Senior Director, Digital Forensics and Incident Response
Listed on 2026-06-21
-
IT/Tech
Cybersecurity
Role:
Senior Director, Digital Forensics & Incident Response
Location: Remote, US
Work Authorization: US Citizenship Required
Blue Voyant is seeking a Senior Director, DFIR to lead high-impact cyber investigations and act as incident commander during complex, high-pressure security incidents.
This is a client-facing leadership role responsible for guiding organizations through critical moments—from initial response through investigation, containment, and recovery—while advising executives, legal counsel, and technical teams.
What You’ll Do- Act as incident commander for complex DFIR engagements end-to-end
- Serve as the primary client lead
, advising executives, legal counsel, insurers, and stakeholders - Lead investigations across ransomware, BEC, cloud/identity compromise, insider threat, and advanced attacks
- Direct forensic analysis across endpoints, cloud, identity, SaaS, email, and network environments
- Translate technical findings into clear business risk and remediation guidance
- Lead executive briefings, client updates, and post-incident reviews
- Manage multiple concurrent incidents in fast-paced, high-pressure environments
- Mentor and develop DFIR consultants and technical teams
- Support incident readiness, tabletop exercises, and client growth initiatives
- 3–5 years of hands‑on DFIR experience in real‑world incidents
- 6–10 years in client‑facing consulting, incident response, or cyber advisory roles
- Proven experience as an incident commander or senior DFIR lead
- Strong background in ransomware, cloud/identity compromise, and complex attack investigations
- Experience working directly with executives, legal counsel, insurers, and technical teams
- Ability to manage multiple stakeholders, work streams, and timelines under pressure
- Leadership experience mentoring or managing technical teams
- Strong knowledge across endpoint, cloud, identity, SaaS, and network forensics
- Experience with tools such as EnCase, FTK, Magnet AXIOM, Velociraptor, Splunk, Sentinel, Crowd Strike (or similar)
- Familiarity with Microsoft 365, Entra , Azure, AWS, Okta, Google Workspace
- Understanding of attacker tradecraft, including persistence, lateral movement, and data exfiltration
- Working knowledge of KQL, SPL, SQL, Power Shell, Python, or Bash
- Exceptional communication skills—able to translate technical issues into business impact
- Strong judgment in high-stress, ambiguous environments
- Composed, credible, and client-focused under pressure
- Collaborative leader with a focus on quality, mentorship, and outcomes
- Experience working with breach counsel, insurers, or regulators
- Incident readiness, tabletop, or IR planning experience
- Certifications such as CISSP, GCFA, GCIH, GCFE, GNFA, OSCP
Bachelor’s degree preferred (Cybersecurity, Computer Science, DFIR, or related), or equivalent professional experience.
Why Blue Voyant?- Work alongside experienced DFIR leaders and experts
, including former government cyber professionals and industry veterans. - Lead high‑impact, global cyber investigations
, supporting clients through critical, business-defining incidents - Gain exposure to complex environments, executive stakeholders, and advanced threat scenarios across industries
- Join a global, mission-driven cybersecurity company defending organisations worldwide with cutting‑edge data, technology, and expertise
- Competitive compensation and comprehensive benefits package
, with support for wellbeing, development, and career growth
All employees must be authorized to work in the United States of America. Blue Voyant provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, Blue Voyant complies with applicable state and local laws governing non‑discrimination in employment in every location in which the company has facilities.
Disclaimer: Please note that pursuant to contractual requirements and applicable law, for employees to perform work on some of the company’s federal contracts, U.S. citizenship is required. Accordingly, an employee’s ability to perform work on such contracts is contingent upon the company’s verification of the employee’s citizenship status.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).