Digital Forensics & Incident Response (DFIR) Lead
$107k - $214.5kRSM US LLP
We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You’ll find an environment that inspires and empowers you to thrive both personally and professionally. There’s no one like you and that’s why there’s nowhere like RSM. The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Lead serves as both incident commander and engagement leader, overseeing multiple complex matters while aligning technical, legal, executive, and insurance workstreams. This role requires strong incident command authority, deep ransomware experience, and the ability to guide cross-functional response efforts at the executive level. Leads maintain oversight across engagements, provide escalation guidance to Supervisors, and ensure investigative quality, consistency, and defensibility across the practice. The DFIR Lead is accountable not only for technical excellence, but also for engagement delivery, stakeholder alignment, and operational leadership during crisis response. Responsibilities: Serve as incident commander during high-severity events, particularly ransomware and enterprise-scale breaches. Oversee multiple concurrent engagements, ensuring quality, consistency, and appropriate resource allocation. Define investigative strategy and escalation thresholds for complex incidents. Align technical response with legal, regulatory, insurance, and executive considerations. Review and approve investigative findings, containment validation, and executive reporting. Act as senior advisor to client executives, legal counsel, and cyber insurers. Provide guidance to Supervisors on advanced investigative decisions and complex threat actor scenarios. Maintain executive-level communication cadence during incidents. Support development of standardized methodologies, playbooks, and quality controls across the practice. Mentor Supervisors and Consultants in both technical depth and client leadership. Participate in on-call rotation and provide oversight during critical incidents. Preferred Qualifications: Expertise in all areas is not required; however, candidates should demonstrate strong foundational knowledge and a willingness to continuously learn and expand their capabilities. Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience. Proven experience leading enterprise-scale ransomware and breach investigations. Deep understanding of: Threat actor operations and ransomware tradecraft Identity compromise and domain-level persistence Cloud and hybrid environment incident response Data exfiltration risk assessment and reporting Strong hands-on familiarity with EDR platforms, SIEM technologies, and forensic toolsets. Demonstrated ability to manage multiple high-pressure engagements simultaneously. Experience coordinating with legal counsel, cyber insurance carriers, and executive leadership. Strong executive presence and crisis communication ability. Experience mentoring and developing DFIR leaders. Certifications such as GCFA, GCIH, CISSP, OSCP, or equivalent preferred. Willingness to participate in on-call rotation. At RSM, we offer a competitive benefits and compensation package for all our people. We offer flexibility in your schedule, empowering you to balance life’s demands, while also maintaining your ability to serve clients. Learn more about our total rewards at All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race; color; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender; sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the US uniformed service; US Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law. Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership. RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at View phone number on click.appcast.io or send us an email at View email address on click.appcast.io. RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future (i.e. F-1 visa holders). If you are a recent U.S. college / university graduate possessing 1-2 years of progressive and relevant work experience in a same or similar role to the one for which you are applying, excluding internships, you may be eligible for hire as an experienced associate. RSM will consider for employment qualified applicants with arrest or conviction records. For those living in California or applying to a position in California, please click here for additional information. At RSM, an employee’s pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range. Compensation Range: $107,000 - $214,500 Individuals selected for this role will be eligible for a discretionary bonus based on firm and individual performance. Not ready to apply yet? Join our Talent Community Why work at RSM? At RSM, we accomplish meaningful work and make an impact on the world around us. We work hard to fully understand our clients and work even harder to understand and identify your unique skills. We celebrate the differences among us and empower our talented professionals to grow forward, both personally and professionally. Our clients benefit from fresh insights and energy as we collaborate to support them, and our teams enjoy a work environment that inspires and empowers them to thrive.
- ...Dfir Manager The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Manager serves as both incident commander and engagement leader, overseeing multiple... ...platforms, SIEM technologies, and forensic toolsets. Demonstrated...Digital
- Accenture is seeking a hands-on technical leader for their Cyber Investigation and Forensic Response (CIFR) practice in Chicago. The candidate will excel in incident response and digital forensics, conducting complex analyses, mentoring investigators, and communicating...Digital
$70.35k - $205.8k
...Cyber Investigation and Forensic Response (CIFR) practice is at... ...consequential cyber incidents. We deliver around-the... ...have deep expertise in Digital Forensics, Incident Response... ...Investigator review Lead medium to large... ...Forensics, Incident Response (DFIR) experience with...DigitalWork experience placementLive inWork at officeLocal area- ...Overview A leading tech-enabled digital intelligence, investigation, and risk advisory firm is looking to appoint a Senior Associate, Digital Forensics and Incident Response (DFIR). The firm is seeking a dynamic new team member to help grow its Digital Forensics...Digital
$87.7k - $164k
...Young Oman is seeking a Cyber Triage and Forensics Incident Analyst based in Chicago, IL. This role... ...with a dedicated team to enhance digital security practices. The ideal candidate... ...over 5 years of experience in incident response, with a focus on digital forensics. A robust...DigitalFlexible hours$117.6k - $161.7k
...metro, Chicago, Boston, Atlanta, Nashville. The Senior Digital Forensics and Incident Response Engineer provides forensics technical expertise and... .... About us About Humana: Humana Inc. (NYSE: HUM) is a leading U.S. healthcare company. Through our Humana insurance services...DigitalFull timeTemporary workFor contractorsApprenticeshipRemote workWork from homeRelocationHome office- Flynaut LLC. is seeking a Cybersecurity Analyst in Chicago, IL to protect clients’ digital assets. As part of the Cybersecurity team, you will monitor security events, conduct incident response, and assist clients in compliance with security frameworks. Experience with...Digital
$115k - $130k
...technology company is seeking an IT Security Engineer to enhance security for digital assets. In this role, you will design and implement security controls, monitor security alerts, and lead incident response. Ideal candidates possess a Bachelor's degree and 4-7 years of...DigitalRemote jobFull time- RSM US LLP in Chicago is seeking a DFIR Manager to guide organizations through critical cyber events. This role requires strong incident command authority and deep expertise in ransomware investigations and cross-functional leadership. The successful candidate will oversee...
- A leading cyber insurance provider is seeking an Incident Manager in Chicago to lead responses to cyber events such as ransomware and data theft. The role involves ensuring client communication, managing the incident lifecycle, and collaborating with teams to support policyholders...
- ...Associates CRA is a leading global consulting firm... ...Overview CRA’s Forensic Services practice supports... ...of, and in response to, data security matters... ...detection, threat analysis, incident response and malware analysis... ...forensic analysis of digital information using...DigitalWork at officeLocal areaRemote workWork from home3 days per week
$103.27k - $206.54k
...training facility, and leading market tools, we... ...seeking a Manager, Forensic Technology to join our... ...Services practice. Responsibilities: Manage and... ...platforms to uncover digital evidence Consult... ...Digital Forensics and Incident Response (DFIR) tools and...DigitalH1bLocal area$181.72k - $272.58k
Anticipated End Date: 2026-07-13 Position Title: Sr. Director, Responsible AI Lead Job Description: Sr. Director, Responsible AI Lead Location:... ...approach, powered by industry-leading capabilities and a digital platform for health. Elevance Health is an Equal Employment...DigitalFull timeContract workTemporary workWork experience placementWork at officeLocal area3 days per week1 day per week- ...description: Cybersecurity Lead Location: Germantown,... ...solutions, and digital solutions. We are distinguished... ...SOC Lead's primary responsibilities include managing the... ...threat hunting and incident response, coordinating... ...incident response and forensic analysis. Ability to adapt...DigitalFull timeContract workTemporary workFor contractorsWork at officeLocal areaImmediate startHome officeFlexible hoursShift work
- ...a Security Supervisor to ensure the safety of guests and employees. The role includes supervising security activities, preparing incident reports, and maintaining records of packages received and distributed. The ideal candidate will enforce hotel policies, conduct investigations...
$242.24k - $333.08k
...oriented, and execution-focused Lead to direct the Program,... ...Manufacturing & Supply Chain) Digital Technologies organizations.... ...expanding beyond traditional PMO responsibilities to establish and operate a... ...(e.g., release management, incident management, user adoption)....Digital$200k - $240k
...Development / Strategy; IT / Digital; Legal / Compliance... ...broader Strategy department, leads the company's AI agenda from... ...relevant business units. Role Responsibilities Own the enterprise Responsible... ...Track and report AI‑related incidents to the ELT, maintaining a structured...DigitalPermanent employmentFull timeTemporary workWork at officeImmediate startWork visaFlexible hours- A leading financial services firm is seeking a Senior Director for their Technology Solutions Department in Chicago. This role emphasizes cybersecurity management, threat assessment, and project leadership. Candidates must hold a Bachelor's degree and have over 15 years...
- Envista Forensics is seeking a Regional Technical Leader in Chicago, IL, to manage... ...forensic investigations. You will lead the team in analyzing incidents and driving results for clients. A... ...commitment to excellence. You will also be responsible for technical training and...
$128.47k - $208.77k
Job Summary Join the Digital Marketing Enablement - Platform Engineering team as a Product... ...and work management solutions. Responsibilities Own and prioritize the product backlog... ...enterprise platform delivery. Knowledge of incidents, defect, and problem management practices...DigitalFlexible hours$130k - $150k
...AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure... ...and perspectives at AHEAD. Duties/Responsibilities AI Change Strategy & Adoption Partner... ...manager enablement specifically for leading AI-augmented teams Track and report on...DigitalWork at office$145.35k - $253.23k
..., a world-class training facility, and leading market tools, we help our people continue... ...for our Advisory Services practice. Responsibilities: Lead Enterprise Portfolio and... ...and applying SAP S/4HANA Public Cloud digital tools for EPPM and project financial management...DigitalH1bLocal area- Humana Inc. seeks a Senior Digital Forensics and Incident Response Engineer to provide technical expertise in cybersecurity and incident response in Chicago, IL. Candidates should have extensive experience in cyber security and digital forensics—including hands-on work...DigitalRemote job
- ...division of MISUMI Group, is a leading provider of standard,... ...components with a world‑class digital manufacturing platform, MISUMI... ...ensuring customers always have a responsive, knowledgeable, proactive point... ...causes, not just individual incidents Team Effectiveness &...DigitalContract workWork experience placementMonday to Friday
- ...ideal candidate will have over 3 years of experience in media planning and digital activation. Responsibilities include implementing media strategies, overseeing campaign planning, and leading client interactions. This role emphasizes strong communication and mentoring...Digital
$21 - $22.34 per hour
...interacting with our customers, driving digital growth, or providing vital behind-the-scenes... ...food. Position Overview As a Culinary Lead at Sur La Table, you play a key role in... ...a high-performing culinary team. Key Responsibilities Leadership & Team Development • Supports...DigitalContract workWork at officeLocal areaFlexible hoursNight shift$134k - $149.5k
Uber Advertising is seeking a Strategic Agency Partnerships Lead in Chicago, IL, responsible for expanding partnerships with agency holding companies.... ...will have over 10 years of experience in media and digital advertising, with a proven record in managing large advertising...Digital- A leading marketing company located in Chicago is seeking a Campaign Manager, Search, responsible for leading paid search campaigns. This role involves creating digital strategies, managing campaigns, and maintaining strong client relationships. Ideal candidates have a...Digital
$50.07k - $66.36k
A global marketing firm is seeking a Campaign Manager to oversee clients' paid search campaigns in Chicago. Responsibilities include implementing digital strategies, optimizing campaigns, and managing client communication. Ideal candidates will have at least 2 years of...Digital$87.21k - $125.27k
...over 3 years of experience in media planning or strategy with strong analytical skills and familiarity with digital marketing and audience tools. Responsibilities include supporting clients with actionable insights and developing client-facing materials while managing a...Digital
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Digital Forensics & Incident Response (DFIR) Lead. Be the first to apply!
- digital reporter Chicago, IL
- digital art internship Chicago, IL
- digital strategy Chicago, IL
- remote digital media Chicago, IL
- digital service engineer Chicago, IL
- digital analytics Chicago, IL
- digital print Chicago, IL
- digital media internship Chicago, IL
- digital media producer Chicago, IL
- digital engineer Chicago, IL


