DFIR & Threat Intelligence
When the alert is real. Forensics, IR, malware analysis, threat intel. SANS/GIAC biased.
Where SOC analysts go when they want to stop closing tickets and start running cases. Smaller market, higher signal, less burnout.
You've done a year or two in SOC, you actually enjoy the bit where an alert turns into a real intrusion, and you can sit with ambiguity for days at a time.
You're trying to skip past SOC entirely. DFIR teams hire people who've already proven they can hold a queue together and write a sensible timeline.
Phased progression
Foundations → first role → specialisation → advanced. The realistic order, not a script.
- 010–6 monthsFoundations
Literacy, lab habits, the cert that opens first conversations.
GCIH - 026–18 monthsFirst paid role
Land a Incident Responder / Junior DFIR Analyst. Operational time, not more certs, earns the next move.
Incident Responder / Junior DFIR Analyst£55–80k IR - 031.5–3 yearsSpecialisation
Add a specialist credential aligned to the work you're already doing.
GCFAGREM£80–110k senior DFIR / malware (UK) - 043+ yearsAdvanced
Move into adjacent roles. Long-term credentials become worth their cost.
Threat Intel AnalystGNFA£80–110k senior DFIR / malware (UK)
- 01Foundations0–6 months
Literacy, lab habits, the cert that opens first conversations.
GCIH - 02First paid role6–18 months
Land a Incident Responder / Junior DFIR Analyst. Operational time, not more certs, earns the next move.
Incident Responder / Junior DFIR Analyst£55–80k IR - 03Specialisation1.5–3 years
Add a specialist credential aligned to the work you're already doing.
GCFAGREM£80–110k senior DFIR / malware (UK) - 04Advanced3+ years
Move into adjacent roles. Long-term credentials become worth their cost.
Threat Intel AnalystGNFA£80–110k senior DFIR / malware (UK)
Certification sequence
Ordered by realistic relevance, not vendor marketing.
- GCIH
- GCFA
- GCIA
- GREM
- CHFI
- GNFA
Practical projects
What to actually build, the portfolio that opens interviews.
- Memory + disk forensics on a captured Windows image
- MITRE ATT&CK mapping for a single intrusion set
- Build an IR runbook for one realistic scenario (ransomware, BEC, web shell)
- ·Detection engineering instead of IR
- ·Threat intel via journalism / OSINT background
Realistic expectations
What no recruiter will tell you.
That GIAC certs alone get you in. They help, but DFIR hiring leans heavily on case writeups, CTF placements, and the ability to articulate what you found and why it matters.
Two to four years from a junior SOC seat is the honest read. Anyone promising a direct entry into DFIR from a bootcamp is selling something.
Where this fits
A pathway is a sequence, not a destination. Here are the roles and certs along it.
The next step
The pathway is plausible. Whether it holds for five years is a different question.
A Career Verdict applies the framework to your actual stage and stack: what holds, what breaks, what would change the call.
A route shows what people usually do. A Career Verdict judges whether it's realistic for you.
A Career Verdict includes
Built on POST's practitioner-authored assessment framework, calibrated by James from twenty years across helpdesk, infrastructure and security. Framework is human-authored; the verdict applies it to your inputs.