RVC
JobsFor Employers
  1. Jobs
  2. /
  3. Digital Forensics and Incident Response (DFIR) analyst

Digital Forensics and Incident Response (DFIR) analyst

rgare | Reinsurance
2h 24m ago
Remote In-Country
Full Time
IC
Ireland

You desire impactful work.

You’re RGA ready

RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies, we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all.

About the Role

We are seeking a senior incident response ("DFIR") professional to lead complex cyber investigations, strengthen RGA's enterprise resilience, and guide security teams through critical incidents. This role combines hands-on DFIR expertise, strategic advisory capabilities, stakeholder engagement, and security program leadership across global environments.


Who Thrives in This Role?

You are motivated by investigating sophisticated attacks, improving security operations, and turning lessons learned into measurable improvements. You want to leverage the latest tooling's and methods to "find evil". Always want to help improve tooling's with new ideas. You are comfortable with engaging executives, legal teams, technology leaders, and technical responders during high-pressure situations.


Key Responsibilities

  • Lead enterprise incident response and cyber crisis engagements from detection through recovery.
  • Direct host, network, cloud, identity, and SaaS investigations across Windows, Linux, macOS, Microsoft 365, AWS, Azure, and hybrid environments.
  • Perform advanced threat hunting and compromise assessments using SIEM, EDR, forensic, and threat intelligence platforms.
  • Develop containment, eradication, and remediation strategies aligned to business risk.
  • Produce executive briefings, technical reports, board-ready updates, and post-incident reviews.
  • Partner with legal, compliance, privacy, audit, and external stakeholders when required.
  • Drive adoption of AI-assisted workflows to improve investigation speed, reporting quality, and operational efficiency.
  • Support the 24/7 on-call rotation.

Required Experience and Expertise

  • 5+ years in incident response, DFIR, security operations, consulting, or related cybersecurity disciplines.
  • Experience leading major cyber incidents involving ransomware, business email compromise, insider threats, cloud compromise, supply chain attacks, or advanced persistent threats.
  • Strong digital forensics capability using industry-standard forensic and triage tools.
  • Experience with Splunk, Microsoft Defender, CrowdStrike Falcon, ServiceNow SIR, and cloud security technologies.
  • Knowledge of network protocols, detection engineering, log analytics, and threat hunting methodologies.
  • Excellent verbal and written communication skills for technical and executive audiences.
  • Demonstrated ability to manage multiple priorities in a global enterprise environment.
  • Forensic tools (FTK, Encase, X-Ways, Magnet Axiom, SIFT or other) experience is mandatory.

Leadership Expectations

Provide technical leadership during investigations, influence strategic security decisions, contribute to capability development, and serve as a trusted advisor for cybersecurity risk management and response readiness.


Education and Certifications

  • Industry certifications such as GCFA, GCFE, GCIH, GCIA, CISSP, CISM, Azure Security Engineer, AWS Security Specialty, or comparable credentials are highly desirable (not mandatory)
  • Bachelor's degree in Cybersecurity, Computer Science, Information Security, Engineering, Intelligence Studies, or a related discipline, or equivalent experience is desirable (not mandatory)

Work Environment

Remote or hybrid eligible. Participation in an on-call rotation. Travel is not required as part of the standard day-to-day duties. The role supports global operations and may engage with stakeholders across multiple regions and time zones.


#LI-DM1


What you can expect from RGA:

  • Gain valuable knowledge from and experience with diverse, caring colleagues around the world.

  • Enjoy a respectful, welcoming environment that fosters individuality and encourages pioneering thought.

  • Join the bright and creative minds of RGA, and experience vast, endless career potential.

We’re excited to get to know you and connect your unique skills with our global opportunities. To create a modern and seamless experience, we use artificial intelligence (AI) in parts of our preliminary screening process. This technology helps us personalize job recommendations, automate interview scheduling, evaluate candidates based solely on experience—without considering name, gender, or other personal details—and provide real-time answers through our chatbot. AI is used only during early screening and never makes hiring decisions. Your RGA recruiter will work closely with you every step of the way to ensure the process feels personal, thoughtful, and focused on you.

Required Skills

splunkmicrosoft_defendercrowdstrike

Required Languages

🇬🇧 English

Related searches

  • Remote In-Country Jobs
  • Senior Jobs
1 jobs
Sort by
2h 24m ago

Digital Forensics and Incident Response (DFIR) analyst

rgare·Reinsurance
splunkmicrosoft_defendercrowdstrike
📡Remote In-Country
|Ireland
General InfoSec
No similar jobs match these filters. Try changing or clearing a filter.
Popular job searches ▸
Remote roles
PythonJavaReactGoDevOpsNode.jsC# / .NET
Countries
United StatesUnited KingdomCanadaUS & EMEAGermanyPolandSpainNetherlandsPortugal
Experience
SeniorMid-levelJunior
R© 2026 RVC Globalbuild c0e1e960
AboutMCPPricingContactPrivacyCookiesRefundsTerms & ConditionsFor Employers