Incident Response & Digital Forensics
When something actually goes wrong, this is the branch that gets called in — containing the breach in real time, then digging through disks, memory, malware, and cloud logs afterward to build a case that holds up to scrutiny (or in court).
Mobile Device Forensics AnalystRansomware Negotiation / Response SpecialisteDiscovery / Litigation Support Forensics
Incident Responder
Gets called in when something is actually breached, to contain it and clean it up.
What it's about & how to get in
When something actually gets breached, you're one of the people brought in to figure out what happened, contain it, kick the attacker out, and get systems back online, under real time pressure, sometimes on a 2am call.
It's a step up from SOC analyst work: you need to be comfortable digging through logs and memory dumps under pressure, coordinating with legal and leadership during an active incident, and writing the post-incident report that explains what failed and how it's getting fixed. Most incident responders spend a couple of years as a SOC or forensics analyst first.
Where you can work
- Dedicated incident response teams inside large enterprises
- IR retainer firms (Mandiant, CrowdStrike Services, Unit 42, and similar) called in when a client is breached
- Cyber insurance companies that keep IR firms on retainer for policyholders
- Government cyber emergency response teams (like CISA's)
- MSSPs and MDR providers with a dedicated IR escalation tier
What it pays
Certifications that open doors
Where you can actually learn it
Digital Forensics Analyst
Recovers and analyzes digital evidence in a way that holds up in court.
What it's about & how to get in
After an incident (or a crime involving digital evidence), you're the one who recovers and analyzes the actual evidence, deleted files, disk images, memory dumps, phone data, in a way that holds up if it ends up in court. That means strict chain-of-custody procedures on top of the technical skill of pulling data back out of a system someone tried to wipe or hide it from.
Some forensics analysts work purely on the corporate incident-response side; others work with law enforcement on criminal cases, which usually requires different training and sometimes government clearance.
Where you can work
- Corporate incident response and legal/e-discovery teams
- Law enforcement digital forensics units (local, state, and federal)
- Digital forensics and e-discovery consulting firms
- Cyber insurance and legal firms handling breach litigation
- Government and military cyber units
What it pays
Certifications that open doors
Where you can actually learn it
Malware Analyst
Takes malicious files apart to figure out exactly what they do and how to stop them.
What it's about & how to get in
A Malware Analyst performs static and dynamic analysis on suspicious files/binaries — disassembling code, running samples in sandboxes, and extracting indicators of compromise (IOCs) and behavioral signatures. Deliverables (IOCs, YARA rules, behavior reports) feed directly into detection and response.
Incident Responders and Digital Forensics Analysts already on this site often pull in a Malware Analyst when a compromise involves an unfamiliar binary they need reverse-engineered rather than just triaged. The Malware Analyst role is more specialized and code-focused than either — closer to reverse engineering than to case management.
Where you can work
- Antivirus/EDR vendors (threat research teams)
- Threat intelligence firms and MDR providers
- Incident response consultancies handling ransomware/APT cases
- Government and defense cyber units
- Large enterprise SOC/IR teams with dedicated malware triage
What it pays
Certifications that open doors
Where you can actually learn it
Cybercrime Investigator / DFIR Consultant
Turns digital evidence into a case that holds up — for law enforcement, courts, or clients.
What it's about & how to get in
A Cybercrime Investigator (or DFIR Consultant in the private sector) manages the full case lifecycle: evidence preservation, chain of custody, cross-jurisdictional coordination, and reporting for legal or client-facing outcomes. It's the role that turns forensic findings into an admissible, defensible narrative.
This differs from the Digital Forensics Analyst role already on the site in emphasis: the Digital Forensics Analyst focuses on technical evidence extraction, while the Investigator/Consultant owns the legal, procedural, and client-communication side — often coordinating directly with the Incident Responder during active cases and with law enforcement or outside counsel afterward.
Where you can work
- Law enforcement cybercrime units and federal agencies
- DFIR consultancies and Big 4 / boutique incident-response firms (client-facing)
- Corporate legal/compliance-aligned investigations teams
- Insurance carriers handling cyber claims (as consultants)
- eDiscovery and litigation-support firms
What it pays
Certifications that open doors
Where you can actually learn it
Cloud / Network Forensics Analyst
Reconstructs what happened across packets, cloud logs, and multi-tenant infrastructure that never touches a hard drive.
What it's about & how to get in
A Cloud/Network Forensics Analyst reconstructs attacker activity from network traffic (PCAPs, NetFlow) and cloud-provider logs (AWS CloudTrail, Azure Activity/Sign-in logs, GCP audit logs) — evidence sources that traditional disk forensics can't reach. This has become essential as more infrastructure and attacker activity moves off endpoints entirely.
It's a specialization that splits off from the Digital Forensics Analyst role already on the site, which traditionally centered on disk/endpoint evidence; this role instead focuses on ephemeral cloud and in-transit network evidence, and it works closely with Incident Responders during active cloud-based intrusions.
Where you can work
- Cloud-native and SaaS companies (AWS/Azure/GCP-heavy environments)
- DFIR consultancies handling cloud breach investigations
- MDR providers monitoring cloud workloads
- Enterprises running hybrid on-prem/cloud infrastructure
- Managed cloud security providers