Senior Director, Digital Forensics and Incident Response
BlueVoyant
Job Description
Job Description
Position: Senior Director, Digital Forensics & Incident Response
Location: Remote, US
Work Authorization: US Citizenship Required
BlueVoyant is seeking a Senior Director, DFIR to lead high-impact cyber investigations and act as incident commander during complex, high-pressure security incidents.
This is a client-facing leadership role responsible for guiding organizations through critical moments—from initial response through investigation, containment, and recovery—while advising executives, legal counsel, and technical teams.
What You’ll Do:- Act as incident commander for complex DFIR engagements end-to-end
- Serve as the primary client lead , advising executives, legal counsel, insurers, and stakeholders
- Lead investigations across ransomware, BEC, cloud/identity compromise, insider threat, and advanced attacks
- Direct forensic analysis across endpoints, cloud, identity, SaaS, email, and network environments
- Translate technical findings into clear business risk and remediation guidance
- Lead executive briefings, client updates, and post-incident reviews
- Manage multiple concurrent incidents in fast-paced, high-pressure environments
- Mentor and develop DFIR consultants and technical teams
- Support incident readiness, tabletop exercises, and client growth initiative.
- 3–5 years of hands-on DFIR experience in real-world incidents
- 6–10 years in client-facing consulting, incident response, or cyber advisory roles
- Proven experience as an incident commander or senior DFIR lead
- Strong background in ransomware, cloud/identity compromise, and complex attack investigations
- Experience working directly with executives, legal counsel, insurers, and technical teams
- Ability to manage multiple stakeholders, workstreams, and timelines under pressure
- Leadership experience mentoring or managing technical teams
- Strong knowledge across endpoint, cloud, identity, SaaS, and network forensics
- Experience with tools such as EnCase, FTK, Magnet AXIOM, Velociraptor, Splunk, Sentinel, CrowdStrike (or similar)
- Familiarity with Microsoft 365, Entra ID, Azure, AWS, Okta, Google Workspace
- Understanding of attacker tradecraft, including persistence, lateral movement, and data exfiltration
- Working knowledge of KQL, SPL, SQL, PowerShell, Python, or Bash
- Exceptional communication skills—able to translate technical issues into business impact
- Strong judgment in high-stress, ambiguous environments
- Composed, credible, and client-focused under pressure
- Collaborative leader with a focus on quality, mentorship, and outcomes
- Experience working with breach counsel, insurers, or regulators
- Incident readiness, tabletop, or IR planning experience
- Certifications such as CISSP, GCFA, GCIH, GCFE, GNFA, OSCP
Bachelor’s degree preferred (Cybersecurity, Computer Science, DFIR, or related), or equivalent professional experience.
Why BlueVoyant?- Work alongside experienced DFIR leaders and experts , including former government cyber professionals and industry veterans.
- Lead high-impact, global cyber investigations , supporting clients through critical, business-defining incidents
- Gain exposure to complex environments, executive stakeholders, and advanced threat scenarios across industries
- Join a global, mission-driven cybersecurity company defending organisations worldwide with cutting-edge data, technology, and expertise
- Competitive compensation and comprehensive benefits package , with support for wellbeing, development, and career growth
About BlueVoyant
BlueVoyant is an AI-driven cybersecurity company dedicated to standing between our customers and cyber threats. By combining human, artificial, and proprietary intelligence, we deliver a unified solution that protects every organization’s network, identities, vendors, and digital footprints as a single attack surface. The company’s award-winning Microsoft Security expertise helps organizations maximize their security investments while reducing risk and ensuring compliance.
Led by CEO, John Hernandez, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and technologies.
Founded in 2017 by Fortune 500 executives, including Chairman of the Board, Jim Rosenthal, Vice Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, San Francisco, London, Budapest, and Latin America and is committed to building a workplace where talented people are empowered to do their best work in the fight against global cyber threats..
All employees must be authorized to work in the United States of America. BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, BlueVoyant complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. Disclaimer: Please note that pursuant to contractual requirements and applicable law, for employees to perform work on some of the company’s federal contracts, U.S. citizenship is required. Accordingly, an employee’s ability to perform work on such contracts is contingent upon the company’s verification of the employee’s citizenship status.
#LI-Remote
Important Information for Applicants: BlueVoyant uses AI-assisted tools within our applicant tracking system to help identify candidates whose experience and skills best match the requirements of a role. This technology provides hiring teams with added insights to support fair and efficient hiring decisions. All applications are reviewed by a member of our hiring team, and final hiring decisions are made by humans, not AI. By submitting your application, you acknowledge that AI tools may assist in the evaluation of your resume as part of the recruitment process.
Interview Expectations: As part of our interview process, we assess your experience through real-time discussion, so we expect responses to be your own. While we embrace the use of AI within our business and recruitment process, we do not permit its use during interviews. Any suspected use of AI during an interview will be challenged, and this may include the use of detection tools.
BlueVoyant Candidate Privacy Notice: To understand how we secure and manage your personal data upon submitting a job application, please see our Candidate Privacy Notice, which can be found here - Candidate Privacy Notice
Powered by JazzHR
jflLN1jXrN
- ...Job Description Job Description Position: Senior Director, Digital Forensics & Incident Response Location: Remote, US Work Authorization: US Citizenship Required BlueVoyant is seeking a Senior Director, DFIR to lead high-impact cyber investigations and...SeniorWork at officeLocal areaRemote workWorldwide
- ...DeepSeas LLC is seeking a Senior SOC Analyst (L2) to drive high‑severity investigations... .... You will lead threat hunting, forensics, and detection engineering efforts to deliver... ...the United States. You will influence incident response across multiple client environments and...SeniorRemote work
- ...Owning the end-to-end incident response process, the full-time Senior Incident Response Analyst will manage tier-1 and tier-2 incidents, conduct forensic investigations, and automate evidence collection... ...in incident response and digital forensics Proven ownership of the...SeniorFull timeRemote work
- BlueVoyant is seeking a Senior Director, Digital Forensics & Incident Response to spearhead cyber investigations in a client-facing leadership role. This position requires managing complex security incidents while advising executives and legal teams. The ideal candidate...SeniorRemote job
- ...Senior Incident Response Security Consultant role within Mandiant, Google Cloud, based in the United States. You will lead end-to-end incident investigations, forensics, threat hunting, and malware triage across diverse environments, coordinating with clients and internal...SeniorRemote job
- GoDaddy is seeking a Senior Security Engineer to lead incident response and forensics across Windows, macOS, Linux, and AWS. The role focuses on automating security operations and leveraging AI-driven capabilities to improve detection and response while mentoring team...SeniorRemote job
- Forensic Focus is seeking a Senior Incident Response Consultant to lead client-facing investigations across cloud, endpoint, and network environments. You will conduct threat hunting, malware triage, containment, and crisis management while documenting attacker TTPs and...SeniorRemote job
$138k - $200k
...customer teams to investigate and contain incidents.Recognize and codify attacker Tools,... ...current and future investigations.Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.Minimum qualifications:...SeniorWork at officeRemote work$138k - $200k
...customer teams to investigate and contain incidents.Recognize and codify attacker Tools,... ...current and future investigations.Conduct host forensics, network forensics, log analysis, and malware triage in support of incident response investigations.Minimum qualifications:...SeniorWork at officeRemote work- ...Senior Consultant, Digital Forensic and Incident Response (DFIR) (Remote) Remote, USA / Exempt Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to cyber incidents such as ransomware, email compromise, malware, data...SeniorFull timeLocal areaRemote workFlexible hoursWeekend work
$190k - $260k
Senior Incident Response & Digital Forensics Analyst Location New York Business Area Legal, Compliance, and Risk Ref # 10054249 Description & Requirements Cyber Security Operations Center — Threat Hunting, Intelligence & Incident ResponseThe RoleBloomberg...SeniorTemporary workFor contractorsWork experience placementImmediate startRemote workShift work$130k - $152.5k
...Position OverviewCRA’s Forensic Services practice... ...contribute to the team in this Senior Associate role may... ...of, and in response to, data security matters... ...detection, threat analysis, incident response and malware analysis... ...forensic analysis of digital information using...SeniorWork at officeLocal areaWork from home3 days per week$140k - $170k
...Position OverviewCRA’s Forensic Services practice... ...investigations space, your responsibilities as an Associate... ...detection, threat analysis, incident response and malware analysis... ...forensic analysis of digital information using... ...from an assigned senior colleague. Additional...Work at officeLocal areaRemote workWork from home3 days per week- ...Managing Security Information and Event Management (SIEM) systems, the full-time Senior Cybersecurity Incident Response Administrator will deploy, install, and monitor infrastructure while creating dashboards for real-time detection of security anomalies, with the flexibility...SeniorFull timeRemote work
- ...DeepSeas is seeking a Senior SOC Analyst (L2) to drive client‑facing detection and response outcomes. You will lead high‑severity incidents, mentor L1/L2 analysts, and turn findings from... ...threat hunting, malware analysis, and forensics into stronger detections and...SeniorRemote job
- ...Leidos in Arlington, VA seeks a Senior Incident Response Analyst to join the DHS CISA SOC program, driving incident detection, response, and threat analysis to protect government networks. You will coordinate investigations, analyze indicators, and develop playbooks...SeniorRemote job
- ...University of Rochester, operating in Remote Work - New York, is seeking an Incident Response Rep IV to support day-to-day information security operations and triage. You will verify, classify and document events, escalating incidents as required, and provide first- and...SeniorRemote job
- ...Atlassian is seeking a Senior Incident Response Analyst to lead security incidents across our corporate and cloud environments. You will hunt for signs of compromise, coordinate cross-functional responses, and develop automated playbooks to improve detection and remediation...SeniorRemote job
- A cybersecurity firm in Virginia is seeking an Incident Response Expert to support critical missions for government agencies. The role requires physical presence in the National Capital Region for initial training, followed by mostly remote work. Candidates must possess...SeniorRemote work
- ...Mandiant, part of Google Cloud, seeks a Senior Incident Response Security Consultant to lead end-to-end incident investigations across cloud, network, and endpoints. You will guide technical teams, communicate findings to executives, and drive remediation strategies on...SeniorRemote job
- ...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is based in our New... ...cybersecurity incident from start to finishOversight of forensics investigationsOversight of third party vendors for e-Discovery...SeniorWork at officeRemote workFlexible hours
- Job DescriptionThe RoleThe Senior Product Cybersecurity Engineer, Product Security Incident Response Team (PSIRT) role sits within the broader Product Cybersecurity organization at General Motors and focuses on responding to and managing product security vulnerabilities...SeniorFull timeLocal areaWork from homeRelocation package
- ...financial services firm is looking for a Senior Security Operations Engineer in Seattle.... ...-functionally to respond to security incidents and enhance Brex's security capabilities... ...demands strong skills in security incident response, familiarity with CI/CD systems, and...SeniorWork at officeRemote work
- ...First Citizens Bank is seeking a Senior Incident Response Analyst to join its Cyber Incident Response team in a remote role across the United States. You will detect and respond to threats, interact with business stakeholders, and help restore operations. This is a...SeniorRemote job
$155k - $200k
...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is based in our New... ...cybersecurity incident from start to finishOversight of forensics investigationsOversight of third party vendors for e-Discovery...SeniorFull timeWork at officeRemote workFlexible hours- ...Project Analyst in eDiscovery Cyber Services to support cyber incident response and data breach matters. You will coordinate project... ...on schedule. You will collaborate with Project Managers and senior team members, use tools like Excel, Power Query, SQL, Python,...SeniorRemote job
$87.32k
...designation reflects the company’s commitment to hiring and supporting active-duty and veteran employees. Responsibilities The Senior Cybersecurity Incident Response Administrator manages Security Information and Event Management (SIEM) systems, including deployment...SeniorFor contractorsLocal areaRemote work- ...Energy RevolutionBecome a Cybersecurity Senior Specialist at Southern California... ...this job, you’ll serve as Cybersecurity Incident Response Team (CSIRT) Coordinator, leading the coordination... ...and manages security incidents. Uses forensics where appropriate. Reviews and shapes...SeniorWork at officeRemote workRelocation
$89.01k - $142.19k
...role: You will be entrusted as the senior most technical member of incident response team for our global information... ...incident response plans, conduct cyber forensic investigations on physical... ...publishing, Elsevier offers a suite of digital solutions and services to support...SeniorFull timeLocal areaWork from home$120k - $135k
...Tetrad Digital Integrity (TDI) is a cybersecurity firm built for high-consequence environments... ...for 25 years! TDI is seeking a Senior Incident Response Analyst to join our team in support of... ...traffic, endpoint telemetry, and forensic artifacts to determine the scope, root...SeniorPermanent employmentContract workRemote work2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Director, Digital Forensics and Incident Response. Be the first to apply!
- digital manager Remote
- digital experience manager Remote
- senior director digital marketing Remote
- director of digital platform Remote
- senior digital account manager Remote
- associate manager digital marketing Remote
- senior manager digital Remote
- digital director Remote
- senior service associate Remote
- senior safety specialist Remote



