Principal Consultant, DFIR, Reactive Services – LATAM

🔥 0 minutes ago

🗣️🇪🇸 Spanish Required

🗣️🇧🇷🇵🇹 Portuguese Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Palo Alto Networks

Palo Alto Networks

10,000+ employees

🔒 Cybersecurity

🏢 Enterprise

💰 $1M Seed Round - Morta Security on 2013-02

Cybersecurity • Enterprise

Palo Alto Networks is a global cybersecurity company that provides AI-driven platforms, products, and services to protect networks, cloud workloads, endpoints, and applications. Its portfolio includes next-generation firewalls, SASE and Prisma Cloud (CNAPP) offerings, the Cortex security operations suite (XDR, XSOAR, XSIAM), and Unit 42 threat intelligence and incident response services. Palo Alto Networks helps enterprises secure AI deployments, automate SOC workflows, and prevent, detect, and respond to sophisticated threats across hybrid and multi-cloud environments.

📋 Description

• Lead and execute complex digital forensics and incident response investigations across enterprise environments. • Serve as a technical lead during ransomware, business email compromise, malware, insider threat, unauthorized access, data theft, and advanced intrusion investigations. • Conduct advanced forensic analysis of endpoints, systems, logs, networks, and cloud environments. • Lead host, network, identity, and cloud investigations during active incidents. • Perform and oversee forensic acquisition, preservation, and analysis in accordance with chain-of-custody procedures. • Use DFIR tools, investigative methodologies, and threat intelligence to support containment, eradication, and recovery. • Manage technical workstreams and coordinate activities across client teams, internal stakeholders, and third-party partners. • Translate technical findings into investigative summaries, timelines, executive briefings, and client-facing reports. • Present findings and recommendations to technical teams, business leaders, legal counsel, and executives. • Provide remediation guidance throughout the incident response and recovery lifecycle. • Mentor junior and mid-level consultants. • Support engagement planning, scoping, quality assurance, delivery, business development, client briefings, and technical discussions. • Contribute to internal DFIR processes, playbooks, tools, training materials, and knowledge-sharing initiatives. • Maintain awareness of emerging threats, attacker techniques, forensic methodologies, and cybersecurity trends. • Travel up to 20% throughout Latin America for client engagements.

🎯 Requirements

• Bachelor’s degree in Computer Science, Information Security, Digital Forensics, or a related field, or equivalent practical experience. • 6–8 years of hands-on experience in Digital Forensics and Incident Response, Security Operations, SOC, threat hunting, or related cybersecurity disciplines. • Experience leading or independently managing complex enterprise incident response investigations. • Experience investigating ransomware, intrusion activity, phishing, malware, business email compromise, insider threats, data theft, or unauthorized access incidents. • Strong knowledge of forensic methodologies, evidence handling, forensic acquisition techniques, and chain-of-custody procedures. • Hands-on experience with EnCase, FTK, Sleuth Kit, Volatility, Velociraptor, X-Ways, Magnet AXIOM, or equivalent forensic frameworks. • Experience investigating Microsoft Windows, Linux, and macOS environments. • Experience analyzing endpoint, network, identity, cloud, and security-platform data. • Understanding of attacker techniques, persistence mechanisms, lateral movement, credential access, and indicators of compromise. • Strong analytical and problem-solving skills. • Excellent written and verbal communication skills. • Ability to communicate complex technical findings to technical and executive audiences. • Ability to manage client relationships and provide trusted technical guidance during critical incidents. • LATAM candidates must be fluent in English and Spanish, English and Portuguese, or Spanish and Portuguese; English, Spanish, and Portuguese is preferred. • Ability to communicate effectively with clients and internal teams across Latin America. • Preferred: experience with cloud, hybrid, or multinational investigations; MITRE ATT&CK; malware analysis; threat hunting; EDR; AWS; Microsoft Azure; Google Cloud Platform; Microsoft 365; cybersecurity consulting; managed security services; MDR; incident response organizations; mentoring; concurrent investigations; listed industry certifications; multinational or enterprise clients in Latin America. • Willingness to travel up to 20% throughout Latin America. • Applicants must not require immigration sponsorship; the employer will not sponsor work visas.

🏖️ Benefits

• Remote work arrangement • Travel support for client engagements (up to 20% throughout Latin America) • Reasonable accommodations for qualified individuals with a disability • Immigration sponsorship is not available

Apply Now

Similar Jobs

🕒 April 30

In All Media

1001 - 5000

💼 Consulting

📣 Marketing

☁️ SaaS

Senior UI/UX Developer at In All Media driving frontend engineering on projects for global organizations. Focusing on responsive, interactive web applications using React and Agile methodologies.

JavaScript

React

TypeScript

🕒 April 1

Codgo.X

11 - 50

💼 Consulting

📣 Marketing

🏢 Enterprise

Desenvolvedor(a) com experiência em ADVPL/TLPP e Angular para atuar na Codgo.X. Foco em arquitetura, desenvolvimento, integrações e melhoria contínua de sistemas no ecossistema Protheus.

🗣️🇧🇷🇵🇹 Portuguese Required

Angular

ERP

Linux

SQL

Subversion