DFIR Specialist – Senior SOC Analyst

Job not on LinkedIn

🔥 12 hours ago

🇵🇭 Philippines – Remote

⏰ Full Time

🟠 Senior

🛡️ Security Operations

👻 Ghost score 12%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of THEOS Cyber

THEOS Cyber

11 - 50 employees

Founded 2019

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

THEOS Cyber is a cybersecurity services firm that provides managed threat detection and response, red teaming, penetration testing, cyber engineering, and digital forensics/incident response to help organizations detect, contain, and remediate cyber threats. The company works with enterprise clients across sectors such as casinos, crypto, financial services, fintech, gaming, manufacturing, NGOs, technology, and utilities, and partners with vendors like Microsoft, CrowdStrike, and Claroty. THEOS emphasizes a customer-focused, outcomes-driven approach with 24/7 monitoring, human-led analysis, threat hunting, and tailored engineering and consulting services.

📋 Description

• Lead end-to-end incident response engagements across business email compromise, ransomware, data breaches, insider threats, and compromise assessment cases • Guide clients through investigation, containment, and long-term remediation • Conduct forensic analysis across cloud, Windows, Linux, and macOS environments • Analyze network traffic and log data from web application firewalls, firewalls, endpoints, cloud platforms, and applications • Use CrowdStrike, FTK, next-generation SIEM platforms, and Magnet AXIOM to identify IOCs, threat-actor TTPs, root cause, and scope of impact • Collaborate with clients and internal stakeholders to communicate findings, provide timely updates, and deliver comprehensive reports • Mentor junior staff and share incident response and digital forensics best practices • Maintain awareness of the evolving threat landscape, including emerging AI- and large language model-related threats • Improve playbooks, methodologies, and tooling, including artefact collectors and parsers • Feed lessons from live engagements back into processes and automation • Travel approximately 5% for on-site client engagements

🎯 Requirements

• Bachelor's degree in Information Security, Computer Science, Digital Forensics, Cybersecurity, or a related discipline, or equivalent professional experience • Experience administering, monitoring, or investigating cloud platforms such as Microsoft Azure, AWS, Google Workspace, or Alibaba Cloud • Minimum of four years of direct experience in cybersecurity operations • Strong proficiency in rapid incident response, creative problem-solving, and report writing • An investigative mindset, with an interest in solving complex problems, learning new techniques, and continuously improving • Prior experience in a client-facing incident response consulting role • Direct experience in incident response and/or digital forensics, with practical experience using forensic and incident response tools • Prior experience developing and delivering tabletop exercises • Strong executive presence, with the ability to present complex technical findings to C-level stakeholders • Proven ability to build collaborative relationships with internal teams, external partners, and clients • Work authorisation requirements may vary by location and will be discussed as part of the process

🏖️ Benefits

• Travel as required, approximately 5%, to support client and business needs through on-site engagements

Apply Now