Senior Digital Forensics and Incident Response Engineer
Ladders
United States
The Role
The role centres on leading forensic investigations into identity theft and account takeover incidents within a healthcare organisation. Day-to-day responsibilities include conducting forensic analyses to determine attack methods and root causes, correlating incident data to identify vulnerabilities, developing automated response workflows, and reporting findings to senior leadership.
Skills & Experience
Candidates should have at least three years in digital forensics and incident response, with experience using Splunk for queries and dashboard development. Familiarity with FTK and EnCase is expected, and GIAC certifications such as GCFE, GCFA, or GIME are desirable. Cloud forensics experience and exposure to AI system investigations are also valued.
Who It Suits
This position suits an experienced DFIR professional comfortable operating independently in a remote environment and eager to influence organisational strategy. Those with a background in healthcare security or fraud investigation, who can bridge technical forensic work with stakeholder communication and capability development, will find it particularly well matched.
Typical advertised salary for Digital Forensics roles in United States: $90,000–$154,000 (median $122,000 — from 207 recent listings analysed by Forensic Focus).
Compare Digital Forensics salaries in United States →
Certifications mentioned: GCFA · GCFE · GIME — find training for these on the DFIR Training Finder.





