All jobs

DFIR Manager, Cyber Risk

100% Remote Full-time Open now

Manager, Digital Forensics & Incident Response, Cyber & Data Resilience

In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.

Kroll’s Cyber & Data Resilience team is seeking a Digital Forensics & Incident Response (DFIR) Consultant to support organizations through high‑impact cyber incidents, investigations, and crisis events. This role is ideal for a practitioner with solid hands‑on DFIR experience who is ready to take greater ownership of investigations, work directly with clients and legal counsel, and contribute to complex, fast‑moving response engagements. You will work as part of a global DFIR team responding to incidents such as ransomware, business email compromise, insider threats, data breaches, and advanced intrusions—helping clients contain threats, understand impact, and recover with confidence.

Key Responsibilities:

  • Lead and support digital forensics and incident response investigations across Windows, macOS, Linux, cloud, SaaS, and identity environments

  • Perform acquisition and analysis across endpoints, servers, cloud, SaaS, identity, and network telemetry while maintaining defensible chain‑of‑custody

  • Identify attacker tradecraft, determine root cause, assess scope and data‑at‑risk, and support threat actor eviction

  • Communicate effectively with all project stakeholders, including clients, outside counsel, insurers and internal teams.
  • Support containment, eradication, and recovery activities in coordination with client security teams and restoration partners

Required Experience & Skills:

  • 3–5 years of hands‑on experience in digital forensics, incident response, or security operations

  • Experience working across modern environments (EDR/XDR, SIEM, cloud, SaaS, identity platforms)

  • Possess excellent project management skills, with ability to communicate complex technical findings clearly to non‑technical stakeholders

  • Comfortable working under pressure during live incidents, including occasional after‑hours response

Nice to have:

  • Industry certifications such as GCFA, GCFE, GCIH, or similar

  • Experience delivering incident readiness services, such as compromise assessments, IRP/playbook development, tabletops, and cyber range activities

  • Exposure to expert witness support or litigation‑related investigations

#LI-TM1

#LI-Remote

Apply To This Job

You might also like

Supervisor, Maintenance Control

100% Remote Full-time

Senior Software Engineer

100% Remote Full-time

Chief of Staff in Product and Technology

100% Remote Full-time

Sales Engineer (Dallas/Fort Worth Region)

100% Remote Full-time

Sales Associate

100% Remote Full-time

Senior Manager of Virtual Sales

100% Remote Full-time

Reliability Engineer

100% Remote Full-time

Condition Based Monitoring Expert

100% Remote Full-time

Vibration Analyst

100% Remote Full-time

Field Sales Executive

100% Remote Full-time

Customer Service Executive – Remote Contract Opportunity for 3-6 Months with arenaflex, Delivering Exceptional Customer Experiences and Driving Business Growth

100% Remote Full-time

Remote Entry‑Level Product Testing & Review Writer – Mobile Messaging App User Experience Analyst (US‑Based, Flexible Hours, $35/hr)

100% Remote Full-time

American furniture warehouse jobs

100% Remote Full-time

UN Women - Consultant Financial Tool Adaptation Expert, Home-based.

100% Remote Full-time

Nurse Navigator – High Risk Cancer Prevention and Wellness Program (hybrid), FL

100% Remote Full-time

Experienced Entry-Level Customer Service Representative – Telehealth Support

100% Remote Full-time

Remote Chat Support ID-2208 – Amazon Store

100% Remote Full-time

Executive Assistant & Revenue Cycle Operations Coordinator

100% Remote Full-time

Retail Cleaning Associate; PT Mornings

100% Remote Full-time

Experienced Entry Level Chat Support Specialists – Remote Work Opportunities with arenaflex

100% Remote Full-time