Digital Forensics & Incident Response (DFIR) Lead
ExternalPrepare for this interview
EliteAI-generated questions, company research, and talking points tailored to this role
Responsibilities
- Serve as incident commander during high-severity events, particularly ransomware and enterprise-scale breaches.
- Oversee multiple concurrent engagements, ensuring quality, consistency, and appropriate resource allocation.
- Define investigative strategy and escalation thresholds for complex incidents.
- Align technical response with legal, regulatory, insurance, and executive considerations.
- Review and approve investigative findings, containment validation, and executive reporting.
- Act as senior advisor to client executives, legal counsel, and cyber insurers.
- Provide guidance to Supervisors on advanced investigative decisions and complex threat actor scenarios.
- Maintain executive-level communication cadence during incidents.
- Support development of standardized methodologies, playbooks, and quality controls across the practice.
- Mentor Supervisors and Consultants in both technical depth and client leadership.
- Participate in on-call rotation and provide oversight during critical incidents.
Requirements
- Expertise in all areas is not required; however, candidates should demonstrate strong foundational knowledge and a willingness to continuously learn and expand their capabilities.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience.
- Proven experience leading enterprise-scale ransomware and breach investigations.
- Deep understanding of: Threat actor operations and ransomware tradecraft
- Identity compromise and domain-level persistence
- Cloud and hybrid environment incident response
- Data exfiltration risk assessment and reporting
- Strong hands-on familiarity with EDR platforms, SIEM technologies, and forensic toolsets.
- Demonstrated ability to manage multiple high-pressure engagements simultaneously.
- Experience coordinating with legal counsel, cyber insurance carriers, and executive leadership.
- Strong executive presence and crisis communication ability.
- Experience mentoring and developing DFIR leaders.
- Certifications such as GCFA, GCIH, CISSP, OSCP, or equivalent preferred.
- Willingness to participate in on-call rotation.
- RSM does not intend to hire entry level candidates who
Additional Information
We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You'll find an environment that inspires and empowers you to thrive both personally and professionally. There's no one like you and that's why there's nowhere like RSM. The RSM Cyber Response team leads organizations through some of their most consequential cyber events. The DFIR Lead serves as both incident commander and engagement leader, overseeing multiple complex matters while aligning technical, legal, executive, and insurance workstreams. This role requires strong incident command authority, deep ransomware experience, and the ability to guide cross-functional response efforts at the executive level. Leads maintain oversight across engagements, provide escalation guidance to Supervisors, and ensure investigative quality, consistency, and defensibility across the practice. The DFIR Lead is accountable not only for technical excellence, but also for engagement delivery, stakeholder alignment, and operational leadership during crisis response.
Your Match
How well this role fits your profile.
Company Intel
What employees say
Worked at rsm? Share your experience