Manager, Digital Forensics & Incident Response (DFIR)
Stealth Talent Solutions
United States
The Role
This hands-on technical leadership position involves directing cyber incident response engagements end-to-end — from initial triage through containment, eradication, and recovery. Day-to-day work includes conducting forensic analysis of Windows hosts, reviewing artifacts, identifying attacker behaviour, and briefing executive and legal stakeholders during active incidents.
Skills & Experience
Candidates must bring 6+ years of hands-on DFIR experience with strong knowledge of Windows event logs, registry, file system artifacts, and persistence mechanisms. Familiarity with SIEM, EDR, and network security tooling is expected, alongside working knowledge of NIST and SANS incident response frameworks. Strong client-facing communication skills are essential.
Who It Suits
This role suits an experienced DFIR practitioner ready to step into a management capacity without leaving technical work behind. It is ideal for someone who has led investigations into ransomware, business email compromise, or insider threats and is comfortable advising legal counsel and C-suite stakeholders under pressure.
Typical advertised salary for Incident Response roles in United States: $125,000–$180,000 (median $150,000 — from 154 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in United States →
Certifications mentioned: SANS — find training for these on the DFIR Training Finder.





