My client is a global risk management and intelligence services firm. They are looking for a DFIR (Digital Forensics & Incident Response) Managing Director to drive incident response engagements, oversee forensic investigations, lead a team of DFIR professionals, and provide strategic direction to improve the organizations' cybersecurity posture.
Responsibilities
Lead and manage the DFIR practice, overseeing incident response engagements, digital forensic investigations, and proactive threat hunting.
Develop and implement DFIR strategies, frameworks, and playbooks to enhance incident response capabilities.
Manage and mentor a team of DFIR professionals, providing technical guidance and career development support.
Act as a senior advisor to clients during cyber incidents, offering leadership and strategic recommendations for mitigation and remediation.
Oversee the collection, preservation, and analysis of digital evidence from various sources, ensuring compliance with legal and regulatory requirements.
Qualifications
10+ years of experience in Cyber DFIR, with at least 3 years in a leadership capacity.
Strong technical expertise in digital forensics tools such as EnCase, FTK, Cellebrite, X-Ways, and others.
Hands-on experience with EDR solutions, cybersecurity platforms, and cloud environments (e.g., Microsoft 365, G-Suite, AWS).
Proficiency in handling various operating systems (Linux, Windows, Mac, iOS) and file systems (FAT, NTFS, EXT).
Expert-level proficiency in data and log analysis using tools like SQL, Python, Splunk, Tableau, and Excel.
Extensive experience in digital evidence collection and forensic analysis from diverse sources.
Familiarity with threat hunting, malware analysis, and memory capture techniques.
Strong understanding of regulatory requirements and legal considerations related to digital forensics.
Preferred Certifications
Certified Computer Examiner (CCE)
Certified Information Systems Security Professional (CISSP)
GIAC Certified Incident Handler (GCIH)
Certified Forensic Computer Examiner (CFCE)
Other relevant certifications in DFIR or cybersecurity etc.