×
Register Here to Apply for Jobs or Post Jobs. X

Senior DFIR Specialist

Job in Ottawa, Ontario, Canada
Listing for: Malleum
Full Time position
Listed on 2026-08-05
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
About Malleum Malleum is at the forefront of next-generation cyber defense, partnering with marquee clients across space, aerospace, defense, government, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience.

We investigate sophisticated intrusions, contain active threats, and help clients recover from attacks targeting the systems, data, and missions that matter most - from ransomware affecting essential operations to adversary activity in sovereign, regulated, and allied environments. Our work sits at the intersection of deep forensic tradecraft, fast-moving operational decision-making, and the national security realities that shape modern cyber defense.

As we continue to scale, we are building a dedicated DFIR capability. The Senior DFIR Specialist will play a defining part in shaping that practice - establishing how we respond, investigate, and deliver for clients in their most critical moments.

If you take pride in tracing adversary tradecraft, establishing the truth under pressure, and building something that endures, Malleum is where your craft meets purpose.

The Opportunity Working remotely and at client sites, in this role you'll deliver and lead hands-on digital forensics and incident response engagements for our clients, operating within enterprise and highly regulated environments, investigating active incidents, preserving and analyzing evidence, and supporting clients through containment, eradication, and recovery.

This is a critical hire and a foundational role within our nascent DFIR practice. In addition to leading investigations, you will help define how we execute incident response engagements - shaping methodologies, refining tooling, and establishing the standards that will scale as the practice grows.

This is a hands-on consulting role for a practitioner who combines strong investigative tradecraft with a builder mindset, and who can step in when incidents demand long hours, rapid mobilization, and sustained focus alongside experienced responders.

What You’ll Do
  • Lead and deliver digital forensics and incident response engagements across endpoint, network, cloud, and hybrid environments
  • Direct complex investigations involving ransomware, intrusion, insider threat, and data compromise, identifying initial access, persistence, lateral movement, and exfiltration
  • Collect, preserve, and analyze forensic artifacts including disk, memory, logs, authentication records, and network telemetry across enterprise and cloud environments
  • Establish scope, timeline, and impact through structured, defensible investigative methodology, producing clear attack narratives and findings
  • Advise clients in real time during active incidents on containment, eradication, recovery, and risk mitigation, supporting decision-making under pressure
  • Produce high-quality deliverables including forensic reports, executive summaries, technical findings, and remediation recommendations, and deliver briefings to both technical and executive stakeholders
  • Operate effectively within regulated, security-sensitive, and mission-critical environments, including rapid mobilization and sustained engagement during active incidents Contribute to the development and refinement of DFIR methodologies, playbooks, tooling, and investigative standards
  • Help define and scale Malleum’s DFIR delivery model, establishing repeatable processes and consistent quality across engagements
  • Collaborate with adjacent practices across offensive security, infrastructure, and program delivery during complex engagements
  • Support scoping, estimation, and statement of work development for DFIR engagements Mentor junior practitioners and contribute to the growth of team capability and overall DFIR tradecraft
What You Bring
  • 8+ years of experience in digital forensics, incident response, or closely related cybersecurity domains, including experience leading complex and high-impact investigations
  • Proven experience operating in client-facing environments, including…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary