Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Digital Forensics & Incident Response (DFIR) Manager

$107k - $214.5k

RSM US LLP

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You'll find an environment that inspires and empowers you to thrive both personally and professionally. There's no one like you and that's why there's nowhere like RSM.

The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Manager serves as both incident commander and engagement leader, overseeing multiple complex matters while aligning technical, legal, executive, and insurance workstreams.

This role requires strong incident command authority, deep ransomware experience, and the ability to guide cross-functional response efforts at the executive level. Managers maintain oversight across engagements, provide escalation guidance to Supervisors, and ensure investigative quality, consistency, and defensibility across the practice.

The DFIR Manager is accountable not only for technical excellence, but also for engagement delivery, stakeholder alignment, and operational leadership during crisis response.

Responsibilities:

  • Serve as incident commander during high-severity events, particularly ransomware and enterprise-scale breaches.
  • Oversee multiple concurrent engagements, ensuring quality, consistency, and appropriate resource allocation.
  • Define investigative strategy and escalation thresholds for complex incidents.
  • Align technical response with legal, regulatory, insurance, and executive considerations.
  • Review and approve investigative findings, containment validation, and executive reporting.
  • Act as senior advisor to client executives, legal counsel, and cyber insurers.
  • Provide guidance to Supervisors on advanced investigative decisions and complex threat actor scenarios.
  • Maintain executive-level communication cadence during incidents.
  • Support development of standardized methodologies, playbooks, and quality controls across the practice.
  • Mentor Supervisors and Consultants in both technical depth and client leadership.
  • Participate in on-call rotation and provide oversight during critical incidents.

Preferred Qualifications:

Expertise in all areas is not required; however, candidates should demonstrate strong foundational knowledge and a willingness to continuously learn and expand their capabilities.

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.
  • Proven experience leading enterprise-scale ransomware and breach investigations.
  • Deep understanding of:
    • Threat actor operations and ransomware tradecraft
    • Identity compromise and domain-level persistence
    • Cloud and hybrid environment incident response
    • Data exfiltration risk assessment and reporting
  • Strong hands-on familiarity with EDR platforms, SIEM technologies, and forensic toolsets.
  • Demonstrated ability to manage multiple high-pressure engagements simultaneously.
  • Experience coordinating with legal counsel, cyber insurance carriers, and executive leadership.
  • Strong executive presence and crisis communication ability.
  • Experience mentoring and developing DFIR leaders.
  • Certifications such as GCFA, GCIH, CISSP, OSCP, or equivalent preferred.
  • Willingness to participate in on-call rotation.

At RSM, we offer a competitive benefits and compensation package for all our people.We offer flexibility in your schedule, empowering you to balance life's demands, while also maintaining your ability to serve clients.Learn more about our total rewards at

All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race; color; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender; sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the US uniformed service; US Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law.

Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership.RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at View phone number on click.appcast.io or send us an email at View email address on click.appcast.io.

RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future (i.e. F-1 visa holders). If you are a recent U.S. college / university graduate possessing 1-2 years of progressive and relevant work experience in a same or similar role to the one for which you are applying, excluding internships, you may be eligible for hire as an experienced associate.

RSM will consider for employment qualified applicants with arrest or conviction records. For those living in California or applying to a position in California, please click here for additional information.

At RSM, an employee's pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range.

Compensation Range: $107,000 - $214,500

Individualsselected for this role will be eligible for a discretionary bonus based on firm and individual performance.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Digital Forensics & Incident Response (DFIR) Manager in Chicago, IL vacancy
  •  ...Dfir Manager The RSM Cyber Response team leads organizations through some of their most consequential cyber...  .... The DFIR Manager serves as both incident commander and engagement leader, overseeing...  ...platforms, SIEM technologies, and forensic toolsets. Demonstrated ability... 
    Digital

    RSM

    Chicago, IL
    3 days ago
  •  ...TITLE: Senior Associate PRACTICE/CORPORATE: Digital Forensics & Incident Response LOCATION: TBD REPORTS TO: Managing Director FLSA: Exempt DATE COMPLETED/...  ...grow our Digital Forensics & Incident Response (DFIR) services. Prescient has built a world class... 
    Digital

    Prescient

    Chicago, IL
    13 days ago
  •  ...IL. This role involves designing scalable tools for digital investigations and incident response, using expertise in cybersecurity, software engineering...  ...automation tools and maintaining secure data management workflows. An excellent opportunity in a fast-paced environment... 
    Digital

    Andersch Ag

    Chicago, IL
    2 days ago
  • $87.7k - $164k

     ...Young Oman is seeking a Cyber Triage and Forensics Incident Analyst based in Chicago, IL. This role...  ...with a dedicated team to enhance digital security practices. The ideal candidate...  ...over 5 years of experience in incident response, with a focus on digital forensics. A robust... 
    Digital
    Flexible hours

    Ernst & Young Oman

    Chicago, IL
    16 hours ago
  • $112k - $139k

    A national law firm is seeking a SOC/Incident Report Engineer for its Chicago office. This hybrid position involves detecting and...  ...to cybersecurity incidents, focusing on threat detection and digital forensics. The ideal candidate will have solid experience in a... 
    Digital
    Work at office

    Benesch, Friedlander, Coplan & Aronoff

    Chicago, IL
    1 day ago
  • $130k - $152.5k

     ...Senior Associate/Cybersecurity & Incident Response (Forensic Services Practice) Boston, MA, United...  ...Our two main services – economic and management consulting – are delivered by practice...  ...; Performing forensic analysis of digital information using standard computer forensics... 
    Digital
    Work at office
    Local area
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    3 days ago
  • $140k - $170k

     ...Associate Principal/Cybersecurity & Incident Response Boston, MA, United States...  ...services – economic and management consulting – are delivered...  ...Position Overview CRA's Forensic Services practice supports...  ...Performing forensic analysis of digital information using standard... 
    Digital
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    1 day ago
  • $100k - $126.5k

     ...Consulting Associate/Cybersecurity & Incident Response CRA's Forensic Services practice supports companies...  ...have majored in Computer Science, Digital Forensics, Information Security, and...  ...collaboratively with a team, effectively manage their time, prioritize tasks, and... 
    Digital
    Work at office
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    3 days ago
  • Flynaut LLC. is seeking a Cybersecurity Analyst in Chicago, IL to protect clients’ digital assets. As part of the Cybersecurity team, you will monitor security events, conduct incident response, and assist clients in compliance with security frameworks. Experience with... 
    Digital

    Flynaut LLC.

    Chicago, IL
    4 days ago
  • $100k - $140k

     ...success, resulting in A&M's Forensic Technology Services being a...  ...is comprised of experienced digital forensics, eDiscovery, data...  ...electronic discovery and disclosure management, digital forensics, forensic...  ...analytics, cyber risk and incident response, privacy, information... 
    Digital
    Part time
    Flexible hours

    Alvarez & Marsal

    Chicago, IL
    1 day ago
  • $115k - $130k

     ...technology company is seeking an IT Security Engineer to enhance security for digital assets. In this role, you will design and implement security controls, monitor security alerts, and lead incident response. Ideal candidates possess a Bachelor's degree and 4-7 years of... 
    Digital
    Remote job
    Full time

    Redwood Logistics

    Chicago, IL
    4 days ago
  •  ...Job Title: Threat and Incident Response Analyst Location: Chicago, IL Contract Duration...  .... Collect, analyze, and preserve digital evidence related to security incidents....  ...monitoring. Work with the Bank's Managed Security Services Provider as well as... 
    Digital
    Contract work

    Javen Technologies

    Chicago, IL
    1 day ago
  •  ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI...  ...hands-on experience in SOC operations and digital investigations will directly shape how...  ...with threat hunting, digital forensics, or malware analysis Familiarity with... 
    Digital
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Worldwide
    Flexible hours

    Alignerr

    Chicago, IL
    4 days ago
  •  ...families to continue treatments and manage the necessary equipment in...  ...Finally, La Rabida provides forensic and treatment services for...  ...Ambulatory and Provider Services is responsible for supervising frontline...  ...of new workflows, digital health tools, or clinical services... 
    Digital
    Work experience placement

    La Rabida Children's Hospital

    Chicago, IL
    1 day ago
  •  ...recommendations when needed. Manages field engineers, provide...  ...following duties. Duties and Responsibilities include the following....  ...construction management or forensic engineering Certificates...  ...Phone and/or Cell phone Digital camera Ladder Moisture... 
    Digital
    For contractors
    Work experience placement
    Work at office

    Upcoresolutions

    Chicago, IL
    8 days ago
  • $108k - $135k

     ...Cyber Security Incident Response Analyst II At Early Warning, we've powered and protected the...  ...investigative analysis activities for a variety of digital devices, computers, storage media,...  ...Performs advanced host and network forensics and malware analysis; Investigates and... 
    Digital
    Hourly pay
    Work experience placement
    Work at office
    Immediate start
    Visa sponsorship
    Work visa
    Flexible hours

    Early Warning Services

    Chicago, IL
    2 days ago
  • A leading global food retailer is seeking a Security Engineering Manager to safeguard their technology environment in Chicago. This role involves enforcing security policies, managing incident responses, and collaborating with IT and business teams. The ideal candidate... 
    Flexible hours

    ViziRecruiter,LLC.

    Chicago, IL
    3 days ago
  • $139.12k - $208.68k

    A leading grocery retailer is seeking a Security Engineering Manager in Chicago to safeguard its technology environment. This role handles security policies, manages the incident response plan, and investigates potential threats. Candidates should have at least 10 years... 
    Flexible hours

    ViziRecruiter,LLC.

    Chicago, IL
    16 hours ago
  •  ...Reporting to the Threat Intelligence Product Manager, the Manager of Intelligence Analysis is responsible for running the daily operations of the...  ...problem‑solving techniques. Malware analysis, digital forensics, and incident response skills. Strong knowledge of how phishing... 
    Digital
    Remote job
    Contract work
    Local area

    COFENSE

    Chicago, IL
    4 days ago
  • $141.96k - $177.44k

     ...Down on the 3Ds (Delivery, Digital and Drive Thru). McDonald's...  ...scale. Accountabilities & Responsibilities: Own the enterprise reference...  ...configurations, lifecycle management, and deprecation strategies...  ...365 (monitoring/telemetry, incident/problem management patterns,... 
    Digital
    Local area
    Flexible hours
    Shift work

    McDonald's Corporation

    Chicago, IL
    3 days ago
  • $108.08k - $192.46k

     ...Manager II Choosing Capgemini means choosing a company where you...  ...' unique requirements. Responsible for software-specific design...  ...team to eliminate recurring incidents and to minimize the impact of...  ...accelerate their dual transition to a digital and sustainable world, while... 
    Digital
    Permanent employment
    Full time
    Contract work
    Local area
    Remote work
    Relocation
    2 days per week
    3 days per week

    Capgemini

    Chicago, IL
    3 days ago
  • $115k - $125k

     ...Responsibilities Are you a seasoned General Manager with a passion for luxury residential property management and possess...  ...i.e., memos, letters, insurance incident reports, etc. Financials:...  ...automation, CRM systems, and digital communication tools. Certified... 
    Digital

    Related Company

    Chicago, IL
    1 day ago
  • $150k - $170k

     ...Description The Microsoft 365 Platform Manager owns the definition,...  ...role partners closely with Digital Workplace leadership, Cyber Security...  ...intentional, scalable, and responsible use of Microsoft 365...  ...365 administration. Routine incident management or operational escalation... 
    Digital
    Full time

    UL Solutions

    Chicago, IL
    16 hours ago
  •  ...empower and facilitate trust for a digital-first world. Today,...  ...handle crucial security and PR incidents daily. Champion Outtake'...  ...how we can transform incident response and brand protection on a global...  ...remains the premier incident management and brand protection platform... 
    Digital
    Work at office
    Immediate start
    Flexible hours

    Outtake

    Chicago, IL
    2 days ago
  • $153.32k - $192.46k

     ...Manager Choosing Capgemini means choosing a company where you...  ...technical lead and mentor. Responsible for software-specific design...  ...team to eliminate recurring incidents and to minimize the impact of...  ...accelerate their dual transition to a digital and sustainable world, while... 
    Digital
    Permanent employment
    Full time
    Contract work
    Local area
    Remote work
    Relocation
    2 days per week
    3 days per week

    Capgemini

    Chicago, IL
    1 day ago
  • $75k - $85k

     ...heartbeat of our community—responsible for the daily operations, staff...  ...consistency in classroom management and lesson implementation...  ...Oversee emergency drills, incident reports, and daily health/safety...  ...staff Organize and manage digital files across shared drives... 
    Digital
    Relocation package

    The Goddard School of Chicago (Roscoe Village), IL

    Chicago, IL
    3 days ago
  •  ...If the position includes overnight responsibilities, this role may be required to respond to...  ...when violations occur. Utilize our digital guest registry system to create room reservations...  ...needs of the families Complete incident reports and submit within 24 hours of... 
    Digital
    Work experience placement
    Work at office
    Shift work
    Night shift

    Ronald McDonald House Chicagoland & Northwest Indiana

    Chicago, IL
    2 days ago
  •  ...AI-powered identity platform manages and governs human and non-human...  ...Saviynt to safeguard their digital assets, drive operational efficiency...  .... This person is ultimately responsible for the entire enterprise...  ...& Handling Policy Incident Response Policy/Procedures... 
    Digital

    Saviynt

    Chicago, IL
    3 days ago
  • $148k - $197.45k

     ...client will be mandatory. Responsibilities: Operations:...  ...Develop and maintain Crisis Management/Disaster Plans. Implement...  ...Outage/Escalation/Missed SLA incidents. Implement and execute automation...  ...Preferred Skills:   Digital Transformation experience leveraging... 
    Digital
    Temporary work
    Work at office
    Remote work
    Flexible hours

    The Nippon Telegraph and Telephone Corporation (NTT)

    Chicago, IL
    1 day ago
  • $76.5k - $89k

     ...key role in the assessment, staffing and management of outside events.   Essential...  ...life-changing worship, special events and digital assets # Provide video leadership and...  ...and online services   Other Key Responsibilities ~ Demonstrates exceptional technical... 
    Digital
    Temporary work
    Casual work
    Immediate start
    Monday to Friday
    Flexible hours
    Day shift
    Afternoon shift

    Christ Church of Oak Brook

    Oak Brook, IL
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Digital Forensics & Incident Response (DFIR) Manager. Be the first to apply!