CASE FILE / JDO-001
DIGITAL FORENSICS & INCIDENT RESPONSE
00:00:00 UTC
SubjectJacson Ott
DisciplineDFIR · Automation
OriginGrand Haven, MI
StatusEngaged @ Unit 42

Jacson
Ott.

Senior DFIR Consultant @ Palo Alto Networks · Unit 42

I work as a Senior DFIR Consultant at Palo Alto Networks Unit 42, dealing with ransomware, insider threats, extorition, and business email compromise — turning chaotic intrusions into structured timelines, and writing the automation that gets the next responder there faster.

Roles & experience

— CASE 009
MAY 2026 — PRESENT
Hybrid / Remote
In Progress

Senior DFIR Consultant

Palo Alto Networks · Unit 42

Technical lead for complex digital forensics and incident response engagements across ransomware, extortion, insider threat, and business email compromise. Set technical direction on active investigations and mentor associate and consultant-level responders.

  • Drive end-to-end investigative strategy on high-impact engagements
  • Mentor junior responders on investigative methodology and client communication
  • Gemini agent and tool development to scale response capabilities
— CASE 008
NOV 2024 — APR 2026
1Y 6MO · Remote
Closed

DFIR Consultant

Palo Alto Networks · Unit 42

Consultant on ransomware, extortion, insider threat, and business email compromise engagements. Direct client interface across the lifecycle of an investigation — from initial scoping through eradication and reporting.

  • Specialized in automating recurring response functions through Cortex XSOAR
  • Drove technical investigation across endpoint, identity, cloud, and email vectors
  • Prepared and delivered findings to audiences of various technical knowledge
— CASE 007
AUG 2023 — NOV 2024
1Y 4MO · Hybrid / Remote
Closed

Associate DFIR Consultant

Palo Alto Networks · Unit 42

Promoted from intern into a full consultant role. Carried active engagements end-to-end while building automation that reduced manual artifact processing across the practice.

  • Authored Cortex XSIAM automations for repeatable investigative workflows
  • Interfaced directly with client stakeholders during active incidents
— CASE 006
MAY 2023 — PRESENT
Concurrent · Spring Lake, MI
Ongoing

IT Consultant

Interior Concepts

Modernized the information technology and security posture of a manufacturing business — moving legacy systems to current cloud and security platforms.

  • Migrated from on-premise Exchange to Exchange Online (Microsoft 365)
  • Replaced legacy phone system with Teams Voice
  • Deployed Unifi Access, Network, and Protect to production
  • Migrated endpoint security to Microsoft Defender for Business
  • Acted as Incident Commander for incident impacting business operations
— CASE 005
MAY 2022 — AUG 2022
4MO · Remote
Closed

Incident Response Intern

Palo Alto Networks · Unit 42

Performed the responsibilities of a consultant on ransomware, extortion, and BEC engagements while contributing tooling that the team continued to use after the internship.

  • Used Axiom, Cortex XDR, Eric Zimmerman's tools, and X-Ways for artifact analysis
  • Built GitLab CI/CD E2E tests with Selenium for the in-house case management platform
  • Co-authored a Python library for programmatic access to that platform — used in live forensic automation
— CASE 004
MAY 2021 — DEC 2021
8MO · Remote
Closed

Digital Technology Intern

Oshkosh Corporation

Researched, tested, and demonstrated emerging datacenter technologies in a team-focused environment.

  • Refreshed documentation for backup and recovery systems
  • Converted email-based reporting into Splunk dashboards for environment visibility
  • Contributed to an automation POC using Ansible, Terraform, and vRealize Automation
— CASE 003
JUN 2020 — AUG 2020
3MO · Remote
Closed

CISO Governance & Compliance Intern

Fiat Chrysler Automobiles

Worked across IT systems and platforms to ensure security solutions adequately mitigated identified risk against business objectives.

  • Mapped CTPAT 2020 criteria to internal cybersecurity policies; streamlined the border crossing process
  • Reviewed and revised 45% of NAFTA FCA cybersecurity policies (~80,000 users in scope)
  • Standardized the external application security approval workflow
— CASE 002
MAY 2019 — AUG 2019
4MO · Muskegon, MI
Closed

IT Technician

Re-Source Industries

General IT and a series of infrastructure-improvement projects in a manufacturing environment.

  • Researched and deployed Puppet across 30 production devices to reduce manual management
  • Configured a local Linux repository to reduce production network bandwidth
  • Wrote 100+ support articles for a production management SaaS to improve customer usability
  • Strengthened long-term infrastructure with asset management and network diagramming
— CASE 001
MAR 2019 — SEP 2019
7MO · Houghton, MI
Closed

Tier 0 IT Technician

Michigan Technological University

Imaged, deployed, and troubleshot university workstations; supported end users through resolution.

Skills & instrumentation

// DFIR & Threat Hunting07
  • Incident Response
  • Cyber Threat Hunting
  • Cortex XSIAM
  • Cortex XDR
  • Magnet Axiom
  • X-Ways
  • Digital Forensics
// Engineering & Automation06
  • Python
  • Gemini
  • Splunk
  • Terraform
  • Puppet
  • Linux Administration
  • Networking
// Security & Governance05
  • Firewall Configuration
  • Security Policy
  • Governance & Law
  • Risk Mitigation

Education & certifications

Community & tinkering

Sep 2020 — 2022 · Houghton, MI

Networking & Computing Student Association · President

Network auditing, documentation, and automation. Leadership and teaching across the org.
Sep 2019 — 2022 · Houghton, MI

RedTeam · CTF Committee Member

Built CTF challenges. Top 10% National Cyber League competitor.
Jan 2016 — Present

Homelab

Remote access & management, file sharing, Windows domain management, and home security — the original sandbox where most of this started.