✦ Luna Orbit — Cybersecurity

Digital Forensics Incident Response Security Consultant, Mandiant

at Google

📍 Remote, US Remote 💰 $113K – $161K USD / year Posted March 31, 2026
Salary $113K – $161K USD / year
Type Full-Time
Experience mid
Exp. Years 3 years
Education Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field, or equivalent practical experience
Category Cybersecurity

As a Digital Forensics Incident Response Security Consultant, you will deliver IR and forensic services, perform live response, log and traffic analysis, and lead investigations for clients, including threat discovery and containment.

  • Conduct host forensics and live response analyses
  • Perform logs and network traffic analysis
  • Collaborate with clients to investigate and contain incidents
  • Document IOCs, TTPs, and investigation findings
  • Build scripts/tools to enhance incident investigations

Role covers host forensics, live response, log and network traffic analysis, enterprise searches; requires OS internals across Windows/Linux/MacOS, network and cloud forensics, memory forensics; scripting and tooling to enhance IR processes.

The ideal candidate is a mid-to-senior security consultant with 3+ years in incident response and digital forensics, strong OS internals knowledge, and proven ability to communicate findings to executives and legal teams. Willingness to travel up to 30% and work with clients across diverse environments is required.

Bachelor's degree in Computer ScienceInformation SystemsCybersecuritya related technical fieldor equivalent practical experience3 years of experience working in end-to-end enterprise incident response investigations3 years of investigative experience with digital forensics and incident responsewith specialization in two of OS internalsLinux/UNIXMacOSnetwork forensicscloud forensicsor memory forensicsAbility to travel up to 30%
Experience in security competitionsCapture the Flags (CTFs) or testing platformsWorking knowledge of network security architecture and administrationAbility to manage project timelines and deliverablesAbility to communicate investigative findings to leadershiplegal counseland clients
Hack The BoxTryHackMeOverTheWireCTF platforms
Bachelor's degree3 years IR/forensicsOS internals (Linux/UNIXMacOSWindows)network/cloud/memory forensicsincident response investigationsthreat modelingIOCs/TTPStravel up to 30%
incident response investigationsforensic analysisend-to-end enterprise incident response investigationsoperating system internalsLinux/UNIX operating system internalsMacOS operating system internalsWindows operating system internalsnetwork forensicscloud forensicsmemory forensics
strong communicationability to communicate investigative findings to technical staffexecutive leadershiplegal counseland clientsproject timelinesmethodical and collaborativecustomer-facing
Industry SaaS
Job Function Provide enterprise incident response and digital forensics investigations for Google Mandiant security engagements
Role Subtype Incident Responder
Tech Domains Linux, UNIX, MacOS, Windows, Network forensics, Cloud forensics
Digital Forensics Incident Response Security Consultantincident responsedigital forensicsforensic analysishost forensicslive response analysislog analysisnetwork traffic analysisenterprise searchesOS internalsLinuxUNIXMacOSWindowscloud forensicsmemory forensicsTTPsIOCsCTFHack The BoxTryHackMeOTWMandiantGoogle Cloudnetwork forensics

Less than 3 years in incident response/digital forensics, Unwilling to travel up to 30%, Inadequate OS internals or forensics experience

Apply for this Position →

Get matched to jobs like this

Luna finds roles that fit your skills and career goals — no endless scrolling required.

Create a Free Profile