Associate Director, Cyber Operations – Cyber Response and Digital Forensics
KPMG US
Albany, NY
The Role
This senior position leads end-to-end investigations into major cyber incidents, analysing disks, memory, logs and network traffic across on-premise and multicloud environments. The role involves reconstructing attack timelines, advising leadership during breaches, implementing containment measures, and building automated triage and detection capabilities.
Skills & Experience
Candidates need extensive hands-on DFIR experience, certifications such as GCFA, GCFE, GNFA, GCIH, EnCE, CFCE or CISSP, and proficiency with tools including EnCase, FTK, Axiom, X-Ways, Volatility, CrowdStrike Falcon, Defender for Endpoint and Splunk, plus scripting in Python and PowerShell.
Who It Suits
Ideal for an experienced DFIR professional ready to lead complex investigations, mentor junior analysts, liaise with executives and legal counsel, and strengthen organisational incident response processes and tooling.
Typical advertised salary for Incident Response roles in United States: $123,000–$179,000 (median $149,000 — from 159 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in United States →
Certifications mentioned: GCFA · GCFE · GNFA · GCIH · EnCE · CFCE · CISSP — find training for these on the DFIR Training Finder.