Senior Director, Digital Forensics and Incident Response
BlueVoyant
Position: Senior Director, Digital Forensics & Incident Response
Location: Remote, US
Work Authorization: US Citizenship Required
BlueVoyant is seeking a Senior Director, DFIR to lead high-impact cyber investigations and act as incident commander during complex, high-pressure security incidents.
This is a client-facing leadership role responsible for guiding organizations through critical moments—from initial response through investigation, containment, and recovery—while advising executives, legal counsel, and technical teams.
What You’ll Do:- Act as incident commander for complex DFIR engagements end-to-end
- Serve as the primary client lead , advising executives, legal counsel, insurers, and stakeholders
- Lead investigations across ransomware, BEC, cloud/identity compromise, insider threat, and advanced attacks
- Direct forensic analysis across endpoints, cloud, identity, SaaS, email, and network environments
- Translate technical findings into clear business risk and remediation guidance
- Lead executive briefings, client updates, and post-incident reviews
- Manage multiple concurrent incidents in fast-paced, high-pressure environments
- Mentor and develop DFIR consultants and technical teams
- Support incident readiness, tabletop exercises, and client growth initiative.
- 3–5 years of hands-on DFIR experience in real-world incidents
- 6–10 years in client-facing consulting, incident response, or cyber advisory roles
- Proven experience as an incident commander or senior DFIR lead
- Strong background in ransomware, cloud/identity compromise, and complex attack investigations
- Experience working directly with executives, legal counsel, insurers, and technical teams
- Ability to manage multiple stakeholders, workstreams, and timelines under pressure
- Leadership experience mentoring or managing technical teams
- Strong knowledge across endpoint, cloud, identity, SaaS, and network forensics
- Experience with tools such as EnCase, FTK, Magnet AXIOM, Velociraptor, Splunk, Sentinel, CrowdStrike (or similar)
- Familiarity with Microsoft 365, Entra ID, Azure, AWS, Okta, Google Workspace
- Understanding of attacker tradecraft, including persistence, lateral movement, and data exfiltration
- Working knowledge of KQL, SPL, SQL, PowerShell, Python, or Bash
- Exceptional communication skills—able to translate technical issues into business impact
- Strong judgment in high-stress, ambiguous environments
- Composed, credible, and client-focused under pressure
- Collaborative leader with a focus on quality, mentorship, and outcomes
- Experience working with breach counsel, insurers, or regulators
- Incident readiness, tabletop, or IR planning experience
- Certifications such as CISSP, GCFA, GCIH, GCFE, GNFA, OSCP
Bachelor’s degree preferred (Cybersecurity, Computer Science, DFIR, or related), or equivalent professional experience.
Why BlueVoyant?- Work alongside experienced DFIR leaders and experts , including former government cyber professionals and industry veterans.
- Lead high-impact, global cyber investigations , supporting clients through critical, business-defining incidents
- Gain exposure to complex environments, executive stakeholders, and advanced threat scenarios across industries
- Join a global, mission-driven cybersecurity company defending organisations worldwide with cutting-edge data, technology, and expertise
- Competitive compensation and comprehensive benefits package , with support for wellbeing, development, and career growth
About BlueVoyant
BlueVoyant is an AI-driven cybersecurity company dedicated to standing between our customers and cyber threats. By combining human, artificial, and proprietary intelligence, we deliver a unified solution that protects every organization’s network, identities, vendors, and digital footprints as a single attack surface. The company’s award-winning Microsoft Security expertise helps organizations maximize their security investments while reducing risk and ensuring compliance.
Led by CEO, John Hernandez, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and technologies.
Founded in 2017 by Fortune 500 executives, including Chairman of the Board, Jim Rosenthal, Vice Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, San Francisco, London, Budapest, and Latin America and is committed to building a workplace where talented people are empowered to do their best work in the fight against global cyber threats..
All employees must be authorized to work in the United States of America. BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, BlueVoyant complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. Disclaimer: Please note that pursuant to contractual requirements and applicable law, for employees to perform work on some of the company’s federal contracts, U.S. citizenship is required. Accordingly, an employee’s ability to perform work on such contracts is contingent upon the company’s verification of the employee’s citizenship status.
#LI-AH1
#LI-Remote
Important Information for Applicants: BlueVoyant uses AI-assisted tools within our applicant tracking system to help identify candidates whose experience and skills best match the requirements of a role. This technology provides hiring teams with added insights to support fair and efficient hiring decisions. All applications are reviewed by a member of our hiring team, and final hiring decisions are made by humans, not AI. By submitting your application, you acknowledge that AI tools may assist in the evaluation of your resume as part of the recruitment process.
Interview Expectations: As part of our interview process, we assess your experience through real-time discussion, so we expect responses to be your own. While we embrace the use of AI within our business and recruitment process, we do not permit its use during interviews. Any suspected use of AI during an interview will be challenged, and this may include the use of detection tools.
BlueVoyant Candidate Privacy Notice: To understand how we secure and manage your personal data upon submitting a job application, please see our Candidate Privacy Notice, which can be found here - Candidate Privacy Notice
- ...Position: Senior Director, Digital Forensics & Incident Response Location: Remote, US Work Authorization: US Citizenship Required BlueVoyant is seeking a Senior Director, DFIR to lead high-impact cyber investigations and act as incident commander during...SeniorFull timeWork at officeLocal areaRemote workWorldwide
$151k - $208k
...Palo Alto Networks, Inc. is looking for a Principal Consultant in Burbank, California, responsible for leading incident response and digital forensics services. This role involves serving as a technical leader on investigations and guiding clients through security incidents...SeniorRemote job- Zurich North America is seeking a Senior Incident Response Consultant to deliver expert incident response services. The role involves leading... ...a Bachelor’s degree or equivalent experience in IT, digital forensics skills, and proficiency in client communication. The position...SeniorRemote job
$142.9k - $266k
Digital Forensics and Incident Response, Senior ManagerThe Opportunity:Serve as a member of the Digital Forensics and Incident Response leadership team, responsible for the strategic direction, operational performance, client delivery, and continued growth of multiple incident...SeniorFull timeContract workPart timeWork at officeLocal areaRemote work$130k - $152.5k
...Position OverviewCRA’s Forensic Services practice... ...contribute to the team in this Senior Associate role may... ...of, and in response to, data security matters... ...detection, threat analysis, incident response and malware analysis... ...forensic analysis of digital information using...SeniorWork at officeLocal areaWork from home3 days per week$175k - $250k
...Position OverviewCRA’s Forensic Services practice... ...investigations space, your responsibilities as a Principal may... ...detection, threat analysis, incident response and malware... ...forensic analysis of digital information using standard... ...from an assigned senior colleague. Additional...Work at officeLocal areaWork from home3 days per week$160.3k - $240.5k
...un rôle pratique, pour agir à titre de responsable technique de l’équipe pendant les heures... ...des enquêtes complexes et la gestion d’incidents majeurs, offrirez des conseils techniques... ...OpportunityOur SecOps team is seeking a senior, hands-on security engineer to serve as...SeniorFull timeWork at officeRemote workWorldwide$90k - $120k
...About Surefire Cyber Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to... ..., predictability, and transparency Job Title: Senior Consultant, Digital Forensics and Incident Response (DFIR) Location: Remote,...SeniorRemote jobFull timeLocal areaFlexible hoursWeekend work- TeleTech Holdings, Inc. is seeking an Incident Response Manager to lead our security operations from a remote location in the United States. You will oversee detection, containment, and remediation of cybersecurity threats while guiding a skilled team of analysts. You’ll...SeniorRemote work
- A cybersecurity firm in Virginia is seeking an Incident Response Expert to support critical missions for government agencies. The role requires physical presence in the National Capital Region for initial training, followed by mostly remote work. Candidates must possess...SeniorRemote work
- BCG Attorney Search is seeking a Senior Cyber Incident Response Attorney for a fully remote position, with a preference for candidates based in Los... ...privacy laws, draft notices and policies, and oversee forensics and e‑Discovery. #J-18808-Ljbffr BCG Attorney SearchSeniorRemote job
$155k - $200k
Wilson Elser is seeking a Senior Cyber Incident Response Attorney to lead defense of complex cybersecurity and data privacy matters. This is a fully remote position open to applicants nationwide. Requirements include a JD, bar admission, 8+ years of legal experience, and...SeniorRemote job- BCG Attorney Search in Miami seeks a Senior Cyber Incident Response Attorney to lead complex cybersecurity matters and breach response for clients nationwide. This fully remote position offers high-stakes, policy-driven work with close collaboration across the firm's cyber...SeniorRemote job
- Wilson Elser, a national law firm with over 1,400 attorneys, invites applications for a Senior Cyber Incident Response Attorney. This is a fully remote role supporting clients nationwide, including opportunities across regions, with leadership in incident response and...SeniorRemote job
- Google Cloud's Mandiant team seeks a Senior Incident Response Security Consultant to deliver end-to-end incident response investigations, threat hunting, malware triage, and containment across enterprise environments. This role is remote eligible and open to candidates...SeniorRemote job
$155k - $200k
Wilson Elser is recruiting a Senior Cyber Incident Response Attorney for a fully remote role. Though based in New Orleans, we welcome applicants nationwide and may place to other regional offices. You will lead breach response, coordinate with clients and carriers, and...SeniorRemote job- Wilson Elser is seeking a Senior Cyber Incident Response Attorney for a fully remote role, primarily serving clients across the United States. The position focuses on leading incident response, data privacy, and breach management, with opportunities to supervise junior...SeniorRemote job
- Wilson Elser is seeking a Senior Cyber Incident Response Attorney for a fully remote role based in the United States. The attorney will lead incident response efforts for cybersecurity and data privacy incidents, oversee breach responses, and coordinate with clients, carriers...SeniorRemote job
- BCG Attorney Search is seeking a Senior Cyber Incident Response Attorney for a fully remote position, based in Chicago, Illinois. The role offers the opportunity to manage complex cybersecurity‑related cases and lead incident response efforts. Candidates should have 8+...SeniorRemote job
- Phase2 Technology is looking for a Cyber Incident Response Business Development Senior Manager to lead and grow its Incident Response business. This role involves driving business development initiatives, engaging key stakeholders, and managing strategic partner relationships...SeniorWork at officeRemote work
- Mercantil Commerce Bank is seeking a skilled Security Analyst III for a remote position focused on information security and incident response. This role involves administering security systems, assessing risks, and managing logging through SIEM utilities, along with hands...SeniorRemote jobHourly pay
- ...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is based in our New... ...cybersecurity incident from start to finishOversight of forensics investigationsOversight of third party vendors for e-Discovery...SeniorWork at officeRemote workFlexible hours
- Job DescriptionThe RoleThe Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT) role sits within the broader Product Cybersecurity organization at General Motors and focuses on responding to and managing product security vulnerabilities...SeniorFull timeLocal areaWork from homeRelocation package
- First Citizens Bank is seeking a Senior Incident Response Analyst to join the Cyber Incident Response team in a remote role across the United States. The candidate will detect and respond to threats, interact with business stakeholders, and restore operations while mentoring...SeniorRemote job
- Wilson Elser is seeking a Senior Cyber Incident Response Attorney to lead complex cybersecurity and data privacy matters. This fully remote role welcomes applicants nationwide and offers the chance to work with top-tier clients across industries. Ideal candidates have...SeniorRemote job
- First Citizens Bank is seeking a Senior Incident Response Analyst for a remote role that can be hired in multiple U.S. markets. You will join the Cyber Incident Response team, detecting and responding to threats, interacting with business stakeholders, and restoring operations...SeniorRemote job
$155k - $200k
...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is based in our New... ...cybersecurity incident from start to finishOversight of forensics investigationsOversight of third party vendors for e-Discovery...SeniorFull timeWork at officeRemote workFlexible hours$138k - $200k
...customer teams to investigate and contain incidents.Recognize and codify attacker Tools,... ...experience working end-to-end incident response investigations, analysis, or containment... ...of investigative experience with network forensics, malware triage analysis, cloud forensics...SeniorWork at officeRemote workShift workNight shift$89.01k - $142.19k
...role: You will be entrusted as the senior most technical member of incident response team for our global information... ...incident response plans, conduct cyber forensic investigations on physical... ...publishing, Elsevier offers a suite of digital solutions and services to support...SeniorFull timeLocal areaWork from home$142.9k - $266k
Cyber Incident Response Business Development Senior ManagerThe Opportunity:Join a team to contribute to Booz Allen's growth efforts for its Incident Response business, applying business development, strategic sales expertise and knowledge of Incident Response, including...SeniorFull timeContract workPart timeWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director, Digital Forensics and Incident Response. Be the first to apply!
- digital manager Remote
- senior manager digital Remote
- digital experience manager Remote
- director of digital platform Remote
- senior digital account manager Remote
- associate manager digital marketing Remote
- senior director digital marketing Remote
- digital director Remote
- senior lead project manager Remote
- senior robotics software engineer Remote

