About the role
Our Senior DFIR Analyst role is an exciting opportunity for those looking to go head-to-head with today's cyber criminals. We're looking for a Senior DFIR Analyst with at least 2 years' experience to lead and support investigations into Business Email Compromise (BEC), ransomware, and web application breaches. You'll drive evidence collection, containment, forensic analysis, reporting while working alongside some of the best in the field.
You'll contribute your expertise to strategy and methodology across various incident types, with a particular focus on forensic investigations into complex cyber incidents. You'll operate confidently both independently and as part of a team, working across the full operational flow and attack chain of security incidents to help our clients respond to cyber attacks and other investigations.
Gridware responds to a broad range of incidents, including Business Email Compromise, insider threat and employee misconduct, cloud and network compromise, ransomware, and data extortion.
What you'll do
- Collect and preserve evidence
- Conduct host-based and network-based forensics
- Perform malware analysis
- Review cloud and application logs
- Use industry best-practice tools for log ingestion, threat hunting, and Endpoint Detection and Response, including KAPE, AXIOM, SOF-ELK, Velociraptor, CrowdStrike, and SentinelOne
What we're looking for
- Hands-on experience with CrowdStrike Falcon for endpoint investigation, threat hunting, and incident containment, including using Real Time Response (RTR) to support forensic evidence collection and response activities
- Real-world experience in incident response, digital forensics, or a security operations centre
- Demonstrated technical capability with digital forensics tools, particularly on Windows systems (experience with Linux and macOS investigations is a plus)
- An autonomous, critical thinker with a positive attitude and a team-first mindset
- General cyber security knowledge, including an understanding of the threat landscape, threat actor groups, and playbooks
- Strong communication skills, able to convey technical concepts to a broad range of audiences
- Certifications such as GCFE, GCFA, or GCIH are helpful in demonstrating capability but not essential
Why Gridware
- Flexible, remote-friendly environment, work fully remote, or from our A-grade office in Australia Square in the heart of Sydney's CBD
- Great Place to Work certified and Top 10 Best Workplace in Australia 2024 & 2025
- Exposure to high-impact, high-urgency incidents across industries
- A flexible, remote-friendly environment — we're DFIR operators and we understand that work can be busy, but so can life
- Variety of casework: Gridware responds to a high volume of incidents, so no two days are the same
- Strong learning and development culture: a collaborative team of innovators with access to leading tooling, training, and thought leadership
- Mental health days and flexible working arrangements





