Senior DFIR Analyst
What makes the role special
About Us:
Founded in 2003 and headquartered in Singapore, Group-IB is a leading creator of cybersecurity
technologies to investigate, prevent, and fight digital crime. Combating cybercrime is in the company’s DNA, shaping its technological capabilities to defend businesses, and citizens, and support law enforcement operations.
Group-IB’s Digital Crime Resistance Centers (DCRCs) are located in the Middle East, Europe, Central Asia, and Asia-Pacific to help critically analyze and promptly mitigate regional and country-specific threats. These mission-critical units help Group-IB strengthen its contribution to global cybercrime prevention and continually expand its threat-hunting capabilities.
Each of us can help make the world a safer place. Join us!
ABOUT THE ROLE
GROUP-IB is hiring a Senior DFIR Analyst to lead incident response engagements across Latin America, end to end: from initial scoping through the final executive briefing. You will work the intrusions at the region's banks, telecoms, retailers and critical infrastructure, as part of a global practice that hands cases across timezones and sees the actors heading here before they arrive.
The DFIR vision: Our ultimate goal is to fight cybercrime by constantly learning and staying one step ahead of the attackers. We do not just solve isolated puzzles; we bring different security experts together to build a complete and strong defense. By handling a large volume of cases, we gain real, practical experience that makes us better every day. Instead of just handing our clients a confusing list of technical data or "homework," we focus on providing clear, actionable answers that explain exactly what happened and what it means for their business. Furthermore, we are constantly researching and looking ahead to ensure we are fully prepared for the future of automated cyber threats
YOUR MISSION
Own the engagement
- Lead client-facing incident response engagements from scoping through closure, across endpoint, cloud, and network evidence.
- Serve as the primary technical point of contact for the client, and coordinate the analysts working alongside you on the case.
- Make sound decisions with incomplete data, balancing analytical depth against the speed the client needs.
- Work as part of a global practice — hand cases across timezones, draw on specialists in other regions, and contribute your findings and tooling back to the wider team.
Do the forensics
- Conduct host forensics across Windows and Active Directory, Unix/Linux, and macOS environments
- Investigate cloud and identity compromise across AWS, Azure/Entra, and GCP
- Perform log analysis, threat hunting, and malware triage in support of your investigations.
- Recognise and codify attacker tools, tactics and procedures so that what you learn in one case strengthens the next.
Deliver the answer
- Produce written reports and verbal briefings that hold up in front of technical teams, executive leadership, regulators, and legal counsel — in Spanish and in English.
- Support quality assurance by reviewing the technical work and written output of your colleagues.
Push the practice forward
- Build the scripts, tooling and methodology that make the next investigation faster than the last.
- Contribute to research, publication, and public speaking. We want your name on the work, and we will give you the room to do it.
- Bring an informed view on integrating and properly bounding non-deterministic systems such as LLMs in an investigative workflow
WHAT WE ARE LOOKING FOR
- 5+ years in DFIR within a consulting, MSSP, CERT, or in-house incident response function.
- Demonstrated experience leading investigations end to end, with direct client or stakeholder ownership.
- Host forensics depth across Windows and Active Directory and across Unix/Linux, with working familiarity of macOS.
- Cloud incident response experience in at least one major platform (AWS, Azure/Entra, or GCP).
- Fluent Spanish and fluent English. You will write reports and brief executives in both
- Willingness to travel across the region for onsite client work, approximately 25% of the time.
- A degree in Computer Science, Information Security, or a related field is welcome. It is not required. Relevant experience and demonstrable skill count for more.
WHAT SETS YOU APART
- Proficiency in Portuguese is highly preferred.
- Malware analysis, static or dynamic, beyond triage depth.
- Certifications such as GCFA, GCFE, GNFA, GREM, GCIH, or cloud platform certifications.
- A track record of published research, conference talks, or open-source contribution.
- Experience across the LATAM regulatory and legal landscape,
WHY CHOOSE GROUP-IB
Group-IB is a global leader in cybersecurity technologies that investigate, predict, prevent, and fight digital crime. We help organizations reduce risk and protect trust. Trusted by governments, major industries, and law enforcement, we deliver adversary-focused, predictive threat intelligence and cyber fraud fusion solutions that detect, analyse, and mitigate regional and country-specific digital crimes.
- Work with real stakes. Group-IB investigates active cybercriminal groups, responds to breaches affecting critical infrastructure, and develops technologies used by law enforcement agencies including INTERPOL, Europol, and Afripol across 60+ countries. We've conducted 1,550+ cybercrime investigations alongside 600+ enterprise customers globally. When you join Group-IB, your work directly disrupts digital crime.
- Grow your way. Choose your own path: deepen your craft as a technical expert, step into leadership, move across to another team, or relocate to one of our Digital Crime Resistance Centers across the Americas, Europe, the Middle East & Africa, Central Asia, and the Asia-Pacific. Your growth is our growth — Group-IB's expansion across 60+ active country operations means real career acceleration.
- We fund professional certifications at company expense — whether you're pursuing CEH, CISSP, OSCP, or specialized certifications in forensics and penetration testing. You don't have to choose between doing the job and advancing your credentials.
- Work alongside industry leaders. Our Unified Risk Platform — Threat Intelligence, Digital Risk Protection, Attack Surface Management, Managed XDR, and more — is recognized by Gartner, Forrester, KuppingerCole, and Datos Insights. Frost & Sullivan named us a 2025 Global Technology Innovation Leader. When you work here, you're building technologies that set the industry standard.
- Real challenges, real expertise. You'll take on complex, real-world problems alongside adversary-centric researchers and incident response experts spread across six continents. We've built 21+ years of proprietary telemetry through 1,500+ joint investigations. No two threats look alike — and neither do the skills you'll develop.
- A team that is genuinely international. Our people come from different countries, speak different languages, and bring different perspectives. What connects us is a shared mission: fighting cybercrime and making the world safer. We care about your wellbeing and happiness as much as your output.
