Skip to main content
Detection & response

DFIR & Threat Intelligence

When the alert is real. Forensics, IR, malware analysis, threat intel. SANS/GIAC biased.

Last reviewed May 2026Reviewed by a practitioner working in incident responder / junior dfir analyst hiringUpdated quarterly against live job listings
The verdict

Where SOC analysts go when they want to stop closing tickets and start running cases. Smaller market, higher signal, less burnout.

You've done a year or two in SOC, you actually enjoy the bit where an alert turns into a real intrusion, and you can sit with ambiguity for days at a time.

You're trying to skip past SOC entirely. DFIR teams hire people who've already proven they can hold a queue together and write a sensible timeline.

Phased progression

Foundations → first role → specialisation → advanced. The realistic order, not a script.

Salary figures are POST practitioner estimates, not survey data.

  1. 01Foundations
    0–6 months

    Literacy, lab habits, the cert that opens first conversations.

    GCIH
  2. 02First paid role
    6–18 months

    Land a Incident Responder / Junior DFIR Analyst. Operational time, not more certs, earns the next move.

    Incident Responder / Junior DFIR Analyst
    £55–80k IR
  3. 03Specialisation
    1.5–3 years

    Add a specialist credential aligned to the work you're already doing.

    GCFAGREM
    £80–110k senior DFIR / malware (UK)
  4. 04Advanced
    3+ years

    Move into adjacent roles. Long-term credentials become worth their cost.

    Threat Intel AnalystGNFA
    £80–110k senior DFIR / malware (UK)

Certification sequence

Ordered by realistic relevance, not vendor marketing.

  • GCIH
  • GCFA
  • GCIA
  • GREM
  • CHFI
  • GNFA

Practical projects

What to actually build, the portfolio that opens interviews.

  • Memory + disk forensics on a captured Windows image
  • MITRE ATT&CK mapping for a single intrusion set
  • Build an IR runbook for one realistic scenario (ransomware, BEC, web shell)
Threat Intel AnalystMalware AnalystDetection Engineer
  • ·Detection engineering instead of IR
  • ·Threat intel via journalism / OSINT background

Realistic expectations

What no recruiter will tell you.

Misconception

That GIAC certs alone get you in. They help, but DFIR hiring leans heavily on case writeups, CTF placements, and the ability to articulate what you found and why it matters.

Honest window

Two to four years from a junior SOC seat is the honest read. Anyone promising a direct entry into DFIR from a bootcamp is selling something.

Practitioner judgement. External evidence review pending.

Last reviewed: not yet reviewed · UK market

Where this fits

A pathway is a sequence, not a destination. Here are the roles and certs along it.

The next step

The pathway is plausible. Whether it holds for five years is a different question.

A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.

A route shows what is possible. A Career Verdict makes the call.

POST ATLASVerdict no. PA-2026-0512
Career analysis report

Career Verdict

Helpdesk → Security Architect

“Realistic, but not by adding another certification.”
  1. 01
    The callA clear judgement on whether your route is realistic, and under what conditions.
  2. 02
    Where the route breaksThe most likely point to stall, and why it happens in practice.
  3. 03
    What to do nextSpecific priorities for the next 6–24 months, and what to drop.
Generated within POST’s practitioner-authored assessment frameworkPOST ATLAS

Career Verdict

£39One-off payment. No subscription.
  • The callA single written judgement on whether the route is realistic for you.
  • Plateaus and failure modesThe flat years and the specific ways this route tends to stall.
  • Where you standThe strongest and weakest parts of your current position, named.
  • Salary realityWhat this route actually pays, set against what you've been told it pays.
See the Career Verdict

Usually within minutes of payment. Kept 24 months, then deleted. Deletion on request at any time.

Built on POST's practitioner-authored assessment framework, informed by two decades across helpdesk, infrastructure and security. The verdict applies that framework to your inputs.