--- title: 'International Contract Bench, Incident Response (DFIR) at MOXFIVE' canonical: 'https://feeny.ai/job/international-contract-bench-incident-response-dfir-moxfive-global-5e7ft6q00nm8' type: 'job' last_seen: '2026-09-12' --- # International Contract Bench, Incident Response (DFIR) at MOXFIVE - **Company:** MOXFIVE - **Location:** Global - **Compensation:** $160k–$203k - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-04-30 - **Last confirmed live:** 2026-09-12 - **Apply:** https://jobs.ashbyhq.com/moxfive/24032577-6576-47cd-bcbb-67dabdb2174e ## Job description ## Who We Are If you feel like Incident Response and Recovery hasn’t changed in the past 10 years, you’re not alone. Business operations aren’t just on endpoints anymore. It’s behind applications in Okta tiles, auto-scaling workloads, code repos, and sprawling data stores across one or many public clouds. At MOXFIVE, we’re focused on eradicating adversaries across our client’s entire digital footprint, and that demands a faster, nimbler approach to DFIR. We know high quality incident response starts and ends with great people. MOXFIVE is looking for the weekend warriors, the late-night crusaders, or any variation in between to do investigative work at a pace that matches your lifestyle. ## Who You Are You’re a “retired” incident responder that’s called it quits because of missed one too many holidays and an exhausting on-call schedule. If you’re honest though, you miss the investigation. Finding actual evil and seeing the latest threat activity is more exciting than your day job, and you’d love to get your fix on some live response data without committing all your waking hours. You know that $I30 isn’t referring to your local interstate, and that the easiest way to get on your bad side is to be handed a timestamp that isn’t in UTC. You’ve got a “Tools” folder sitting on your workstation somewhere with your favorite forensic scripts at the ready to tear into the next piece of suspicious activity you see. And speaking of suspicious activity, you’ve honed a keen sense for knowing the difference between legitimate users and threat actor activity because you’ve seen them in action. Hundreds of times. Windows environment investigations feel like the back of your hand at this point, and you’ve been starting to expand your knowledge on cloud-native forensics. Account takeovers are the new malware after all, and investigating the latest threats across Azure, GCP, AWS, and SaaS Apps is the growing frontier you’ve been looking to sink your teeth into. You’re insatiably curious, addicted to threat intel, and an investigator at heart. Ultimately, you’d love an opportunity that allows you to get deeply technical and solve real cases at an intensity that’s compatible with your day job and every day life. ## Why You Matter You’ll be joining a seasoned team of high performing incident response consultants as part of our contract bench that are the tip of the spear for all forensic activity at MOXFIVE. With that, you’ll be eligible for picking up live response work and analysis to support breaches ranging from ransomware to nation-state threats at a schedule that makes sense for you. Your analysis expands our capacity to support clients at the highest level of quality. ## What You'll Bring - Experience responding to threat activity as an IR consultant or SOC analyst - Strong understanding of Windows/Mac/Linux fundamentals, forensic artifacts, BEC analysis, and network analysis - Existing knowledge or passion to learn cloud-native investigations across AWS, GCP, and Azure - An unwavering emphasis on investigation at the highest level of quality - Perspective and voice to continue to shape our practice - At least a few free hours a week on your schedule to take on IR work. We’re day-job friendly (as long as your employer is cool with it). Disclaimer: All official MOXFIVE communications will only come from an @[moxfive.com](http://moxfive.com) email address. ## About MOXFIVE ## Company Overview - **One-liner**: MOXFIVE provides technical advisory services and a proprietary platform to help organizations respond to cyberattacks, minimize business impact, and build operational resilience. - **Entity Type**: Private (growth-stage; secured a growth investment from Falfurrias in 2024) - **Headquarters**: McLean, Virginia, United States (Tysons Corner area) - **Founded**: 2019 - **Founders**: Mike Wager (CEO) ## Core Business - **Primary industry**: Cybersecurity – incident response, digital forensics, and business resilience consulting. - **Target customers**: B2B – organizations of all sizes (SMB to enterprise) that need rapid, expert-led response to ransomware, nation-state threats, and other cyber incidents. - **Mission or purpose**: “Minimize the business impact of cyber attacks.” ## Products & Services - **MOXFIVE Platform**: Proprietary platform that centralizes incident response milestones, project details, and costs across workstreams, providing full transparency during an attack. - **Incident Response (IR) Services**: Technical Advisors lead forensics, containment, and recovery – including ransomware negotiation and restoration – using proven playbooks and an ecosystem of specialized providers. - **Business Resilience & Advisory**: Proactive gap analysis, resilience roadmap building, and implementation services to harden environments against future attacks. - **Agentic Forensics Platform**: Launched in 2025 – a next-generation digital incident response tool leveraging agentic AI to accelerate forensic investigations. ## Market Standing - **Valuation/Market Cap**: Not disclosed. - **Key Metric**: Total funding – the company raised a growth investment from Falfurrias (majority recapitalization announced August 2024); terms not disclosed. Also acquired modePUSH in 2025 to strengthen forensics capabilities. - **Notable Investors/Partners**: Falfurrias Capital Partners (growth investor); strategic partnerships with technology and service providers (ecosystem of experts). Joined the Agentic AI Foundation in 2026. - **Growth Signals**: - Named to Inc. 5000 list of fastest-growing private companies (2023, 2024). - Recognized as Inc. Best Workplaces honoree (2023, 2024, 2025). - Named Cyber Security Consulting Services Team of the Year by Intelligent Insurer (2024, 2025). - Employee headcount grew ~47.6% year over year (48 employees on LinkedIn, 56 on Built In – indicative of rapid scaling). - Managed over 3,500 incident response events; saved victims more than $300 million in 2024 alone. - Average 40%+ reduction in days to recover using their playbooks and platform. ## Competitive Advantages - **Platform + Talent Model**: Combines a proprietary orchestration platform with experienced Technical Advisors who have deep IT and security operational backgrounds, enabling faster, more consistent outcomes than traditional consulting firms. - **Scalable Ecosystem**: Leverages pre-vetted third-party experts and technology partners so the right skills are deployed rapidly without overstaffing. - **Business-First Lens**: Technical decisions are framed by business impact, making them a trusted advisor to both IT teams and C-suite executives. ## Strategic Focus - **Expanding Forensics & AI Capabilities**: The acquisition of modePUSH and launch of the Agentic Forensics Platform signal a push to automate and accelerate digital forensics. - **International Growth**: Presence already in UK, UAE, and India; likely expanding geographic coverage. - **Scaling the Team**: Continuous hiring for technical roles (DFIR Consultants, Restoration Engineers, Technical Advisors, Project Managers) to handle increasing incident volumes. ## Why Work Here - **Culture & Values**: Built on five core values – Accountability, Excellence, Collaboration, Integrity, and Resilience. Described as collaborative, team-oriented, and mission-driven. - **Work Model**: Remote-first organization (headquarters in Tysons Corner, VA but most roles are remote). Some positions may require flexible schedules (e.g., Wed–Sun for DFIR consultants). - **Perks & Benefits**: Competitive compensation + bonus, immediate 401k with company match, unlimited PTO, paid parental leave, health/dental/vision insurance, professional development reimbursement for training and certifications. - **Engineering & IR Culture**: High-impact work – “you’re the first person people call in an emergency.” Voice in shaping technology stack and methodology as the company scales. - **Recognition**: Three-time Inc. Best Workplaces honoree and ranked #1 security company on the Inc. 5000 in 2023. ## Sources 1. [MOXFIVE Official Website](https://www.moxfive.com/) 2. [About Us - MOXFIVE](https://www.moxfive.com/about-us) 3. [Careers - MOXFIVE](https://www.moxfive.com/career) 4. [Built In Profile](https://builtin.com/company/moxfive) 5. [LinkedIn Company Page](https://www.linkedin.com/company/moxfive) 6. [PRWeb - MOXFIVE Acquires modePUSH](https://www.prweb.com/releases/moxfive-acquires-modepush-to-strengthen-forensics-expertise-and-deliver-a-next-generation-incident-response-experience-302407115.html) (via LinkedIn) 7. [FinTech Global - Falfurrias Investment](https://fintech.global/2024/08/28/moxfive-secures-growth-investment-from-falfurrias-to-enhance-cyber-defenses/) (via LinkedIn) ## Other roles at MOXFIVE - [Principal DFIR Consultant](https://feeny.ai/job/principal-dfir-consultant-moxfive-remote-421pq11q0j06) - [Technical Advisor](https://feeny.ai/job/technical-advisor-moxfive-remote-x1jz7dcmyjxg) - [Senior Consultant, DFIR (Wed-Sun)](https://feeny.ai/job/senior-consultant-dfir-wed-sun-moxfive-remote-52rtvmqpy13g) - [Managing Director, Resilience Advisory](https://feeny.ai/job/managing-director-resilience-advisory-moxfive-remote-y6rsjbyrsjse) - [Technical Sales Executive](https://feeny.ai/job/technical-sales-executive-moxfive-remote-pj8shkshxmka) - [Director of Customer Success](https://feeny.ai/job/director-of-customer-success-moxfive-remote-9m19mya8sea0) - [Senior Platform Engineer](https://feeny.ai/job/senior-platform-engineer-moxfive-remote-vzxnmr574ted) - [Senior Restoration Engineer](https://feeny.ai/job/senior-restoration-engineer-moxfive-remote-ap0g3vm0ndd4) - [Project Manager (Incident Response)](https://feeny.ai/job/project-manager-incident-response-moxfive-remote-yznssq028nw4) - [Contract Bench, Incident Responder (DFIR)](https://feeny.ai/job/contract-bench-incident-responder-dfir-moxfive-remote-d2dfbfayknny)