Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Digital Forensics & Incident Response (DFIR) Lead

$107k - $214.5k
Full-time

RSM US LLP

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM. The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Lead serves as both incident commander and engagement leader, overseeing multiple complex matters while aligning technical, legal, executive, and insurance workstreams. This role requires strong incident command authority, deep ransomware experience, and the ability to guide cross-functional response efforts at the executive level. Leads maintain oversight across engagements, provide escalation guidance to Supervisors, and ensure investigative quality, consistency, and defensibility across the practice. The DFIR Lead is accountable not only for technical excellence, but also for engagement delivery, stakeholder alignment, and operational leadership during crisis response. Responsibilities: Serve as incident commander during high-severity events, particularly ransomware and enterprise-scale breaches. Oversee multiple concurrent engagements, ensuring quality, consistency, and appropriate resource allocation. Define investigative strategy and escalation thresholds for complex incidents. Align technical response with legal, regulatory, insurance, and executive considerations. Review and approve investigative findings, containment validation, and executive reporting. Act as senior advisor to client executives, legal counsel, and cyber insurers. Provide guidance to Supervisors on advanced investigative decisions and complex threat actor scenarios. Maintain executive-level communication cadence during incidents. Support development of standardized methodologies, playbooks, and quality controls across the practice. Mentor Supervisors and Consultants in both technical depth and client leadership. Participate in on-call rotation and provide oversight during critical incidents. Preferred Qualifications: Expertise in all areas is not required; however, candidates should demonstrate strong foundational knowledge and a willingness to continuously learn and expand their capabilities. Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience. Proven experience leading enterprise-scale ransomware and breach investigations. Deep understanding of: Threat actor operations and ransomware tradecraft Identity compromise and domain-level persistence Cloud and hybrid environment incident response Data exfiltration risk assessment and reporting Strong hands-on familiarity with EDR platforms, SIEM technologies, and forensic toolsets. Demonstrated ability to manage multiple high-pressure engagements simultaneously. Experience coordinating with legal counsel, cyber insurance carriers, and executive leadership. Strong executive presence and crisis communication ability. Experience mentoring and developing DFIR leaders. Certifications such as GCFA, GCIH, CISSP, OSCP, or equivalent preferred. Willingness to participate in on-call rotation. At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race; color; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender; sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the US uniformed service; US Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership. RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at View phone number on click.appcast.io or send us an email at View email address on click.appcast.io. RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future (i.e. F-1 visa holders). If you are a recent U.S. college / university graduate possessing 1-2 years of progressive and relevant work experience in a same or similar role to the one for which you are applying, excluding internships, you may be eligible for hire as an experienced associate. RSM will consider for employment qualified applicants with arrest or conviction records. For those living in California or applying to a position in California, please click here for additional information. At RSM, an employee’s pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range. Compensation Range: $107,000 - $214,500 Individuals selected for this role will be eligible for a discretionary bonus based on firm and individual performance. Not ready to apply yet? Join our Talent Community Why work at RSM? At RSM, we accomplish meaningful work and make an impact on the world around us. We work hard to fully understand our clients and work even harder to understand and identify your unique skills. We celebrate the differences among us and empower our talented professionals to grow forward, both personally and professionally. Our clients benefit from fresh insights and energy as we collaborate to support them, and our teams enjoy a work environment that inspires and empowers them to thrive.

Vacancy posted 6 hours ago
Similar jobs that could be interesting for youBased on the Digital Forensics & Incident Response (DFIR) Lead in Chicago, IL vacancy
  •  ...Dfir Manager The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Manager serves as both incident commander and engagement leader, overseeing multiple...  ...platforms, SIEM technologies, and forensic toolsets. Demonstrated... 
    Digital

    RSM

    Chicago, IL
    21 hours ago
  • Accenture is seeking a hands-on technical leader for their Cyber Investigation and Forensic Response (CIFR) practice in Chicago. The candidate will excel in incident response and digital forensics, conducting complex analyses, mentoring investigators, and communicating... 
    Digital

    Accenture

    Chicago, IL
    1 day ago
  • $70.35k - $205.8k

     ...Cyber Investigation and Forensic Response (CIFR) practice is at...  ...consequential cyber incidents. We deliver around-the...  ...have deep expertise in Digital Forensics, Incident Response...  ...Investigator review Lead medium to large...  ...Forensics, Incident Response (DFIR) experience with... 
    Digital
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Chicago, IL
    1 day ago
  •  ...Overview A leading tech-enabled digital intelligence, investigation, and risk advisory firm is looking to appoint a Senior Associate, Digital Forensics and Incident Response (DFIR). The firm is seeking a dynamic new team member to help grow its Digital Forensics... 
    Digital
    Chicago, IL
    20 days ago
  • $87.7k - $164k

     ...Young Oman is seeking a Cyber Triage and Forensics Incident Analyst based in Chicago, IL. This role...  ...with a dedicated team to enhance digital security practices. The ideal candidate...  ...over 5 years of experience in incident response, with a focus on digital forensics. A robust... 
    Digital
    Flexible hours

    Ernst & Young Oman

    Chicago, IL
    13 hours ago
  • $117.6k - $161.7k

     ...metro, Chicago, Boston, Atlanta, Nashville. The Senior Digital Forensics and Incident Response Engineer provides forensics technical expertise and...  .... About us About Humana: Humana Inc. (NYSE: HUM) is a leading U.S. healthcare company. Through our Humana insurance services... 
    Digital
    Full time
    Temporary work
    For contractors
    Apprenticeship
    Remote work
    Work from home
    Relocation
    Home office

    Humana Inc

    Chicago, IL
    1 day ago
  • Flynaut LLC. is seeking a Cybersecurity Analyst in Chicago, IL to protect clients’ digital assets. As part of the Cybersecurity team, you will monitor security events, conduct incident response, and assist clients in compliance with security frameworks. Experience with... 
    Digital

    Flynaut LLC.

    Chicago, IL
    3 days ago
  • $115k - $130k

     ...technology company is seeking an IT Security Engineer to enhance security for digital assets. In this role, you will design and implement security controls, monitor security alerts, and lead incident response. Ideal candidates possess a Bachelor's degree and 4-7 years of... 
    Digital
    Remote job
    Full time

    Redwood Logistics

    Chicago, IL
    3 days ago
  • RSM US LLP in Chicago is seeking a DFIR Manager to guide organizations through critical cyber events. This role requires strong incident command authority and deep expertise in ransomware investigations and cross-functional leadership. The successful candidate will oversee... 

    RSM US LLP

    Chicago, IL
    2 days ago
  • A leading cyber insurance provider is seeking an Incident Manager in Chicago to lead responses to cyber events such as ransomware and data theft. The role involves ensuring client communication, managing the incident lifecycle, and collaborating with teams to support policyholders... 

    Canopius Group

    Chicago, IL
    13 hours ago
  •  ...Associates CRA is a leading global consulting firm...  ...Overview CRA’s  Forensic Services practice supports...  ...of, and in response to, data security matters...  ...detection, threat analysis, incident response and malware analysis...  ...forensic analysis of digital information using... 
    Digital
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    more than 2 months ago
  • $103.27k - $206.54k

     ...training facility, and leading market tools, we...  ...seeking a Manager, Forensic Technology to join our...  ...Services practice. Responsibilities: Manage and...  ...platforms to uncover digital evidence Consult...  ...Digital Forensics and Incident Response (DFIR) tools and... 
    Digital
    H1b
    Local area

    KPMG

    Chicago, IL
    2 days ago
  • $181.72k - $272.58k

    Anticipated End Date: 2026-07-13 Position Title: Sr. Director, Responsible AI Lead Job Description: Sr. Director, Responsible AI Lead Location:...  ...approach, powered by industry-leading capabilities and a digital platform for health. Elevance Health is an Equal Employment... 
    Digital
    Full time
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Local area
    3 days per week
    1 day per week

    Elevance Health

    Chicago, IL
    6 hours ago
  •  ...description: Cybersecurity Lead Location: Germantown,...  ...solutions, and digital solutions. We are distinguished...  ...SOC Lead's primary responsibilities include managing the...  ...threat hunting and incident response, coordinating...  ...incident response and forensic analysis. Ability to adapt... 
    Digital
    Full time
    Contract work
    Temporary work
    For contractors
    Work at office
    Local area
    Immediate start
    Home office
    Flexible hours
    Shift work

    Management Solutions

    Chicago, IL
    21 hours ago
  •  ...a Security Supervisor to ensure the safety of guests and employees. The role includes supervising security activities, preparing incident reports, and maintaining records of packages received and distributed. The ideal candidate will enforce hotel policies, conduct investigations... 

    Sonesta International Hotels

    Chicago, IL
    4 days ago
  • $242.24k - $333.08k

     ...oriented, and execution-focused Lead to direct the Program,...  ...Manufacturing & Supply Chain) Digital Technologies organizations....  ...expanding beyond traditional PMO responsibilities to establish and operate a...  ...(e.g., release management, incident management, user adoption).... 
    Digital

    Mars, Incorporated and its Affiliates

    Chicago, IL
    13 hours ago
  • $200k - $240k

     ...Development / Strategy; IT / Digital; Legal / Compliance...  ...broader Strategy department, leads the company's AI agenda from...  ...relevant business units. Role Responsibilities Own the enterprise Responsible...  ...Track and report AI‑related incidents to the ELT, maintaining a structured... 
    Digital
    Permanent employment
    Full time
    Temporary work
    Work at office
    Immediate start
    Work visa
    Flexible hours

    RWE Americas

    Chicago, IL
    3 days ago
  • A leading financial services firm is seeking a Senior Director for their Technology Solutions Department in Chicago. This role emphasizes cybersecurity management, threat assessment, and project leadership. Candidates must hold a Bachelor's degree and have over 15 years... 

    Golub Capital BDC Inc

    Chicago, IL
    1 day ago
  • Envista Forensics is seeking a Regional Technical Leader in Chicago, IL, to manage...  ...forensic investigations. You will lead the team in analyzing incidents and driving results for clients. A...  ...commitment to excellence. You will also be responsible for technical training and... 

    Envista Forensics

    Chicago, IL
    2 days ago
  • $128.47k - $208.77k

    Job Summary Join the Digital Marketing Enablement - Platform Engineering team as a Product...  ...and work management solutions. Responsibilities Own and prioritize the product backlog...  ...enterprise platform delivery. Knowledge of incidents, defect, and problem management practices... 
    Digital
    Flexible hours

    Caterpillar Brazil

    Chicago, IL
    13 hours ago
  • $130k - $150k

     ...AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure...  ...and perspectives at AHEAD. Duties/Responsibilities AI Change Strategy & Adoption Partner...  ...manager enablement specifically for leading AI-augmented teams Track and report on... 
    Digital
    Work at office

    Medium

    Chicago, IL
    21 hours ago
  • $145.35k - $253.23k

     ..., a world-class training facility, and leading market tools, we help our people continue...  ...for our Advisory Services practice. Responsibilities: Lead Enterprise Portfolio and...  ...and applying SAP S/4HANA Public Cloud digital tools for EPPM and project financial management... 
    Digital
    H1b
    Local area

    KPMG

    Chicago, IL
    2 days ago
  • Humana Inc. seeks a Senior Digital Forensics and Incident Response Engineer to provide technical expertise in cybersecurity and incident response in Chicago, IL. Candidates should have extensive experience in cyber security and digital forensics—including hands-on work... 
    Digital
    Remote job

    Humana Inc

    Chicago, IL
    1 day ago
  •  ...division of MISUMI Group, is a leading provider of standard,...  ...components with a world‑class digital manufacturing platform, MISUMI...  ...ensuring customers always have a responsive, knowledgeable, proactive point...  ...causes, not just individual incidents Team Effectiveness &... 
    Digital
    Contract work
    Work experience placement
    Monday to Friday

    Fictiv

    Chicago, IL
    2 days ago
  •  ...ideal candidate will have over 3 years of experience in media planning and digital activation. Responsibilities include implementing media strategies, overseeing campaign planning, and leading client interactions. This role emphasizes strong communication and mentoring... 
    Digital

    Publicisgroupe

    Chicago, IL
    4 days ago
  • $21 - $22.34 per hour

     ...interacting with our customers, driving digital growth, or providing vital behind-the-scenes...  ...food. Position Overview As a Culinary Lead at Sur La Table, you play a key role in...  ...a high-performing culinary team. Key Responsibilities Leadership & Team Development • Supports... 
    Digital
    Contract work
    Work at office
    Local area
    Flexible hours
    Night shift

    CSC Generation

    Chicago, IL
    3 hours ago
  • $134k - $149.5k

    Uber Advertising is seeking a Strategic Agency Partnerships Lead in Chicago, IL, responsible for expanding partnerships with agency holding companies....  ...will have over 10 years of experience in media and digital advertising, with a proven record in managing large advertising... 
    Digital

    Uber Advertising

    Chicago, IL
    3 days ago
  • A leading marketing company located in Chicago is seeking a Campaign Manager, Search, responsible for leading paid search campaigns. This role involves creating digital strategies, managing campaigns, and maintaining strong client relationships. Ideal candidates have a... 
    Digital

    Publicis Media

    Chicago, IL
    2 days ago
  • $50.07k - $66.36k

    A global marketing firm is seeking a Campaign Manager to oversee clients' paid search campaigns in Chicago. Responsibilities include implementing digital strategies, optimizing campaigns, and managing client communication. Ideal candidates will have at least 2 years of... 
    Digital

    Publicis Groupe ANZ

    Chicago, IL
    1 day ago
  • $87.21k - $125.27k

     ...over 3 years of experience in media planning or strategy with strong analytical skills and familiarity with digital marketing and audience tools. Responsibilities include supporting clients with actionable insights and developing client-facing materials while managing a... 
    Digital

    UNAVAILABLE

    Chicago, IL
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Digital Forensics & Incident Response (DFIR) Lead. Be the first to apply!