Digital Forensics & Incident Response (DFIR) Manager
$107k - $214.5kRSM US LLP
We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You'll find an environment that inspires and empowers you to thrive both personally and professionally. There's no one like you and that's why there's nowhere like RSM.
The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Manager serves as both incident commander and engagement leader, overseeing multiple complex matters while aligning technical, legal, executive, and insurance workstreams.
This role requires strong incident command authority, deep ransomware experience, and the ability to guide cross-functional response efforts at the executive level. Managers maintain oversight across engagements, provide escalation guidance to Supervisors, and ensure investigative quality, consistency, and defensibility across the practice.
The DFIR Manager is accountable not only for technical excellence, but also for engagement delivery, stakeholder alignment, and operational leadership during crisis response.
Responsibilities:
- Serve as incident commander during high-severity events, particularly ransomware and enterprise-scale breaches.
- Oversee multiple concurrent engagements, ensuring quality, consistency, and appropriate resource allocation.
- Define investigative strategy and escalation thresholds for complex incidents.
- Align technical response with legal, regulatory, insurance, and executive considerations.
- Review and approve investigative findings, containment validation, and executive reporting.
- Act as senior advisor to client executives, legal counsel, and cyber insurers.
- Provide guidance to Supervisors on advanced investigative decisions and complex threat actor scenarios.
- Maintain executive-level communication cadence during incidents.
- Support development of standardized methodologies, playbooks, and quality controls across the practice.
- Mentor Supervisors and Consultants in both technical depth and client leadership.
- Participate in on-call rotation and provide oversight during critical incidents.
Preferred Qualifications:
Expertise in all areas is not required; however, candidates should demonstrate strong foundational knowledge and a willingness to continuously learn and expand their capabilities.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.
- Proven experience leading enterprise-scale ransomware and breach investigations.
- Deep understanding of:
- Threat actor operations and ransomware tradecraft
- Identity compromise and domain-level persistence
- Cloud and hybrid environment incident response
- Data exfiltration risk assessment and reporting
- Strong hands-on familiarity with EDR platforms, SIEM technologies, and forensic toolsets.
- Demonstrated ability to manage multiple high-pressure engagements simultaneously.
- Experience coordinating with legal counsel, cyber insurance carriers, and executive leadership.
- Strong executive presence and crisis communication ability.
- Experience mentoring and developing DFIR leaders.
- Certifications such as GCFA, GCIH, CISSP, OSCP, or equivalent preferred.
- Willingness to participate in on-call rotation.
At RSM, we offer a competitive benefits and compensation package for all our people.We offer flexibility in your schedule, empowering you to balance life's demands, while also maintaining your ability to serve clients.Learn more about our total rewards at
All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race; color; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender; sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the US uniformed service; US Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law.
Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership.RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at View phone number on click.appcast.io or send us an email at View email address on click.appcast.io.
RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future (i.e. F-1 visa holders). If you are a recent U.S. college / university graduate possessing 1-2 years of progressive and relevant work experience in a same or similar role to the one for which you are applying, excluding internships, you may be eligible for hire as an experienced associate.
RSM will consider for employment qualified applicants with arrest or conviction records. For those living in California or applying to a position in California, please click here for additional information.
At RSM, an employee's pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range.
Compensation Range: $107,000 - $214,500Individualsselected for this role will be eligible for a discretionary bonus based on firm and individual performance.
- ...Dfir Manager The RSM Cyber Response team leads organizations through some of their most consequential cyber... .... The DFIR Manager serves as both incident commander and engagement leader, overseeing... ...platforms, SIEM technologies, and forensic toolsets. Demonstrated ability...Digital
- ...TITLE: Senior Associate PRACTICE/CORPORATE: Digital Forensics & Incident Response LOCATION: TBD REPORTS TO: Managing Director FLSA: Exempt DATE COMPLETED/... ...grow our Digital Forensics & Incident Response (DFIR) services. Prescient has built a world class...Digital
- ...IL. This role involves designing scalable tools for digital investigations and incident response, using expertise in cybersecurity, software engineering... ...automation tools and maintaining secure data management workflows. An excellent opportunity in a fast-paced environment...Digital
$87.7k - $164k
...Young Oman is seeking a Cyber Triage and Forensics Incident Analyst based in Chicago, IL. This role... ...with a dedicated team to enhance digital security practices. The ideal candidate... ...over 5 years of experience in incident response, with a focus on digital forensics. A robust...DigitalFlexible hours$112k - $139k
A national law firm is seeking a SOC/Incident Report Engineer for its Chicago office. This hybrid position involves detecting and... ...to cybersecurity incidents, focusing on threat detection and digital forensics. The ideal candidate will have solid experience in a...DigitalWork at office$130k - $152.5k
...Senior Associate/Cybersecurity & Incident Response (Forensic Services Practice) Boston, MA, United... ...Our two main services – economic and management consulting – are delivered by practice... ...; Performing forensic analysis of digital information using standard computer forensics...DigitalWork at officeLocal areaWork from home3 days per week$140k - $170k
...Associate Principal/Cybersecurity & Incident Response Boston, MA, United States... ...services – economic and management consulting – are delivered... ...Position Overview CRA's Forensic Services practice supports... ...Performing forensic analysis of digital information using standard...DigitalWork at officeLocal areaRemote workWork from home3 days per week$100k - $126.5k
...Consulting Associate/Cybersecurity & Incident Response CRA's Forensic Services practice supports companies... ...have majored in Computer Science, Digital Forensics, Information Security, and... ...collaboratively with a team, effectively manage their time, prioritize tasks, and...DigitalWork at officeWork from home3 days per week- Flynaut LLC. is seeking a Cybersecurity Analyst in Chicago, IL to protect clients’ digital assets. As part of the Cybersecurity team, you will monitor security events, conduct incident response, and assist clients in compliance with security frameworks. Experience with...Digital
$100k - $140k
...success, resulting in A&M's Forensic Technology Services being a... ...is comprised of experienced digital forensics, eDiscovery, data... ...electronic discovery and disclosure management, digital forensics, forensic... ...analytics, cyber risk and incident response, privacy, information...DigitalPart timeFlexible hours$115k - $130k
...technology company is seeking an IT Security Engineer to enhance security for digital assets. In this role, you will design and implement security controls, monitor security alerts, and lead incident response. Ideal candidates possess a Bachelor's degree and 4-7 years of...DigitalRemote jobFull time- ...Job Title: Threat and Incident Response Analyst Location: Chicago, IL Contract Duration... .... Collect, analyze, and preserve digital evidence related to security incidents.... ...monitoring. Work with the Bank's Managed Security Services Provider as well as...DigitalContract work
- ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI... ...hands-on experience in SOC operations and digital investigations will directly shape how... ...with threat hunting, digital forensics, or malware analysis Familiarity with...DigitalHourly payOngoing contractContract workFreelanceRemote workWorldwideFlexible hours
- ...families to continue treatments and manage the necessary equipment in... ...Finally, La Rabida provides forensic and treatment services for... ...Ambulatory and Provider Services is responsible for supervising frontline... ...of new workflows, digital health tools, or clinical services...DigitalWork experience placement
- ...recommendations when needed. Manages field engineers, provide... ...following duties. Duties and Responsibilities include the following.... ...construction management or forensic engineering Certificates... ...Phone and/or Cell phone Digital camera Ladder Moisture...DigitalFor contractorsWork experience placementWork at office
$108k - $135k
...Cyber Security Incident Response Analyst II At Early Warning, we've powered and protected the... ...investigative analysis activities for a variety of digital devices, computers, storage media,... ...Performs advanced host and network forensics and malware analysis; Investigates and...DigitalHourly payWork experience placementWork at officeImmediate startVisa sponsorshipWork visaFlexible hours- A leading global food retailer is seeking a Security Engineering Manager to safeguard their technology environment in Chicago. This role involves enforcing security policies, managing incident responses, and collaborating with IT and business teams. The ideal candidate...Flexible hours
$139.12k - $208.68k
A leading grocery retailer is seeking a Security Engineering Manager in Chicago to safeguard its technology environment. This role handles security policies, manages the incident response plan, and investigates potential threats. Candidates should have at least 10 years...Flexible hours- ...Reporting to the Threat Intelligence Product Manager, the Manager of Intelligence Analysis is responsible for running the daily operations of the... ...problem‑solving techniques. Malware analysis, digital forensics, and incident response skills. Strong knowledge of how phishing...DigitalRemote jobContract workLocal area
$141.96k - $177.44k
...Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald's... ...scale. Accountabilities & Responsibilities: Own the enterprise reference... ...configurations, lifecycle management, and deprecation strategies... ...365 (monitoring/telemetry, incident/problem management patterns,...DigitalLocal areaFlexible hoursShift work$108.08k - $192.46k
...Manager II Choosing Capgemini means choosing a company where you... ...' unique requirements. Responsible for software-specific design... ...team to eliminate recurring incidents and to minimize the impact of... ...accelerate their dual transition to a digital and sustainable world, while...DigitalPermanent employmentFull timeContract workLocal areaRemote workRelocation2 days per week3 days per week$115k - $125k
...Responsibilities Are you a seasoned General Manager with a passion for luxury residential property management and possess... ...i.e., memos, letters, insurance incident reports, etc. Financials:... ...automation, CRM systems, and digital communication tools. Certified...Digital$150k - $170k
...Description The Microsoft 365 Platform Manager owns the definition,... ...role partners closely with Digital Workplace leadership, Cyber Security... ...intentional, scalable, and responsible use of Microsoft 365... ...365 administration. Routine incident management or operational escalation...DigitalFull time- ...empower and facilitate trust for a digital-first world. Today,... ...handle crucial security and PR incidents daily. Champion Outtake'... ...how we can transform incident response and brand protection on a global... ...remains the premier incident management and brand protection platform...DigitalWork at officeImmediate startFlexible hours
$153.32k - $192.46k
...Manager Choosing Capgemini means choosing a company where you... ...technical lead and mentor. Responsible for software-specific design... ...team to eliminate recurring incidents and to minimize the impact of... ...accelerate their dual transition to a digital and sustainable world, while...DigitalPermanent employmentFull timeContract workLocal areaRemote workRelocation2 days per week3 days per week$75k - $85k
...heartbeat of our community—responsible for the daily operations, staff... ...consistency in classroom management and lesson implementation... ...Oversee emergency drills, incident reports, and daily health/safety... ...staff Organize and manage digital files across shared drives...DigitalRelocation package- ...If the position includes overnight responsibilities, this role may be required to respond to... ...when violations occur. Utilize our digital guest registry system to create room reservations... ...needs of the families Complete incident reports and submit within 24 hours of...DigitalWork experience placementWork at officeShift workNight shift
- ...AI-powered identity platform manages and governs human and non-human... ...Saviynt to safeguard their digital assets, drive operational efficiency... .... This person is ultimately responsible for the entire enterprise... ...& Handling Policy Incident Response Policy/Procedures...Digital
$148k - $197.45k
...client will be mandatory. Responsibilities: Operations:... ...Develop and maintain Crisis Management/Disaster Plans. Implement... ...Outage/Escalation/Missed SLA incidents. Implement and execute automation... ...Preferred Skills: Digital Transformation experience leveraging...DigitalTemporary workWork at officeRemote workFlexible hours$76.5k - $89k
...key role in the assessment, staffing and management of outside events. Essential... ...life-changing worship, special events and digital assets # Provide video leadership and... ...and online services Other Key Responsibilities ~ Demonstrates exceptional technical...DigitalTemporary workCasual workImmediate startMonday to FridayFlexible hoursDay shiftAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Digital Forensics & Incident Response (DFIR) Manager. Be the first to apply!
- hvac manager Chicago, IL
- pharma manager Chicago, IL
- translation manager Chicago, IL
- remote coding manager Chicago, IL
- overnight manager Chicago, IL
- infection prevention manager Chicago, IL
- global labeling manager Chicago, IL
- manager corporate partnerships Chicago, IL
- programmatic manager Chicago, IL
- full time manager Chicago, IL


