Remote Jobs RockRemote Jobs Rock

Principal Consultant, Cloud DFIR (Unit 42) - Remote

📅 Aug 9
DFIRIncident ResponseCloud SecurityAWS

📜 Description

  • Lead cloud-focused incident response and digital forensics engagements.
  • Investigate attacks involving cloud infrastructure, identity compromise, ransomware, data theft, and unauthorized access.
  • Analyze cloud telemetry, including audit logs, IAM activity, network traffic, storage access, containers, and endpoint data.
  • Conduct forensic acquisition and analysis across cloud, hybrid, and enterprise environments.
  • Serve as a technical lead during active investigations, guiding strategy and client communications.
  • Deliver clear findings, executive-ready reporting, and remediation guidance.

🛠️ Requirements

  • 6–8+ years of experience in DFIR, incident response, cloud security, or related cybersecurity disciplines.
  • 3+ years of hands-on experience securing, operating, or investigating AWS, Azure, or GCP environments.
  • Experience leading investigations involving cloud breaches, ransomware, advanced intrusions, or data compromise incidents.
  • Strong understanding of cloud architecture, IAM, networking, logging, and security controls.
  • Experience analyzing cloud-native telemetry such as AWS CloudTrail, Azure Activity Logs, Microsoft Entra ID, or Google Cloud Audit Logs.
  • Hands-on experience with industry-standard DFIR and investigative tools.
  • Experience investigating Windows, Linux, macOS, cloud workloads, and hybrid environments.
  • Strong client-facing communication and consulting skills.
Full job description

As a Principal Consultant in Cloud DFIR at Palo Alto Networks, you will lead cloud-focused incident response and digital forensics investigations to protect digital environments.

Description

  • Lead cloud-focused incident response and digital forensics engagements.
  • Investigate attacks involving cloud infrastructure, identity compromise, ransomware, data theft, and unauthorized access.
  • Analyze cloud telemetry, including audit logs, IAM activity, network traffic, storage access, containers, and endpoint data.
  • Conduct forensic acquisition and analysis across cloud, hybrid, and enterprise environments.
  • Serve as a technical lead during active investigations, guiding strategy and client communications.
  • Deliver clear findings, executive-ready reporting, and remediation guidance.

Requirements

  • 6–8+ years of experience in DFIR, incident response, cloud security, or related cybersecurity disciplines.
  • 3+ years of hands-on experience securing, operating, or investigating AWS, Azure, or GCP environments.
  • Experience leading investigations involving cloud breaches, ransomware, advanced intrusions, or data compromise incidents.
  • Strong understanding of cloud architecture, IAM, networking, logging, and security controls.
  • Experience analyzing cloud-native telemetry such as AWS CloudTrail, Azure Activity Logs, Microsoft Entra ID, or Google Cloud Audit Logs.
  • Hands-on experience with industry-standard DFIR and investigative tools.
  • Experience investigating Windows, Linux, macOS, cloud workloads, and hybrid environments.
  • Strong client-facing communication and consulting skills.
Cyberark1

Channel Solutions Consultant

Cyberark1👥 10,000+ employees🏢 Computer & Network Security
🕒 5 days ago

As a Channel Solutions Consultant at Palo Alto Networks, you will lead technical strategies for strategic reseller partners, driving growth through enhanced security practices and services.

Partner Solution ConsultingSystems EngineeringSecurity ArchitectureTechnical Leadership
🕒 4 days ago

As a Senior Consultant in Veeva's Managed Services team, you will support biopharmaceutical clients in implementing and optimizing the Vault Safety solution, ensuring effective drug safety and pharmacovigilance practices.

Drug SafetyPharmacovigilanceSQLSafety Systems Implementation

Trusted by Remote Workers