bluevoyant
New

Senior Director, Digital Forensics and Incident Response

Remotesenior
OtherDirector
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Act as incident commander for complex DFIR engagements end-to-end Serve as the primary client lead, advising executives, legal counsel, insurers,

Technical Tools
OtherDirector

Role: Senior Director, Digital Forensics & Incident Response
Location: Remote, US
Work Authorization: US Citizenship Required

BlueVoyant is seeking a Senior Director, DFIR to lead high-impact cyber investigations and act as incident commander during complex, high-pressure security incidents.

This is a client-facing leadership role responsible for guiding organizations through critical moments—from initial response through investigation, containment, and recovery—while advising executives, legal counsel, and technical teams.

Responsibilities

~1 min read
  • Act as incident commander for complex DFIR engagements end-to-end
  • Serve as the primary client lead, advising executives, legal counsel, insurers, and stakeholders
  • Lead investigations across ransomware, BEC, cloud/identity compromise, insider threat, and advanced attacks
  • Direct forensic analysis across endpoints, cloud, identity, SaaS, email, and network environments
  • Translate technical findings into clear business risk and remediation guidance
  • Lead executive briefings, client updates, and post-incident reviews
  • Manage multiple concurrent incidents in fast-paced, high-pressure environments
  • Mentor and develop DFIR consultants and technical teams
  • Support incident readiness, tabletop exercises, and client growth initiatives
  • 3–5 years of hands-on DFIR experience in real-world incidents
  • 6–10 years in client-facing consulting, incident response, or cyber advisory roles
  • Proven experience as an incident commander or senior DFIR lead
  • Strong background in ransomware, cloud/identity compromise, and complex attack investigations
  • Experience working directly with executives, legal counsel, insurers, and technical teams
  • Ability to manage multiple stakeholders, workstreams, and timelines under pressure
  • Leadership experience mentoring or managing technical teams
  • Strong knowledge across endpoint, cloud, identity, SaaS, and network forensics
  • Experience with tools such as EnCase, FTK, Magnet AXIOM, Velociraptor, Splunk, Sentinel, CrowdStrike (or similar)
  • Familiarity with Microsoft 365, Entra ID, Azure, AWS, Okta, Google Workspace
  • Understanding of attacker tradecraft, including persistence, lateral movement, and data exfiltration
  • Working knowledge of KQL, SPL, SQL, PowerShell, Python, or Bash
  • Exceptional communication skills—able to translate technical issues into business impact
  • Strong judgment in high-stress, ambiguous environments
  • Composed, credible, and client-focused under pressure
  • Collaborative leader with a focus on quality, mentorship, and outcomes

Nice to Have

~1 min read
  • Experience working with breach counsel, insurers, or regulators
  • Incident readiness, tabletop, or IR planning experience
  • Certifications such as CISSP, GCFA, GCIH, GCFE, GNFA, OSCP

Bachelor’s degree preferred (Cybersecurity, Computer Science, DFIR, or related), or equivalent professional experience.
 

  • Work alongside experienced DFIR leaders and experts, including former government cyber professionals and industry veterans.
  • Lead high-impact, global cyber investigations, supporting clients through critical, business-defining incidents
  • ​​​​Gain exposure to complex environments, executive stakeholders, and advanced threat scenarios across industries
  • Join a global, mission-driven cybersecurity company defending organisations worldwide with cutting-edge data, technology, and expertise
  • Competitive compensation and comprehensive benefits package, with support for wellbeing, development, and career growth

Requirements

~1 min read

As part of our interview process, we assess your experience through real-time discussion, so we expect responses to be your own. While we support the use of AI in our business, it is not permitted during interviews, and any suspected use may be challenged, including through detection methods.

BlueVoyant Candidate Privacy Notice

To understand how we secure and manage your personal data upon submitting a job application, please see our Candidate Privacy Notice, which can be found here - Candidate Privacy Notice

Location & Eligibility

Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Open to applicants worldwide

Listing Details

Posted
June 8, 2026
First seen
June 9, 2026
Last seen
June 12, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
58%
Scored at
June 9, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

bluevoyantSenior Director, Digital Forensics and Incident Response