
Breaking into larger scale DFIR pathways Canada
DFIRSOCcareerincident responsethreat huntingMandiantcybersecurityCanadacertificationsmalware analysis
A Tier 3 SOC analyst working with approximately 80 customers (some with 20k+ employees) is seeking advice on transitioning into full-time DFIR roles at major companies like Mandiant. They currently handle large incidents, incident command, and threat hunting in a Microsoft environment. Their certifications include GCIH, GCFA, AZ-104, and AZ-500, and they are currently working on improving malware reverse engineering skills. They have stayed at their current position despite being underpaid because they prefer not to job hop.