or master's degree or equivalent practical self-study, at least two years of relevant experience, and familiarity with forensic tools, EDR/XDR platforms, SIEMs, scripting, and technical investigations under pressure. It is available in Prague, Brno, or remote in the Czech Republic or Slovakia, with Prague-based employees required to work from the office at least two days per week.
