MOXFIVE Logo

MOXFIVE

Principal DFIR Consultant

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
230K-300K Annually
Senior level
Remote
Hiring Remotely in USA
230K-300K Annually
Senior level
Lead digital forensics and incident response investigations across Windows, macOS, Linux, cloud, and SaaS environments. Investigate ransomware, nation-state threats, account takeovers, identity abuse, and multi-cloud intrusions across AWS, GCP, and Azure. Analyze endpoint, network, identity, and cloud audit data while maintaining rigorous evidentiary standards. Advise on investigative methodology, threat intelligence, and incident response services, and help design LLM-based tooling to accelerate triage, timeline creation, and reporting.
The summary above was generated by AI

Who We Are
If you feel like Incident Response and Recovery hasn't changed in the past 10 years, you're not alone. Business operations aren't just on endpoints anymore. It's behind applications in Okta tiles, auto-scaling workloads, code repos, and sprawling data stores across one or many public clouds. At MOXFIVE, we're focused on eradicating adversaries across our client's entire digital footprint, and that demands a faster, nimbler approach to DFIR, one where AI-driven tooling helps our consultants investigate faster without cutting corners on rigor.
We're looking to expand our IR Consulting Team with individuals driven to protect clients, eliminate threat actors, and build the next era of digital forensics and incident response for the modern enterprise, including the LLM-based investigative platform we're building to get them there.
Who You Are
You know that $I30 isn't referring to your local interstate, and that the easiest way to get on your bad side is to be handed a timestamp that isn't in UTC. You've got a "Tools" folder sitting on your workstation somewhere with your favorite forensic scripts at the ready to tear into the next piece of suspicious activity you see. And speaking of suspicious activity, you've honed a keen sense for knowing the difference between legitimate users and threat actor activity because you've seen them in action. Hundreds of times.
Windows environment investigations feel like the back of your hand at this point, and you've been starting to expand your knowledge on cloud-native forensics. Account takeovers are the new malware after all, and investigating the latest threats across Azure, GCP, AWS, and SaaS Apps is the growing frontier you've been looking to sink your teeth into. You know your way around CloudTrail and GuardDuty findings in AWS, Admin Activity and Data Access logs in GCP, and sign-in and audit logs in Entra ID, and you're just as comfortable chasing a rogue service principal or a suspicious Workload Identity Federation grant as you are pulling apart a $MFT.
You've also got an eye toward where the work is heading. You're not afraid to put LLMs and AI tooling to work as part of the investigative process, whether that's rapidly triaging thousands of authentication logs for anomalous patterns, building timeline narratives faster without sacrificing accuracy, or using AI-assisted tooling to spot the needle in a haystack of cloud audit logs. You know these tools augment a sharp analyst, they don't replace one, and you hold the output to the same evidentiary standard you'd hold your own analysis to. And you don't just want to be a consumer of that tooling. You want a hand in building it, translating what you know about how a real investigation actually unfolds into the logic, prompts, and guardrails of an LLM-based investigative platform that can eventually help the next analyst move faster than you did.
You're insatiably curious, addicted to threat intel, and a builder at heart. Ultimately, you're looking for the right opportunity that uses your technical chops to find and eliminate meaningful adversaries while putting your stamp on a better approach to traditional DFIR consulting.
Why You Matter
You'll be joining a seasoned team of high performing incident response consultants that are the tip of the spear for all forensic activity at MOXFIVE. From ransomware to nation-state threats, you'll be supporting and leading meaningful cases across traditional enterprise and cloud-native environments, including multi-cloud intrusions spanning AWS, GCP, and Azure where the adversary is living off cloud-native identity and API abuse rather than dropping malware on disk. Your voice has significant weight in shaping our technology stack, investigative methodology, and service offerings as we continue to scale, including how we responsibly build LLM-driven capabilities into the investigative workflow itself. You won't just be a user of that platform. Your casework, your instincts for what matters in an investigation, and your judgment calls in the field will directly shape how it's built, so that the methodology baked into the tooling reflects the same rigor you bring to a report.
What You'll Bring

  • Experience responding to threat activity as an IR consultant or SOC analyst

  • Strong understanding of Windows/Mac/Linux fundamentals, forensic artifacts, and network analysis

  • Existing knowledge or passion to learn cloud-native investigations across AWS, GCP, and Azure, including familiarity with core log sources like CloudTrail, VPC Flow Logs, GCP Admin Activity/Data Access logs, and Entra ID/M365 audit logs

  • Curiosity about how LLMs and AI-assisted tooling can accelerate investigation and reporting without compromising forensic rigor, and interest in helping shape an internal LLM-based investigative platform built to accelerate future casework

  • An unwavering emphasis on investigation at the highest level of quality

Similar Jobs

20 Days Ago
Remote
USA
122K-270K Annually
Senior level
122K-270K Annually
Senior level
Insurance
Lead and execute DFIR investigations for ransomware and BEC incidents: act as incident commander, manage triage/response, mentor and build DFIR team, develop IR processes, perform forensic analysis across endpoints, networks, memory and cloud, and communicate findings to clients and stakeholders.
Top Skills: AccessAWSAxiomAzureBashCrowdstrikeEdrElkEncaseExcelFtkGCPGoMicrosoft 365Microsoft DefenderPowerPointPowershellPythonSentineloneSiftVolatilityWordX-Ways
27 Minutes Ago
In-Office or Remote
153K-239K Annually
Senior level
153K-239K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Leads Boeing’s Systems Engineering, Integration and Test organization for the Sapphire program. Owns SEIT standards, governance, CONOPS, archetype roadmaps, engineering toolchains, requirements traceability, integration testing, KPIs, and continuous improvement. Provides technical leadership across engineering teams and IPTs, removes execution blockers, presents readiness evidence to executives, and drives repeatable delivery across PLM, ERP, MES, and related enterprise systems. Up to 20% travel may be required.
Top Skills: AdoAgileAlmBorisDigital ThreadDoorsErpIcdsJIRAMbseMesMicrosoft PlannerMicrosoft ProjectMiddlewareMomPdmPlmPolarionPower BIRequirements ManagementTeamcenterTest Automation
27 Minutes Ago
In-Office or Remote
133K-207K Annually
Senior level
133K-207K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Leads guidance, navigation, and control engineering for the MQ-25 unmanned aircraft, including requirements, nonlinear simulations, flight-control laws, software integration, verification, hardware-in-the-loop testing, contingency management, and flight-test support. Uses aerospace models and programming languages to develop and validate vehicle controllers, supports DO-178B/C activities, and mentors other engineers.
Top Skills: CC++Do-178B/CFortranHardware-In-The-LoopMatlabMatrixxPid ControlPythonSimulinkSystembuildVehicle Management Systems

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account