DFIR Manager, Cyber Risk
Manager, Digital Forensics & Incident Response, Cyber & Data Resilience In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarityânot just answersâin all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, youâll contribute to a supportive and collaborative work environment that empowers you to excel. Krollâs Cyber & Data Resilience team is seeking a Digital Forensics & Incident Response (DFIR) Consultant to support organizations through highâimpact cyber incidents, investigations, and crisis events. This role is ideal for a practitioner with solid handsâon DFIR experience who is ready to take greater ownership of investigations, work directly with clients and legal counsel, and contribute to complex, fastâmoving response engagements. You will work as part of a global DFIR team responding to incidents such as ransomware, business email compromise, insider threats, data breaches, and advanced intrusionsâhelping clients contain threats, understand impact, and recover with confidence.Key Responsibilities:Lead and support digital forensics and incident response investigations across Windows, macOS, Linux, cloud, SaaS, and identity environments Perform acquisition and analysis across endpoints, servers, cloud, SaaS, identity, and network telemetry while maintaining defensible chainâofâcustodyIdentify attacker tradecraft, determine root cause, assess scope and dataâatârisk, and support threat actor evictionCommunicate effectively with all project stakeholders, including clients, outside counsel, insurers and internal teams.Support containment, eradication, and recovery activities in coordination with client security teams and restoration partners Required Experience & Skills:3â5 years of handsâon experience in digital forensics, incident response, or security operationsExperience working across modern environments (EDR/XDR, SIEM, cloud, SaaS, identity platforms)Possess excellent project management skills, with ability to communicate complex technical findings clearly to nonâtechnical stakeholdersComfortable working under pressure during live incidents, including occasional afterâhours responseNice to have:Industry certifications such as GCFA, GCFE, GCIH, or similarExperience delivering incident readiness services, such as compromise assessments, IRP/playbook development, tabletops, and cyber range activitiesExposure to expert witness support or litigationârelated investigations#LI-TM1#LI-Remote
Apply Now
Apply Now