Digital Forensics & Incident Response (DFIR) Manager
$107k - $214.5kDormont Manufacturing Company
We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM. The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Manager serves as both incident commander and engagement leader, overseeing multiple complex matters while aligning technical, legal, executive, and insurance workstreams. This role requires strong incident command authority, deep ransomware experience, and the ability to guide cross‑functional response efforts at the executive level. Managers maintain oversight across engagements, provide escalation guidance to Supervisors, and ensure investigative quality, consistency, and defensibility across the practice. The DFIR Manager is accountable not only for technical excellence, but also for engagement delivery, stakeholder alignment, and operational leadership during crisis response. Responsibilities Serve as incident commander during high‑severity events, particularly ransomware and enterprise‑scale breaches. Oversee multiple concurrent engagements, ensuring quality, consistency, and appropriate resource allocation. Define investigative strategy and escalation thresholds for complex incidents. Align technical response with legal, regulatory, insurance, and executive considerations. Review and approve investigative findings, containment validation, and executive reporting. Act as senior advisor to client executives, legal counsel, and cyber insurers. Provide guidance to Supervisors on advanced investigative decisions and complex threat actor scenarios. Maintain executive‑level communication cadence during incidents. Support development of standardized methodologies, playbooks, and quality controls across the practice. Mentor Supervisors and Consultants in both technical depth and client leadership. Participate in on‑call rotation and provide oversight during critical incidents. Preferred Qualifications Expertise in all areas is not required; however, candidates should demonstrate strong foundational knowledge and a willingness to continuously learn and expand their capabilities. Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience. Proven experience leading enterprise‑scale ransomware and breach investigations. Deep understanding of: Threat actor operations and ransomware tradecraft Identity compromise and domain‑level persistence Cloud and hybrid environment incident response Data exfiltration risk assessment and reporting Strong hands‑on familiarity with EDR platforms, SIEM technologies, and forensic toolsets. Demonstrated ability to manage multiple high‑pressure engagements simultaneously. Experience coordinating with legal counsel, cyber insurance carriers, and executive leadership. Strong executive presence and crisis communication ability. Experience mentoring and developing DFIR leaders. Certifications such as GCFA, GCIH, CISSP, OSCP, or equivalent preferred. Willingness to participate in on‑call rotation. At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race, color, creed, sincerely held religious beliefs, practices or observances, sex (including pregnancy or disabilities related to nursing), gender, sexual orientation, HIV status, national origin, ancestry, familial or marital status, age, physical or mental disability, citizenship, political affiliation, medical condition (including family and medical leave), domestic violence victim status, past, current or prospective service in the US uniformed service, US Military/Veteran status, pre‑disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment. RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. At RSM, an employee’s pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range. Compensation Range: $107,000 - $214,500 Individuals selected for this role will be eligible for a discretionary bonus based on firm and individual performance. #J-18808-Ljbffr
- ...Dfir Manager The RSM Cyber Response team leads organizations through some of their most consequential cyber... .... The DFIR Manager serves as both incident commander and engagement leader, overseeing... ...platforms, SIEM technologies, and forensic toolsets. Demonstrated ability...Digital
- ...Overview A leading tech-enabled digital intelligence, investigation, and risk advisory firm is looking to appoint a Senior Associate, Digital Forensics and Incident Response (DFIR). The firm is seeking a dynamic new team member to help grow its Digital Forensics...Digital
$87.7k - $164k
...Young Oman is seeking a Cyber Triage and Forensics Incident Analyst based in Chicago, IL. This role... ...with a dedicated team to enhance digital security practices. The ideal candidate... ...over 5 years of experience in incident response, with a focus on digital forensics. A robust...DigitalFlexible hours$112k - $139k
A national law firm is seeking a SOC/Incident Report Engineer for its Chicago office. This hybrid position involves detecting and... ...to cybersecurity incidents, focusing on threat detection and digital forensics. The ideal candidate will have solid experience in a...DigitalWork at office$100k - $126.5k
...Consulting Associate/Cybersecurity & Incident Response CRA's Forensic Services practice supports companies... ...have majored in Computer Science, Digital Forensics, Information Security, and... ...collaboratively with a team, effectively manage their time, prioritize tasks, and...DigitalWork at officeWork from home3 days per week$130k - $152.5k
...services - economic and management consulting - are... ...Position Overview CRA’s Forensic Services [ practice supports... ...of, and in response to, data security matters... ...detection, threat analysis, incident response and malware... ...forensic analysis of digital information using...DigitalFull timeWork at officeLocal areaWork from home3 days per week- Flynaut LLC. is seeking a Cybersecurity Analyst in Chicago, IL to protect clients’ digital assets. As part of the Cybersecurity team, you will monitor security events, conduct incident response, and assist clients in compliance with security frameworks. Experience with...Digital
$115k - $130k
...technology company is seeking an IT Security Engineer to enhance security for digital assets. In this role, you will design and implement security controls, monitor security alerts, and lead incident response. Ideal candidates possess a Bachelor's degree and 4-7 years of...DigitalRemote jobFull time- ...services – economic and management consulting – are... ...Position Overview CRA’s Forensic Services practice... ...space, your responsibilities as a Principal may include... ...detection, threat analysis, incident response and malware... ...forensic analysis of digital information using...DigitalWork at officeLocal areaRemote workWork from home3 days per week
- ...recommendations when needed. Manages field engineers, provide... ...following duties. Duties and Responsibilities include the following. Other... ...construction management or forensic engineering Certificates and... ...and/or Cell phone Ladder Digital level Tape measure Rope and...DigitalFor contractorsWork experience placementWork at office
$108k - $135k
...Cyber Security Incident Response Analyst II At Early Warning, we've powered and protected the... ...investigative analysis activities for a variety of digital devices, computers, storage media,... ...Performs advanced host and network forensics and malware analysis; Investigates and...DigitalHourly payWork experience placementWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- A leading global food retailer is seeking a Security Engineering Manager to safeguard their technology environment in Chicago. This role involves enforcing security policies, managing incident responses, and collaborating with IT and business teams. The ideal candidate...Flexible hours
$139.12k - $208.68k
A leading grocery retailer is seeking a Security Engineering Manager in Chicago to safeguard its technology environment. This role handles security policies, manages the incident response plan, and investigates potential threats. Candidates should have at least 10 years...Flexible hours$103.27k - $206.54k
...KPMG is currently seeking a Manager, Forensic Technology to join our... ...Advisory Services practice. Responsibilities: Manage and advise... ...platforms to uncover digital evidence Consult with... ...line Digital Forensics and Incident Response (DFIR) tools and techniques to...DigitalH1bLocal area- ...empower and facilitate trust for a digital-first world. Today,... ...handle crucial security and PR incidents daily. Champion Outtake'... ...how we can transform incident response and brand protection on a global... ...remains the premier incident management and brand protection platform...DigitalWork at officeImmediate startFlexible hours
$108.08k - $192.46k
...Manager II Choosing Capgemini means choosing a company where you... ...’ unique requirements. Responsible for software-specific design... ...team to eliminate recurring incidents and to minimize the impact of... ...accelerate their dual transition to a digital and sustainable world, while...DigitalPermanent employmentFull timeContract workLocal areaRemote workRelocation2 days per week3 days per week$111.53k - $158.55k
...Manager Choosing Capgemini means choosing a company where you... ...technical lead and mentor. Responsible for software-specific design... ...team to eliminate recurring incidents and to minimize the impact of... ...accelerate their dual transition to a digital and sustainable world, while...DigitalPermanent employmentFull timeContract workLocal areaRemote workRelocation2 days per week3 days per week$150k - $170k
...Description The Microsoft 365 Platform Manager owns the definition,... ...role partners closely with Digital Workplace leadership, Cyber Security... ...intentional, scalable, and responsible use of Microsoft 365... ...365 administration. Routine incident management or operational escalation...DigitalFull time- ...If the position includes overnight responsibilities, this role may be required to respond to... ...when violations occur. Utilize our digital guest registry system to create room reservations... ...needs of the families Complete incident reports and submit within 24 hours of...DigitalWork experience placementWork at officeShift workNight shift
$145k - $165k
...experiences powered by our range of digital hardware, our proprietary content management system and our industry leading... ...technology industry. Responsibilities: Go-To-Market Execution... ...seriously. Coates has reported these incidents to law enforcement and is cooperating...DigitalFlexible hoursShift work$80k - $90k
...Overview The Safety & Security Manager contributes to the... ...employees; coordinates accident/incident process; conducts audits and... ...voluntary long-term disability Key Responsibilities Ensure compliance with state... ...coordinate Audit TAS Safety digital files to maintain a clean...DigitalTemporary workWork at officeLocal areaShift workWeekend work$12 per day
...Summary & Objectives The Senior Marketing Manager will spearhead the development and... ...’s specialized services in cyber incident response, digital asset security, and crypto investigations... ...incident response and cryptocurrency forensics and investigations. Cultivate and...DigitalLocal areaImmediate startRemote workFlexible hours- ...Financial Services, Leasing, Asset Management, or Capital Markets Role... ...is a senior leadership role responsible for end-to-end service... ...adoption of ITIL, automation, and digital service management practices... ...Deep understanding of incident, problem, change, release, and...DigitalContract workWork at office
$59.15k - $106.93k
...opportunity for a Project Manager I (PM) who will work alongside... ...nationwide. Primary Responsibilities Independently lead project... ...smarter, more efficient digital and mission innovations. Headquartered... ...enforcement and report the incident to the . Commitment to...DigitalContract workFor subcontractorLocal areaImmediate startWork from home$120.96k - $181.44k
...Finance, Legal, Sustainability, Commercial, Digital and E-commerce, Technology and more. Overview The Security Engineering Manager plays a critical role in safeguarding our... ...Security. This role manages the ADUSA Incident Response Plan across all scenarios, ensuring timely...DigitalFull timeWork at officeRemote workFlexible hoursWeekend work$167.37k - $209.21k
...Double Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald's... ...Overview As Senior Manager, Offensive Security , you will... ...testers and red team operators responsible for proactively identifying,... ...You will partner closely with Incident Response, Detection Engineering...DigitalLocal areaShift work$148k - $197.45k
...the client will be mandatory. Responsibilities Accountable for end‑to‑end... ...Develop and maintain Crisis Management/Disaster Plans. Implement project... .../Escalation/Missed SLA incidents. Implement and execute automation... .... Preferred Skills Digital Transformation experience leveraging...DigitalTemporary workFlexible hours- ...AI-powered identity platform manages and governs human and non-human... ...Saviynt to safeguard their digital assets, drive operational efficiency... .... This person is ultimately responsible for the entire enterprise... ...& Handling Policy Incident Response Policy/Procedures...Digital
- ...about your craft! You will build and manage a pipeline of State and Local Accounts... ...and potential Salesforce customers. Digital HQ - Living and breathing the Slack... ...the Slack platform for disaster and incident preparedness, response and recovery. A key mission based sales...DigitalLocal area
$110k - $125k
...experiences powered by our range of digital hardware, our proprietary content management system and our industry leading... ...best customer experiences. Responsibilities • Project Delivery: Ensure... .... Coates has reported these incidents to law enforcement and is cooperating...DigitalFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Digital Forensics & Incident Response (DFIR) Manager. Be the first to apply!
- apple localization manager Chicago, IL
- compounding manager Chicago, IL
- nicu manager Chicago, IL
- ca identity manager Chicago, IL
- mitigation manager Chicago, IL
- senior compensation manager Chicago, IL
- manager total rewards Chicago, IL
- manager salesforce Chicago, IL
- valuation manager Chicago, IL
- fraud prevention manager Chicago, IL

