Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Digital Forensics & Incident Response (DFIR) Manager

RSM US LLP

Dfir Manager

The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Manager serves as both incident commander and engagement leader, overseeing multiple complex matters while aligning technical, legal, executive, and insurance workstreams.

This role requires strong incident command authority, deep ransomware experience, and the ability to guide cross-functional response efforts at the executive level. Managers maintain oversight across engagements, provide escalation guidance to Supervisors, and ensure investigative quality, consistency, and defensibility across the practice.

The DFIR Manager is accountable not only for technical excellence, but also for engagement delivery, stakeholder alignment, and operational leadership during crisis response.

Responsibilities:

  • Serve as incident commander during high-severity events, particularly ransomware and enterprise-scale breaches.
  • Oversee multiple concurrent engagements, ensuring quality, consistency, and appropriate resource allocation.
  • Define investigative strategy and escalation thresholds for complex incidents.
  • Align technical response with legal, regulatory, insurance, and executive considerations.
  • Review and approve investigative findings, containment validation, and executive reporting.
  • Act as senior advisor to client executives, legal counsel, and cyber insurers.
  • Provide guidance to Supervisors on advanced investigative decisions and complex threat actor scenarios.
  • Maintain executive-level communication cadence during incidents.
  • Support development of standardized methodologies, playbooks, and quality controls across the practice.
  • Mentor Supervisors and Consultants in both technical depth and client leadership.
  • Participate in on-call rotation and provide oversight during critical incidents.

Preferred Qualifications:

Expertise in all areas is not required; however, candidates should demonstrate strong foundational knowledge and a willingness to continuously learn and expand their capabilities.

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.
  • Proven experience leading enterprise-scale ransomware and breach investigations.
  • Deep understanding of:
    • Threat actor operations and ransomware tradecraft
    • Identity compromise and domain-level persistence
    • Cloud and hybrid environment incident response
    • Data exfiltration risk assessment and reporting
  • Strong hands-on familiarity with EDR platforms, SIEM technologies, and forensic toolsets.
  • Demonstrated ability to manage multiple high-pressure engagements simultaneously.
  • Experience coordinating with legal counsel, cyber insurance carriers, and executive leadership.
  • Strong executive presence and crisis communication ability.
  • Experience mentoring and developing DFIR leaders.
  • Certifications such as GCFA, GCIH, CISSP, OSCP, or equivalent preferred.
  • Willingness to participate in on-call rotation.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Digital Forensics & Incident Response (DFIR) Manager in Chicago, IL vacancy
  • $107k - $214.5k

     ...nowhere like RSM. The RSM Cyber Response team leads organizations through some...  ...consequential cyber events. The DFIR Manager serves as both incident commander and engagement leader, overseeing...  ...platforms, SIEM technologies, and forensic toolsets. Demonstrated ability... 
    Digital
    Work experience placement
    Internship
    Local area

    RSM Global

    Chicago, IL
    3 days ago
  •  ...Overview A leading tech-enabled digital intelligence, investigation, and risk advisory firm is looking to appoint a Senior Associate, Digital Forensics and Incident Response (DFIR). The firm is seeking a dynamic new team member to help grow its Digital Forensics... 
    Digital
    Chicago, IL
    2 days ago
  • $87.7k - $164k

     ...Young Oman is seeking a Cyber Triage and Forensics Incident Analyst based in Chicago, IL. This role...  ...with a dedicated team to enhance digital security practices. The ideal candidate...  ...over 5 years of experience in incident response, with a focus on digital forensics. A robust... 
    Digital
    Flexible hours

    Ernst & Young Oman

    Chicago, IL
    1 day ago
  • $112k - $139k

     ...A national law firm is seeking a SOC/Incident Report Engineer for its Chicago office. This hybrid position involves detecting and...  ...to cybersecurity incidents, focusing on threat detection and digital forensics. The ideal candidate will have solid experience in a... 
    Digital
    Work at office

    Benesch

    Chicago, IL
    2 days ago
  • $130k - $152.5k

     ...Senior Associate/Cybersecurity & Incident Response (Forensic Services Practice) Boston, MA, United...  ...Our two main services – economic and management consulting – are delivered by practice...  ...; Performing forensic analysis of digital information using standard computer forensics... 
    Digital
    Work at office
    Local area
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    4 days ago
  • $140k - $170k

     ...Associate Principal/Cybersecurity & Incident Response Boston, MA, United States...  ...services – economic and management consulting – are delivered...  ...Position Overview CRA's Forensic Services practice supports...  ...Performing forensic analysis of digital information using standard... 
    Digital
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    2 days ago
  • $100k - $126.5k

     ...Consulting Associate/Cybersecurity & Incident Response CRA's Forensic Services practice supports companies...  ...have majored in Computer Science, Digital Forensics, Information Security, and...  ...collaboratively with a team, effectively manage their time, prioritize tasks, and... 
    Digital
    Work at office
    Work from home
    3 days per week

    Charles River Associates

    Chicago, IL
    4 days ago
  • $115k - $130k

     ...technology company is seeking an IT Security Engineer to enhance security for digital assets. In this role, you will design and implement security controls, monitor security alerts, and lead incident response. Ideal candidates possess a Bachelor's degree and 4–7 years of... 
    Digital
    Full time
    Remote work

    Redwood Logistics

    Chicago, IL
    2 days ago
  • Flynaut LLC. is seeking a Cybersecurity Analyst in Chicago, IL to protect clients’ digital assets. As part of the Cybersecurity team, you will monitor security events, conduct incident response, and assist clients in compliance with security frameworks. Experience with... 
    Digital

    Flynaut LLC.

    Chicago, IL
    18 hours ago
  • $115k - $130k

     ...an IT Security Engineer to enhance security controls within digital environments. This remote role involves technical design, implementation...  ...Computer Science or Information Security and solid skills in incident response, security technologies, and scripting are welcomed. The... 
    Digital
    Remote work

    Redwood Logistics

    Chicago, IL
    2 days ago
  • $100k - $140k

     ...success, resulting in A&M's Forensic Technology Services being a...  ...is comprised of experienced digital forensics, eDiscovery, data...  ...electronic discovery and disclosure management, digital forensics, forensic...  ...analytics, cyber risk and incident response, privacy, information... 
    Digital
    Part time
    Flexible hours

    Alvarez & Marsal

    Chicago, IL
    2 days ago
  •  ...consider a career in Advisory. We are currently seeking a Manager, Incident Response to join our Advisory practice. Responsibilities...  ...facilitation, and cross functional stakeholder management (legal, forensics, privacy, communications, and leadership) during high... 
    Work experience placement
    H1b
    Local area

    KPMG

    Chicago, IL
    4 days ago
  •  ...Job Title: Threat and Incident Response Analyst Location: Chicago, IL Contract Duration...  .... Collect, analyze, and preserve digital evidence related to security incidents....  ...monitoring. Work with the Bank's Managed Security Services Provider as well as... 
    Digital
    Contract work

    Javen Technologies

    Chicago, IL
    2 days ago
  •  ...Incident Response Analyst (AI Training) About the Role We're partnering with leading AI...  ...hands-on experience in SOC operations and digital investigations will directly shape how...  ...with threat hunting, digital forensics, or malware analysis Familiarity with... 
    Digital
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Worldwide
    Flexible hours

    Alignerr

    Chicago, IL
    5 days ago
  •  ...families to continue treatments and manage the necessary equipment in...  ...Finally, La Rabida provides forensic and treatment services for...  ...Ambulatory and Provider Services is responsible for supervising frontline...  ...of new workflows, digital health tools, or clinical services... 
    Digital
    Work experience placement

    La Rabida Children's Hospital

    Chicago, IL
    2 days ago
  • $132.5k - $338.3k

     ...global Cyber Investigation and Forensic Response (CIFR) practice is at the...  ...most consequential cyber incidents. Within CIFR, our Cyber Recovery...  ...Minimum 5 years Management and Client Facing experience...  ...organizations build their digital core, optimize their operations... 
    Digital
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Chicago, IL
    4 days ago
  •  ...recommendations when needed. Manages field engineers, provide...  ...following duties. Duties and Responsibilities include the following. Other...  ...construction management or forensic engineering Certificates and...  ...and/or Cell phone Ladder Digital level Tape measure Rope and... 
    Digital
    For contractors
    Work experience placement
    Work at office

    Upcoresolutions

    Chicago, IL
    18 hours ago
  • $139.12k - $208.68k

     ...A leading grocery retailer is seeking a Security Engineering Manager in Chicago to safeguard its technology environment. This role handles security policies, manages the incident response plan, and investigates potential threats. Candidates should have at least 10 years... 
    Flexible hours

    ViziRecruiter

    Chicago, IL
    2 days ago
  • $108k - $135k

     ...Cyber Security Incident Response Analyst II At Early Warning, we've powered and protected the...  ...investigative analysis activities for a variety of digital devices, computers, storage media,...  ...Performs advanced host and network forensics and malware analysis; Investigates and... 
    Digital
    Hourly pay
    Work experience placement
    Work at office
    Immediate start
    Visa sponsorship
    Work visa
    Flexible hours

    Early Warning Services

    Chicago, IL
    3 days ago
  • A leading global food retailer is seeking a Security Engineering Manager to safeguard their technology environment in Chicago. This role involves enforcing security policies, managing incident responses, and collaborating with IT and business teams. The ideal candidate... 
    Flexible hours

    ViziRecruiter,LLC.

    Chicago, IL
    4 days ago
  •  ...Reporting to the Threat Intelligence Product Manager, the Manager of Intelligence Analysis is responsible for running the daily operations of the...  ...problem‑solving techniques. Malware analysis, digital forensics, and incident response skills. Strong knowledge of how... 
    Digital
    Contract work
    Local area
    Remote work

    COFENSE

    Chicago, IL
    5 days ago
  • $108.08k - $192.46k

     ...Manager II Choosing Capgemini means choosing a company where you...  ...' unique requirements. Responsible for software-specific design...  ...team to eliminate recurring incidents and to minimize the impact of...  ...accelerate their dual transition to a digital and sustainable world, while... 
    Digital
    Permanent employment
    Full time
    Contract work
    Local area
    Remote work
    Relocation
    2 days per week
    3 days per week

    Capgemini

    Chicago, IL
    4 days ago
  • $115k - $125k

     ...Responsibilities Property Oversight: Ensure that the residential community...  ...regulations to effectively manage the property including construction...  ..., memos, letters, insurance incident reports, etc. Financials:...  ..., CRM systems, and digital communication tools. Certified... 
    Digital

    Related Company

    Chicago, IL
    1 day ago
  • $153.32k - $192.46k

     ...Manager Choosing Capgemini means choosing a company where you...  ...technical lead and mentor. Responsible for software-specific design...  ...team to eliminate recurring incidents and to minimize the impact of...  ...accelerate their dual transition to a digital and sustainable world, while... 
    Digital
    Permanent employment
    Full time
    Contract work
    Local area
    Remote work
    Relocation
    2 days per week
    3 days per week

    Capgemini

    Chicago, IL
    7 days ago
  • $150k - $170k

     ...Description The Microsoft 365 Platform Manager owns the definition,...  ...role partners closely with Digital Workplace leadership, Cyber Security...  ...intentional, scalable, and responsible use of Microsoft 365...  ...365 administration. Routine incident management or operational escalation... 
    Digital
    Full time

    UL Solutions

    Chicago, IL
    1 day ago
  • $103.27k - $206.54k

     ...KPMG is currently seeking a Manager, Forensic Technology to join our...  ...Advisory Services practice. Responsibilities: Manage and advise...  ...platforms to uncover digital evidence Consult with...  ...line Digital Forensics and Incident Response (DFIR) tools and techniques to... 
    Digital
    H1b
    Local area

    KPMG

    Chicago, IL
    2 days ago
  •  ...empower and facilitate trust for a digital-first world. Today,...  ...handle crucial security and PR incidents daily. Champion Outtake'...  ...how we can transform incident response and brand protection on a global...  ...remains the premier incident management and brand protection platform... 
    Digital
    Work at office
    Immediate start
    Flexible hours

    Outtake

    Chicago, IL
    3 days ago
  • $59.15k - $106.93k

     ...opportunity for a Project Manager I (PM) who will work alongside...  ...nationwide. Primary Responsibilities Independently lead project...  ...smarter, more efficient digital and mission innovations. Headquartered...  ...enforcement and report the incident to the U.S. Federal Trade... 
    Digital
    Contract work
    For subcontractor
    Local area
    Immediate start
    Work from home

    Leidos

    Chicago, IL
    5 days ago
  •  ...Description The Customer Success Manager, Senior Manager is a highly...  ...individual contributor responsible for driving quantifiable business...  ...device companies to support digital health initiatives, regulatory...  ...Escalation Play and Case Oversight & Incident Management processes when... 
    Digital
    Work at office
    Flexible hours
    3 days per week

    Israelvcforum

    Chicago, IL
    1 day ago
  • $12 per day

     ...Summary & Objectives The Senior Marketing Manager will spearhead the development and...  ...’s specialized services in cyber incident response, digital asset security, and crypto investigations...  ...incident response and cryptocurrency forensics and investigations. Cultivate and... 
    Digital
    Local area
    Immediate start
    Remote work
    Flexible hours

    DigitalMint

    Chicago, IL
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Digital Forensics & Incident Response (DFIR) Manager. Be the first to apply!