Digital Forensics and Incident Response (DFIR) analyst
rgare · Remote, Ireland · Remote
Posted Oct 2, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
You desire impactful work.
You’re RGA ready
RGA is a purpose-driven organization working to solve today’s challenges through innovation and collaboration. A Fortune 200 Company and listed among its World’s Most Admired Companies , we’re the only global reinsurance company to focus primarily on life- and health-related solutions. Join our multinational team of intelligent, motivated, and collaborative people, and help us make financial protection accessible to all.
About the Role
We are seeking a senior incident response ("DFIR") professional to lead complex cyber investigations, strengthen RGA's enterprise resilience, and guide security teams through critical incidents. This role combines hands-on DFIR expertise, strategic advisory capabilities, stakeholder engagement, and security program leadership across global environments.
Who Thrives in This Role?
You are motivated by investigating sophisticated attacks, improving security operations, and turning lessons learned into measurable improvements. You want to leverage the latest tooling's and methods to "find evil". Always want to help improve tooling's with new ideas. You are comfortable with engaging executives, legal teams, technology leaders, and technical responders during high-pressure situations.
Key Responsibilities
Lead enterprise incident response and cyber crisis engagements from detection through recovery.
Direct host, network, cloud, identity, and SaaS investigations across Windows, Linux, macOS, Microsoft 365, AWS, Azure, and hybrid environments.
Perform advanced threat hunting and compromise assessments using SIEM, EDR, forensic, and threat intelligence platforms.
Develop containment, eradication, and remediation strategies aligned to business risk.
Produce executive briefings, technical reports, board-ready updates, and post-incident reviews.
Partner with legal, compliance, privacy, audit, and external stakeholders when required.
Drive adoption of AI-assisted workflows to improve investigation speed, reporting quality, and operational efficiency.
Support the 24/7 on-call rotation.
Required Experience and Expertise
5+ years in incident response, DFIR, security operations, consulting, or related cybersecurity disciplines.
Experience leading major cyber incidents involving ransomware, business email compromise, insider threats, cloud compromise, supply chain attacks, or advanced persistent threats.
Strong digital forensics capability using industry-standard forensic and triage tools.
Experience with Splunk, Microsoft Defender, CrowdStrike Falcon, ServiceNow SIR, and cloud security technologies.
Knowledge of network protocols, detection engineering, log analytics, and threat hunting methodologies.
Excellent verbal and written communication skills for technical and executive audiences.
Demonstrated ability to manage multiple priorities in a global enterprise environment.
Forensic tools (FTK, Encase, X-Ways, Magnet Axiom, SIFT or…