Senior Director, Digital Forensics and Incident Response
Quick Summary
Act as incident commander for complex DFIR engagements end-to-end Serve as the primary client lead, advising executives, legal counsel, insurers,
Role: Senior Director, Digital Forensics & Incident Response
Location: Remote, US
Work Authorization: US Citizenship Required
BlueVoyant is seeking a Senior Director, DFIR to lead high-impact cyber investigations and act as incident commander during complex, high-pressure security incidents.
This is a client-facing leadership role responsible for guiding organizations through critical moments—from initial response through investigation, containment, and recovery—while advising executives, legal counsel, and technical teams.
Responsibilities
~1 min read- →Act as incident commander for complex DFIR engagements end-to-end
- →Serve as the primary client lead, advising executives, legal counsel, insurers, and stakeholders
- →Lead investigations across ransomware, BEC, cloud/identity compromise, insider threat, and advanced attacks
- →Direct forensic analysis across endpoints, cloud, identity, SaaS, email, and network environments
- →Translate technical findings into clear business risk and remediation guidance
- →Lead executive briefings, client updates, and post-incident reviews
- →Manage multiple concurrent incidents in fast-paced, high-pressure environments
- →Mentor and develop DFIR consultants and technical teams
- →Support incident readiness, tabletop exercises, and client growth initiatives
- 3–5 years of hands-on DFIR experience in real-world incidents
- 6–10 years in client-facing consulting, incident response, or cyber advisory roles
- Proven experience as an incident commander or senior DFIR lead
- Strong background in ransomware, cloud/identity compromise, and complex attack investigations
- Experience working directly with executives, legal counsel, insurers, and technical teams
- Ability to manage multiple stakeholders, workstreams, and timelines under pressure
- Leadership experience mentoring or managing technical teams
- Strong knowledge across endpoint, cloud, identity, SaaS, and network forensics
- Experience with tools such as EnCase, FTK, Magnet AXIOM, Velociraptor, Splunk, Sentinel, CrowdStrike (or similar)
- Familiarity with Microsoft 365, Entra ID, Azure, AWS, Okta, Google Workspace
- Understanding of attacker tradecraft, including persistence, lateral movement, and data exfiltration
- Working knowledge of KQL, SPL, SQL, PowerShell, Python, or Bash
- Exceptional communication skills—able to translate technical issues into business impact
- Strong judgment in high-stress, ambiguous environments
- Composed, credible, and client-focused under pressure
- Collaborative leader with a focus on quality, mentorship, and outcomes
Nice to Have
~1 min read- Experience working with breach counsel, insurers, or regulators
- Incident readiness, tabletop, or IR planning experience
- Certifications such as CISSP, GCFA, GCIH, GCFE, GNFA, OSCP
Bachelor’s degree preferred (Cybersecurity, Computer Science, DFIR, or related), or equivalent professional experience.
- Work alongside experienced DFIR leaders and experts, including former government cyber professionals and industry veterans.
- Lead high-impact, global cyber investigations, supporting clients through critical, business-defining incidents
- Gain exposure to complex environments, executive stakeholders, and advanced threat scenarios across industries
- Join a global, mission-driven cybersecurity company defending organisations worldwide with cutting-edge data, technology, and expertise
- Competitive compensation and comprehensive benefits package, with support for wellbeing, development, and career growth
Requirements
~1 min readAs part of our interview process, we assess your experience through real-time discussion, so we expect responses to be your own. While we support the use of AI in our business, it is not permitted during interviews, and any suspected use may be challenged, including through detection methods.
BlueVoyant Candidate Privacy Notice
To understand how we secure and manage your personal data upon submitting a job application, please see our Candidate Privacy Notice, which can be found here - Candidate Privacy Notice
Location & Eligibility
Listing Details
- Posted
- June 8, 2026
- First seen
- June 9, 2026
- Last seen
- June 12, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 58%
- Scored at
- June 9, 2026
Signal breakdown
Please let bluevoyant know you found this job on Jobera.
3 other jobs at bluevoyant
View all →Explore open roles at bluevoyant.
Similar Director jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.