Remote job
DFIR – Engagement Manager
Job details
About this role
Role overview
This position leads end-to-end delivery of digital forensics and incident response (DFIR) engagements for global enterprises facing active, high-stakes cyber threats such as ransomware, business email compromise, identity compromise, zero-day exploitation, advanced persistent threat activity, and cloud or SaaS breaches. The role blends hands-on DFIR practitioner knowledge with strong project management, serving as the central coordinator between technical analysts, customer executives, breach counsel, cyber insurance carriers, and account teams. It is a remote role based in U.S. Pacific, Mountain, Alaska, or Hawaii time zones, with occasional work on federally regulated customer environments.
Responsibilities
- Own the full lifecycle of DFIR investigations, from scoping and staffing through budget management, delivery, and case closure. - Assign analysts to engagements based on scope, required skillset, and availability, and monitor capacity to keep workload balanced. - Lead intake, requirements gathering, scoping calls, and statement-of-work or tri-party agreement development with prospective and active clients. - Track retainer hour budgets against scope, coordinate uplift or overage discussions with customers and account teams, and manage engagement financials. - Establish clear communication channels across all investigation stakeholders and own escalations through to resolution. - Oversee case documentation, evidence handling, chain of custody, and retention or deletion timelines, including early-deletion requests. - Partner with technical leads to shape investigative direction, validate findings, and ensure deliverables meet customer and reporting standards; provide surge support for data collection and forensic analysis when needed.
Requirements
- Practitioner-level DFIR knowledge combined with proven project and engagement management skills. - Strong communication skills, with the ability to move between technical detail and executive-level conversations during active incidents. - Experience overseeing investigations end-to-end, including staffing, scoping, budgeting, and stakeholder management. - Familiarity with incident response best practices, standard operating procedures, evidence handling, and chain of custody. - Intellectual curiosity, adaptability, and a self-starter mindset suited to fast-moving breach response. - U.S. citizenship and eligibility to support federally regulated customer investigations.
Nice to have
- Hands-on experience with malware analysis and memory forensics. - Background in endpoint threat hunting and compromise assessments. - Familiarity with cyber threat intelligence platforms and workflows. - Active participation in the security community through speaking or publishing.
Benefits and work setup
- Remote work based in U.S. Pacific, Mountain, Alaska, or Hawaii time zones. - Equity participation through restricted stock units and an employee stock purchase plan. - Flexible paid time off, paid company holidays, paid sick time, gender-neutral parental leave, and grandparent leave. - Medical, dental, and vision coverage, 401(k) with company match, life and disability insurance, and flexible spending accounts. - Voluntary coverage including hospital, accident, and critical illness; employee assistance program; pre-paid legal; pet insurance; fertility, adoption, and surrogacy support; and a home office allowance plus mobile phone reimbursement.