Principal Consultant, DFIR, Reactive Services (Unit 42) – LATAM
Palo Alto Networks
- Location
- Sao Paulo Brazil
- Work model
- On-Site
- Level
- Principal
- H-1B history
- 168 approvals (FY2023)
- Posted
- 17h ago
Skills
About this role
Our Mission
At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.
Who We Are
In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us! This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.
Job Summary
The Principal Consultant, Reactive Services is a senior individual contributor within Unit 42, responsible for leading and executing complex digital forensics and incident response engagements across a wide range of client environments throughout Latin America. In this role, you will work alongside Consulting Directors and other senior Unit 42 leaders to investigate high-impact cybersecurity incidents, guide technical response activities, and advise clients throughout the incident response lifecycle. You will serve as a technical leader during active investigations, independently manage key workstreams, and help ensure the delivery of high-quality outcomes in fast-paced and high-pressure client environments. This position is ideal for an experienced DFIR practitioner who enjoys leading hands-on technical investigations, solving complex security challenges, mentoring other consultants, and working directly with technical and executive stakeholders during critical cybersecurity incidents.
Key Responsibilities
Lead and execute complex digital forensics and incident response investigations across enterprise environments. Serve as a technical lead during investigations involving ransomware, business email compromise, malware, insider threats, unauthorized access, data theft, and advanced intrusion activity. Conduct advanced forensic analysis of endpoints, systems, logs, networks, and cloud environments to identify attacker activity and determine the scope and impact of compromise. Lead host, network, identity, and cloud investigations during active cybersecurity incidents. Perform and oversee forensic acquisition, preservation, and analysis of evidence in accordance with industry best practices and chain-of-custody procedures. Utilize industry-standard DFIR tools, investigative methodologies, and threat intelligence to identify malicious activity and support containment, eradication, and recovery efforts. Independently manage technical workstreams and coordinate investigative activities across client teams, internal stakeholders, and third-party partners. Translate complex technical findings into clear investigative summaries, timelines, executive briefings, and client-facing reports. Present technical findings and strategic recommendations to technical teams, business leaders, legal counsel, and executive stakeholders. Provide remediation guidance and advise clients throughout the incident response and recovery lifecycle. Mentor junior and mid-level consultants and provide technical guidance during active engagements. Support engagement planning, scoping, quality assurance, and delivery across multiple concurrent investigations. Maintain awareness of emerging threats, attacker techniques, forensic