Consultant, DFIR, Reactive Services; Unit – Remote
Santa Clara, Santa Clara County, California, 95053, USA
Listed on 2026-01-17
-
IT/Tech
Cybersecurity, Information Security
Company Description Our Mission
At Palo Alto Networks® everything starts and ends with our mission:
Being the cybersecurity partner of choice, protecting our digital way of life.
Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we’re looking for innovators who are as committed to shaping the future of cybersecurity as we are.
Who We AreThis role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.
Job DescriptionJob Summary
As a client-facing Consultant in our reactive services team, you will be a critical first responder for our customers. You will lead and manage incident response engagements from start to finish, working directly with diverse stakeholders, including C-suite executives, to guide them through complex cybersecurity incidents and deliver actionable solutions based on your findings.
Key Responsibilities- Lead reactive incident response engagements, guiding clients through digital forensics investigations and security incident containment.
- Perform host-based forensic analysis across Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs).
- Investigate data breaches using advanced forensics tools (e.g., EnCase, FTK, Splunk) to determine the source and scope of malicious activity.
- Examine firewall, web, database, and other log sources to identify evidence and artifacts of compromise.
- Proactively collaborate with clients and internal teams, providing expert guidance on tactical remediation recommendations to improve their security posture.
- Produce and present high-quality deliverables for client engagements, communicating complex findings to both technical and executive stakeholders.
- Travel as needed (approximately 30%) to support client-facing engagement demands.
- 2+ years of incident response or digital forensics experience with a passion for cybersecurity
- Proficient with host-based forensics and data breach response
- Experienced with EnCase, FTK, X-Ways, SIFT, Splunk, Volatility, Wire Shark, TCPDump, and open-source forensic tools
- Ability to grow into a valuable contributor to practice and, specifically
- have an external presence via public speaking, conferences, and/or publications
- have credibility, executive presence, and gravitas
- be able to have a meaningful and rapid delivery contribution
- have the potential and capacity to understand all aspects of the business and an excellent understanding of PANW products
- be collaborative and build relationships internally, externally, and across all PANW functions, including the sales team
- Incident Response Consulting is highly preferred
- Bachelor’s Degree in Information Security, Digital Forensics, Cyber Security, Computer Science, related field, or equivalent experience required
Unit 42 Consulting is Palo Alto Network’s security advisory team. Our vision is to create a more secure digital world by providing the highest quality incident response, risk management, and digital forensics services to clients of all sizes. Our team is composed of recognized experts and incident responders with deep technical expertise and experience in investigations, data breach response, digital forensics, and information security.
With a highly successful track record of delivering mission-critical cybersecurity solutions, we are experienced in working quickly to provide an effective incident response, attack readiness, and remediation plans with a focus on providing long-term support to improve our clients’ security posture.
The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).