Published Date
3 weeks ago
Work Arrangement
Hybrid • Reston, VA
Open Positions
3 openings
Experience Level
Senior
About the opportunity
Investigate high-severity nation-state intrusions, ransomware campaigns, and cloud compromise incidents at Mandiant.
What you will do
- check_circle Lead forensic investigations of enterprise security compromises, ransomware deployments, and data breaches.
- check_circle Analyze disk images, volatile memory, Windows Event Logs, and cloud audit logs to construct attack timelines.
- check_circle Perform static and dynamic malware triage to extract indicators of compromise (IOCs) and adversary TTPs.
- check_circle Develop automated containment playbooks using Google Cloud Chronicle and SOAR platforms.
What we are looking for
- arrow_circle_right 5+ years experience in digital forensics, incident response (DFIR), and threat hunting.
- arrow_circle_right Certifications: GCFE, GCFA, GCIH, or GNFA.
- arrow_circle_right Mastery of forensic tools (EnCase, FTK, Volatility, X-Ways, Velociraptor, KAPE) and cloud log analysis.
Skills & Tech Stack
Why candidate applications stand out
Verified Technical Credentials
Applications include direct proof-of-work repositories and instructor verification endorsements.
Fast-Track Hiring Visibility
Direct internal referral channels through enterprise partners bypass automated resume discard filters.