DFIR Consultant Speculative
Cape Town - South Africa
Job Summary
Note: This is a real job with one of South Africas foremost DFIR experts. Because they are exploring candidates in a speculative approach we are keeping it broad. If you have any questions please do just let me know.
A specialist cyber security consultancy is looking to engage with experienced DFIR professionals who have a strong blend of digital forensics incident response and investigative capabilities.
This opportunity is ideal for individuals who thrive in fast-paced environments enjoy solving technically complex problems and can operate across both proactive and reactive security engagements.
The organisation works across a range of sectors supporting investigations incident response activities and security operations for enterprise environments.
- Conduct digital forensic investigations across enterprise environments
- Support incident response activities including triage containment eradication and recovery
- Acquire preserve and analyse digital evidence from endpoints servers cloud and mobile environments
- Produce technical reporting and communicate findings to both technical and non-technical stakeholders
- Assist with the development and improvement of forensic methodologies tooling and response procedures
- Work closely with internal teams and external stakeholders during active investigations
- Support threat-led investigations and contribute to post-incident remediation efforts
- Stay current with emerging threats attack techniques and DFIR tooling
- Commercial experience within Digital Forensics and Incident Response
- Strong understanding of forensic principles evidence handling and investigative workflows
- Experience with industry-standard forensic and incident response tooling
- Familiarity with Windows Linux cloud and enterprise environments
- Scripting or automation capability with Python PowerShell or Bash
- Strong written and verbal communication skills
- Ability to operate independently and within collaborative response teams
- Exposure to consulting MSSP or incident response environments
- Experience supporting complex investigations or high-severity incidents
- Knowledge of cloud security and SaaS ecosystems
- Relevant industry certifications are advantageous (GCFA GCIH CISSP CFCE EnCE etc.)
- Remote with travel
- Exposure to complex and high-impact investigations
- Ongoing training and professional development opportunities
- Market-related compensation dependent on experience