Principal Consultant, Cloud DFIR (Unit 42) - Remote
$151k - $208kPalo Alto Networks
Our Mission
At Palo Alto Networks®, we’re united by a shared mission—to protect our digital way of life. We thrive at the intersection of innovation and impact, solving real-world problems with cutting-edge technology and bold thinking. Here, everyone has a voice, and every idea counts. If you’re ready to do the most meaningful work of your career alongside people who are just as passionate as you are, you’re in the right place.
Who We Are
In order to be the cybersecurity partner of choice, we must trailblaze the path and shape the future of our industry. This is something our employees work at each day and is defined by our values: Disruption, Collaboration, Execution, Integrity, and Inclusion. We weave AI into the fabric of everything we do and use it to augment the impact every individual can have. If you are passionate about solving real-world problems and ideating beside the best and the brightest, we invite you to join us!
This role is remote, but distance is no barrier to impact. Our hybrid teams collaborate across geographies to solve big problems, stay close to our customers, and grow together. You will be part of a culture that values trust, accountability, and shared success where your work truly matters.
Job Summary
Job Summary
The Principal Consultant, Cloud DFIR, Reactive Services is a senior individual contributor within Unit 42 responsible for leading cloud-focused incident response and digital forensics investigations across AWS, Azure, GCP, and hybrid enterprise environments.
In this role, you will serve as a technical lead on active incidents, partnering with Consulting Directors and clients to investigate security breaches, determine scope and impact, contain threats, and guide recovery efforts. You will perform advanced cloud forensic analysis, identify attacker activity, and provide actionable remediation recommendations during high-severity cybersecurity events.
Key Responsibilities
Lead cloud-focused incident response and digital forensics engagements.
Investigate attacks involving cloud infrastructure, identity compromise, ransomware, data theft, and unauthorized access.
Analyze cloud telemetry, including audit logs, IAM activity, network traffic, storage access, containers, and endpoint data.
Conduct forensic acquisition and analysis across cloud, hybrid, and enterprise environments.
Serve as a technical lead during active investigations, guiding strategy and client communications.
Deliver clear findings, executive-ready reporting, and remediation guidance.
Support development of cloud investigation methodologies, playbooks, and tooling.
Mentor team members and contribute to knowledge sharing across Unit 42.
Qualifications
Required Qualifications
6–8+ years of experience in DFIR, incident response, cloud security, or related cybersecurity disciplines.
3+ years of hands-on experience securing, operating, or investigating AWS, Azure, or GCP environments.
Experience leading investigations involving cloud breaches, ransomware, advanced intrusions, or data compromise incidents.
Strong understanding of cloud architecture, IAM, networking, logging, and security controls.
Experience analyzing cloud-native telemetry such as AWS CloudTrail, Azure Activity Logs, Microsoft Entra ID, or Google Cloud Audit Logs.
Hands-on experience with industry-standard DFIR and investigative tools.
Experience investigating Windows, Linux, macOS, cloud workloads, and hybrid environments.
Strong client-facing communication and consulting skills.
Preferred Qualifications
Experience responding to enterprise-scale cloud security incidents.
Knowledge of cloud security platforms such as AWS Security Hub, GuardDuty, Microsoft Defender, Sentinel, or Google Security Command Center.
Experience investigating containerized or Kubernetes environments.
Knowledge of MITRE ATT&CK and modern cloud threat actor tradecraft.
Consulting, MDR, or professional services experience.
Certifications such as GCFA, GCIH, CISSP, AWS Security Specialty, Azure Security Engineer, or equivalent.
Ability to travel up to 20% as required for client engagements.
Compensation Disclosure
The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/com-missioned roles) is expected to be the annual range listed below. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found here ( .
$151,000.00 - $208,000.00/yr
Our Commitment
We’re trailblazers that dream big, take risks, and challenge cybersecurity’s status quo. It’s simple: we can’t accomplish our mission without diverse teams innovating, together.
We are committed to providing reasonable accommodations for all qualified individuals with a disability. If you require assistance or accommodation due to a disability or special need, please contact us at View email address on click.appcast.io .
Palo Alto Networks is an equal opportunity employer. We celebrate diversity in our workplace, and all qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or other legally protected characteristics.
All your information will be kept confidential according to EEO guidelines.
Is role eligible for Immigration Sponsorship? No. Please note that we will not sponsor applicants for work visas for this position.
$102k - $139.5k
...Networks®, we're united by a shared... ...This role is remote, but distance is... ...Summary The Consultant, Reactive Services... ...role within Unit 42, responsible... ...Senior Consultants, Principal Consultants,... ...build advanced DFIR capabilities in... ..., logs, and cloud environments to...Remote workCloudUnitVisa sponsorshipWork visa$128k - $176k
...cybersecurity. Who We Are This role is remote, but distance is no barrier to impact. Our... ...Job Summary This client-facing Senior Consultant role leads and produces deliverables for... ...publications. Additional Information The Team Unit 42 Consulting is Palo Alto Network's...Remote jobUnitShift workWeekend work$163k - $224.5k
...Palo Alto Networks®, we're united by a shared mission-to protect... ...to join us! This role is remote, but distance is no barrier... ...Summary Job Summary As a Principal Consultant for SOC Transformation &... ...mastery across SIEM, SOAR, EDR, cloud security, and threat...Remote workPrincipalCloudUnitVisa sponsorshipWork visa- ...Connectivity, and Intelligent Cloud solutions. The company's... ...Responsibilities The Principal Consultant role is a balanced subject matter... ...IT and independent Business Units Influence and drive... ...paid company holidays, hybrid/remote work, paid bonding leave for...Remote workPrincipalCloudUnitFor contractorsWork experience placementLocal areaFlexible hours
- Principal Consultant - MS (St. Louis) Location: St. Louis, MO Company Overview... ..., and Intelligent Cloud solutions. The company's proprietary... ...IT and independent Business Units Influence and drive business... ...company holidays, hybrid/remote work, paid bonding leave for...Remote workPrincipalCloudUnitFor contractorsWork experience placementLocal areaFlexible hours
$172.5k - $250.2k
...What you'll do The Principal Solution Consultant, Federal serves as a trusted... ...government business processes, cloud technologies, and Docusign'... ...Job Designation Remote: Employee is not required... ...to receive Restricted Stock Units (RSUs). Global benefits...Remote workPrincipalCloudUnitPermanent employmentFull timeContract workWork at officeLocal area- ...transparency Job Title: Principal, Restoration and Remediation Location: Remote (USA) Role: Full... ...Impact As a Principal Consultant on the Restoration and... ...(on-prem, cloud, and SaaS), including user... ...recovery workstreams across DFIR, IT, legal, and insurance...Remote workPrincipalCloudFull timeInternshipLocal areaFlexible hours
- ...Maintenance Customer Order (MCO) focused Sr/Principal Consultant for a multi-division distribution... ...extensive experience in the Company’s M3 cloud solutions, specifically within the... ...rollout of global model, new business unit walkthrough’s, gap analysis, cutover planning...PrincipalCloudUnit
- ...Environment Great Benefits MES Consultant in Life Sciences - Intermediate to Principal As a full-time MES consultant,... ..., software validation and unit testing. In addition, this role requires... ...job advancement. Location: Remote within the United States, Puerto...Remote workPrincipalUnitFull time
- ...Principal Consultant - Data Architecture Poland About Us Do you want to boost your career and collaborate with expert, talented colleagues... ...data, integration and analytics architectures across cloud and hybrid environments Translate business objectives into...Remote workPrincipalCloud
- Principal Consultant, Digital Forensic and Incident Response (DFIR) (Remote) Remote About Surefire Cyber Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to cyber incidents such as ransomware, email compromise, malware...Remote jobPrincipalFull timeLocal areaFlexible hoursWeekend work
$162.7k - $263.18k
...Principal Threat Intelligence Researcher At Palo Alto Networks®, we're united by a shared mission—to protect our digital way of life. We... ...you to join us! This role is remote, but distance is no barrier to... ...Intelligence Researcher on the Unit 42 CTI Services Delivery Team,...Remote workPrincipalUnitShift work- ...Workday Integration Principal Consultant Cognizant Workday Practice continues to grow its Global Delivery Center in Manila. Join our dedicated... ..., Document Transformation, Workday Studio, and Workday Cloud Connect for Third Party Payroll (CCTPP) certification preferred...Remote workPrincipalCloud
$90k - $150k
...Description Job Description Job Title: Principal Consultant – Commercial Data & Marketing Technology Primary Location: Remote, must reside in the US and will have... ...Required Technical Environment / Stack Data & Cloud Platforms Databricks Delta Lake Unity...Remote workPrincipalCloudVisa sponsorship$126k - $198k
...leading analytics software firm is seeking a Principal Consultant in Fraud to join their Professional Services team. This remote role involves implementing their Fraud technology... ..., and proficiency in Java, Kubernetes, and cloud services. The position offers a competitive...Remote jobPrincipalCloud- ...Oracle Cloud SCM Consultant Apply deep knowledge of Oracle Cloud SCM Applications especially in OM, PO, INVENTORY, COSTING, MFG modules and... ...Job Category Client Services Locations Hyderabad, Telangana, India (Remote) Minimum Salary NA Maximum Salary NA...Remote workPrincipalCloud
- ...Principal Consultant- Azure, IAM & Endpoint Solutions The Principal Consultant will lead the architecture, deployment, and optimization of... ...Implement and tune Microsoft Defender for Endpoint, Identity, Cloud Apps, and Office 365. Configure EDR, threat analytics,...Remote workPrincipalCloudWork at office
- ...Job Description This job is remote, but you may be required to come... ...has an opening for a Network Consultant rec 11195-1 This position is... ...Collaborate and liaise with other units and serve as a technical... ...environment within a VMware or other cloud-based enterprise environment....Remote workCloudUnit
$120k - $160k
...Description At a glance: The principal consultant provides expertise utilizing... ...technical designs in a remote or in-person capacity as requested... ...across ten countries; United States, Canada, Mexico, Chile... ...Oracle NetSuite, Stripe, Google Cloud Platform, Zone Billing,...Remote workPrincipalCloudCasual workLocal areaFlexible hoursNight shift- ...Tekfortune is a fast-growing consulting firm specialized in permanent,... ...landscape, virtual recruiting and remote work are critical for the... ...Integrations, including EIB, Studio and Cloud Connect integrations - This... ...gather requirements, coding, unit testing, rollout and...Remote workCloudUnitPermanent employmentContract work
$120 per hour
...Trident Consulting is seeking a "Kinaxis Senior Solution Consultant "... ...Consultant Location: Remote - Travel to client if required... ...including estimation, build, unit testing, and demo sessions... ...across IT, data & analytics, cloud, cybersecurity, finance & accounting...Remote workCloudUnitContract work- ...successful delivery of complex cybersecurity consulting engagements leveraging Palo Alto Networks... ...and enterprise security design Cloud security Security operations and SOC modernization... ...Threat detection and response Remote access and Zero Trust architectures Network...Remote workPrincipalCloud
$100k - $150k
....S., Canada, and India. The Principal Consultant is a senior-level consulting... ...the time · Ability to work remote with a stable internet connection... ...the industry with secure, cloud-based mobile products that... ...about. · Bias to Action: We're united by an innate drive to take...Remote workPrincipalCloudContract workWork at office- MES Consultant in Life Sciences - Intermediate to Principal As a full‑time MES consultant, you will provide consulting services... ..., software validation and unit testing. In addition, you will work... ...of time depending on project). Remote work available from the United States...Remote workPrincipalUnitFull time
- ...Principal Consultant (DevOps) Atlanta, GA Xebia is a pioneering software engineering and IT consultancy company, transforming and executing... ...a particular field, such as Agile, DevOps, Data and AI, Cloud, Software Technology, Low Code, and Microsoft Solutions....Remote workPrincipalCloudTemporary workFlexible hours
- Network Advisory, Principal Consultant Wanted: Dynamic and creative individuals ready to connect with... ...‑defined networking, network security, cloud networking models, and enterprise... ...Skillsets Travel is less than 25% This is a remote position based in the US 10 years...Remote workPrincipalCloudWork experience placement
$163.9k - $235.55k
...your work matters-and so do you. The Principal, Cybersecurity Awareness & Communications... ...technology communications within a SaaS or cloud-based environment. - Experience... ...bonus plan and to receive restricted stock unit awards as part of total compensation. Learn...PrincipalCloudUnit$162.7k - $263.18k
...Alto Networks®, we’re united by a shared mission—to... ...join us! This role is remote, but distance is no barrier... ...Summary The Team Unit 42 is the global threat... ...it. We are seeking a Principal Cyber Threat Intelligence... ...intelligence drives our research, consultant engagements, and...Remote workPrincipalUnitVisa sponsorshipWork visa- ...Principal Enterprise Architect – Mergers & Acquisitions IQVIA's AI & Technology Solutions... ...Privacy, Legal/IP, Finance, and Business Units to support IQVIA's strong M&A strategy—covering... ...Strong working knowledge of: Cloud platforms (AWS, Azure, GCP) Hybrid and...Remote workPrincipalCloudUnitWork at office
$136.28k - $172.74k
...,281.39 - $172,744.42 Annually Location... ...Bargaining Unit C19 : PROTEC... ...Systems Analyst - Principal (BSA) to join our team... ...serves as the lead consultant for enhancing and sustaining... ...Oracle Procurement Cloud and Supplier Cloud,... .... The ratio of remote to onsite work will...Remote workPrincipalCloudUnitBi-weekly payFull timeTemporary workPart timeWork at officeImmediate startFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Consultant, Cloud DFIR (Unit 42) - Remote. Be the first to apply!
- consultant senior consultant United States
- work from home nurse consultant United States
- java consultant United States
- aws consultant United States
- revenue cycle consultant United States
- network consultant United States
- jira consultant United States
- consultant on call United States
- care consultant United States
- workplace consultant United States



