My client is a global risk management and intelligence services firm. They are looking for a DFIR (Digital Forensics & Incident Response) Managing Director to drive incident response engagements, oversee forensic investigations, lead a team of DFIR professionals, and provide strategic direction to improve the organizations' cybersecurity posture.
Responsibilities
- Lead and manage the DFIR practice, overseeing incident response engagements, digital forensic investigations, and proactive threat hunting.
- Develop and implement DFIR strategies, frameworks, and playbooks to enhance incident response capabilities.
- Manage and mentor a team of DFIR professionals, providing technical guidance and career development support.
- Act as a senior advisor to clients during cyber incidents, offering leadership and strategic recommendations for mitigation and remediation.
- Oversee the collection, preservation, and analysis of digital evidence from various sources, ensuring compliance with legal and regulatory requirements.
Qualifications
- 10+ years of experience in Cyber DFIR, with at least 3 years in a leadership capacity.
- Strong technical expertise in digital forensics tools such as EnCase, FTK, Cellebrite, X-Ways, and others.
- Hands-on experience with EDR solutions, cybersecurity platforms, and cloud environments (e.g., Microsoft 365, G-Suite, AWS).
- Proficiency in handling various operating systems (Linux, Windows, Mac, iOS) and file systems (FAT, NTFS, EXT).
- Expert-level proficiency in data and log analysis using tools like SQL, Python, Splunk, Tableau, and Excel.
- Extensive experience in digital evidence collection and forensic analysis from diverse sources.
- Familiarity with threat hunting, malware analysis, and memory capture techniques.
- Strong understanding of regulatory requirements and legal considerations related to digital forensics.
Preferred Certifications
- Certified Computer Examiner (CCE)
- Certified Information Systems Security Professional (CISSP)
- GIAC Certified Incident Handler (GCIH)
- Certified Forensic Computer Examiner (CFCE)
- Other relevant certifications in DFIR or cybersecurity etc.