The Incident Response (DFIR) Case Manager is responsible for providing support to clients when they have become or suspect they may be the victim of a cyber-attack. This is done by conducting high ...
The Incident Response (DFIR) Case Manager is responsible for providing support to clients when they have become or suspect they may be the victim of a cyber-attack. This is done by conducting high ...
$151K - $208K/yr
Job Summary Job Summary The Principal Consultant, Cloud DFIR, Reactive Services is a senior individual contributor within Unit 42 responsible for leading cloud-focused incident response and digital ...
$151K - $208K/yr
Job Summary Job Summary The Principal Consultant, Cloud DFIR, Reactive Services is a senior individual contributor within Unit 42 responsible for leading cloud-focused incident response and digital ...
$151K - $208K/yr
This position is ideal for an experienced DFIR practitioner who thrives in fast-paced incident response environments and enjoys solving complex technical challenges during critical security events.
$151K - $208K/yr
This position is ideal for an experienced DFIR practitioner who thrives in fast-paced incident response environments and enjoys solving complex technical challenges during critical security events.
$65K - $86K/yr
Fundierte Kenntnisse in Forensik, Betriebssystemen, Netzwerkanalyse sowie gรคngigen DFIR-Tools * Sehr starkes analytisches Denkvermรถgen, strukturierte Arbeitsweise und hohe Problemlรถsungskompetenz ...
$65K - $86K/yr
Fundierte Kenntnisse in Forensik, Betriebssystemen, Netzwerkanalyse sowie gรคngigen DFIR-Tools * Sehr starkes analytisches Denkvermรถgen, strukturierte Arbeitsweise und hohe Problemlรถsungskompetenz ...
ASSYST is seeking an experienced Digital Forensics & Incident Response (DFIR) Analyst to support enterprise cybersecurity operations through advanced threat hunting, digital forensic analysis, and ...
Quick apply
ASSYST is seeking an experienced Digital Forensics & Incident Response (DFIR) Analyst to support enterprise cybersecurity operations through advanced threat hunting, digital forensic analysis, and ...
Senior Consultant, Digital Forensics and Incident Response (DFIR) Location: Remote, USA / ExemptCompensation: $90K-$120K, 20% Bonus What Makes You Stand Out You are an experienced cybersecurity ...
Quick apply
Senior Consultant, Digital Forensics and Incident Response (DFIR) Location: Remote, USA / ExemptCompensation: $90K-$120K, 20% Bonus What Makes You Stand Out You are an experienced cybersecurity ...
As the DFIR Director, you will lead a global team that safeguards the company by detecting, analyzing, and responding to cyber threats in real time. This is a strategic leadership role accountable ...
As the DFIR Director, you will lead a global team that safeguards the company by detecting, analyzing, and responding to cyber threats in real time. This is a strategic leadership role accountable ...
We are seeking a seasoned and strategic DFIR Director to join our Digital Forensics and Incident Response (DFIR) practice. This leadership role is responsible for overseeing complex incident response ...
Quick apply
We are seeking a seasoned and strategic DFIR Director to join our Digital Forensics and Incident Response (DFIR) practice. This leadership role is responsible for overseeing complex incident response ...
Principal Consultant, Digital Forensic and Incident Response (DFIR) (Remote)
Wilmington, DE ยท Remote
$100K - $160K/yr
... DFIR), with extensive experience, including client-facing roles, sophisticated forensic analysis, and a proven track record of independently managing investigations of varying sizes and complexities.
Quick apply
Principal Consultant, Digital Forensic and Incident Response (DFIR) (Remote)
Wilmington, DE ยท Remote
$100K - $160K/yr
... DFIR), with extensive experience, including client-facing roles, sophisticated forensic analysis, and a proven track record of independently managing investigations of varying sizes and complexities.
Senior Cyber Lead
Linthicum, MD ยท On-site
Provide technical leadership and oversight for Digital Forensics and Incident Response (DFIR) operations supporting DoD law enforcement, counterintelligence, cyber operations, and Defense Industrial ...
Senior Cyber Lead
Linthicum, MD ยท On-site
Provide technical leadership and oversight for Digital Forensics and Incident Response (DFIR) operations supporting DoD law enforcement, counterintelligence, cyber operations, and Defense Industrial ...
Provide technical leadership and oversight for Digital Forensics and Incident Response (DFIR) operations supporting DoD law enforcement, counterintelligence, cyber operations, and Defense Industrial ...
Provide technical leadership and oversight for Digital Forensics and Incident Response (DFIR) operations supporting DoD law enforcement, counterintelligence, cyber operations, and Defense Industrial ...
Provide technical leadership and oversight for Digital Forensics and Incident Response (DFIR) operations supporting DoD law enforcement, counterintelligence, cyber operations, and Defense Industrial ...
Provide technical leadership and oversight for Digital Forensics and Incident Response (DFIR) operations supporting DoD law enforcement, counterintelligence, cyber operations, and Defense Industrial ...
Provide technical leadership and oversight for Digital Forensics and Incident Response (DFIR) operations supporting DoD law enforcement, counterintelligence, cyber operations, and Defense Industrial ...
Provide technical leadership and oversight for Digital Forensics and Incident Response (DFIR) operations supporting DoD law enforcement, counterintelligence, cyber operations, and Defense Industrial ...
Senior Purple Team Engineer / Lead (Blue Focused)
$96K - $132K/yr
Use DFIR tools and platforms (e.g., Velociraptor) for threat hunting, artifact collection, and timeline analysis. * Feed incident lessons learned back into detection engineering and preventive ...
Senior Purple Team Engineer / Lead (Blue Focused)
$96K - $132K/yr
Use DFIR tools and platforms (e.g., Velociraptor) for threat hunting, artifact collection, and timeline analysis. * Feed incident lessons learned back into detection engineering and preventive ...
CSIRT Analyst
$111K - $125K/yr
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
Quick apply
CSIRT Analyst
$111K - $125K/yr
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
CSIRT Analyst
Buffalo, NY ยท On-site
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
Quick apply
CSIRT Analyst
Buffalo, NY ยท On-site
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
CSIRT Analyst
Anchorage, AK ยท On-site
$125K - $140K/yr
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
Quick apply
CSIRT Analyst
Anchorage, AK ยท On-site
$125K - $140K/yr
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
CSIRT Analyst
Buffalo, NY ยท On-site
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
Quick apply
CSIRT Analyst
Buffalo, NY ยท On-site
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
CSIRT Analyst
Anchorage, AK ยท On-site
$125K - $140K/yr
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
Quick apply
CSIRT Analyst
Anchorage, AK ยท On-site
$125K - $140K/yr
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
CSIRT Analyst
Buffalo, NY ยท On-site
$111K - $125K/yr
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
Quick apply
CSIRT Analyst
Buffalo, NY ยท On-site
$111K - $125K/yr
You conduct DFIR assignments, including DFIR readiness assessments * You participate in the weekly Threat Hunting duty to proactively chase threats through novel Tools, Techniques & Procedures (TTPs)
Dfir information
See salary details
$33.5K - $46.3K
1% of jobs
$46.3K - $59K
0% of jobs
$59K - $71.8K
0% of jobs
$71.8K - $84.6K
0% of jobs
$84.6K - $97.4K
4% of jobs
$109.3K is the 25th percentile. Wages below this are outliers.
$97.4K - $110.1K
21% of jobs
$110.1K - $122.9K
15% of jobs
The median wage is $132.8K / yr.
$122.9K - $135.7K
12% of jobs
$135.7K - $148.5K
14% of jobs
$148.5K - $161.2K
7% of jobs
$161.9K is the 75th percentile. Wages above this are outliers.
$161.2K - $174K
26% of jobs
$33.5K
$137.7K
$174K
How much do dfir jobs pay per year?
What are the key skills and qualifications needed to thrive in the Dfir position, and why are they important?
To thrive as a DFIR (Digital Forensics and Incident Response) professional, you need expertise in computer forensics, incident response methodologies, and network security, typically supported by a related degree or cybersecurity certifications like GCFA, GCFE, or CEH. Familiarity with forensic imaging tools (e.g., EnCase, FTK, X-Ways), SIEM platforms, and scripting languages is crucial for investigating and addressing security incidents. Analytical thinking, problem-solving, and strong communication skills set individuals apart in this position. These capabilities are essential for accurately identifying, analyzing, and mitigating digital threats in high-pressure environments.
What are some common challenges faced by DFIR professionals in their daily work?
DFIR professionals often handle cases involving complex cyberattacks, requiring them to quickly analyze large volumes of digital evidence and determine the scope of incidents. Challenges can include working under tight time constraints, managing sensitive information, and staying updated with rapidly evolving attack techniques and security technologies. Teamwork and collaboration with other IT and security personnel are frequent, as incident response is rarely a solo effort. Success in this field typically relies on a balance of technical expertise, methodical investigation, and the ability to adapt to new threats and technologies on a daily basis.
What is a DFIR job?
A DFIR (Digital Forensics and Incident Response) job involves investigating cybersecurity incidents, analyzing digital evidence, and responding to security breaches. Professionals in this field use forensic tools to recover data, trace attack origins, and mitigate cyber threats. DFIR experts work in law enforcement, private security firms, and corporate cybersecurity teams. Their responsibilities include malware analysis, log analysis, and ensuring systems are secured against future attacks. Strong technical skills in digital forensics, networking, and security best practices are essential for success in this field.

Other
Medical, Dental, Vision, Life, Retirement, PTO
Posted 27 days ago
Job description
Description
Why choose FRSecure? We believe information security is fun. We focus on equipping our clients, communities, and employees with knowledge to better protect themselves against risk. Our first core value, we tell the truth, sets a foundation for meaningful relationships and employee growth, ultimately providing the highest quality work in the industry. We are consistently awarded for outstanding service, industry-leading methodology, organizational growth, and a reputable culture. Our benefits are something to talk about as well. We offer a flexible and rewarding work environment, medical, dental and vision insurance, HSA/FSA/DCA accounts, life and disability insurance, 401(k) with employer match up to 4%, employee assistance program (EAP), unlimited paid time off, paid parental leave, education/growth assistance, pet insurance, and more.
We are experts on a mission to fix the broken information security industry. We believe that behind every data compromise are people, and everyone deserves to have their data and livelihood protected. We take great pride in what we do and how we do it, and we truly believe we can accomplish our mission. It starts with hiring the right people to help us get there. If this resonates with you, apply now to join our dedicated team!
Position Summary: The Incident Response (DFIR) Case Manager is responsible for providing support to clients when they have become or suspect they may be the victim of a cyber-attack. This is done by conducting high quality and timely incident response investigations in environments of varying security maturity including identification and containment phases and advising clients regarding recovery and remediation steps to assist them in returning to normal business operations. Our Incident Response Case Managers have a blend of proactive project responsibilities, such as leading tabletops and plan coaching, as well as triage and case work.
Working Location: This position is available on a full-time remote basis in the following states: Arizona, Colorado, Florida, Georgia, Idaho, Illinois, Kansas, Kentucky, Massachusetts, Michigan, Minnesota, Montana, North Carolina, Ohio, Pennsylvania, South Dakota, Tennessee, Texas, Washington, and Wisconsin. Only candidates located in the United States will be considered. Office headquarters and operational business hours are based in Edina, MN (Central Time).
Application Deadline: June 5, 2026ย
What Your Day Looks Like as an Incident Response (DFIR) Case Manager:
- Performing a forensic review of client systems for artifacts and indicators of compromise (IOCs) to further identify, contain, and eradicate malware and/or malicious intruders
- Conducting triage, threat-hunting, and case management for incident response clients
- Documenting detailed evidence, findings, and create a report output
- Meeting with clients during the planning, information sharing, and technical support stages
- Creating and delivering proactive projects to clients including tabletop exercises, plan coaching, assessments
- Conducting regular calls with clients to consult on incident response programs
- Continue education by researching and investigating developments in cyber forensics/attack methodologies; increase existing skillset to handle these matters
- Attending and participating in regular internal meetings
- Participating in on-call rotation, providing timely and effective support to clients, ensuring adherence to service level agreements (SLAs) and resolving issues within established response and resolution times
- Performing periodic after-hours and weekends on-call work
Working Hours: Standard working hours for this position are between 8:00am-5:00pm in the time zone in which the employee is based, with the expectation that there may be client calls, project/task responsibilities, meetings, or other company obligations in which the employee will need to work outside of these hours, as standard business hours are 8:00am-5:00pm Central Time.
This position also includes on-call responsibilities. On-call duty will be 1 week in duration with the on-call assignment being dependent upon the number of Case Managers on the team. During the on-call rotation, the employee will be required to monitor an email inbox for incoming CSIRT requests as well as answer incoming calls to the CSIRT after-hours hotline and perform incident triage duties.
Travel: There is minimal travel associated with this position, typically less than 5-10%. Occasional travel includes conferences or on-site client projects as needed, as well as any team or company activities.
Requirements
What You Bring to the Incident Response (DFIR) Case Manager role:
- 3-5 years of information security experience
- 3-5 years of experience with Active Directory, Systems Administration, Exchange Administration, M365 and/or other cloud environments
- 3-5 years of experience in presenting information security concepts
- GCIH, GCFA, ECIH certifications preferred
- Prior experience in threat hunting and/or incident handling
- Prior experience in management of EDR and/or SIEM technologies
- Experience with firewalls and network devices best practices and logging
- Solid understanding of computer systems administration in large environments
- Demonstrated analytical skills to interpret data, identify trends, and ensure accuracy in all deliverables
- Ability to clearly convey complex information to diverse audiences and actively listen to understand needs and provide effective solutions
- Proven customer service skills with a customer-focused mindset, including the ability to build relationships, resolve issues effectively, and deliver a positive, responsive client experience
- Ability to communicate highly technical topics to non-technical people effectively
- Ability to handle and work with large amounts of data
- Proficient with all Microsoft Office Suite products
Salary: FRSecure believes in and operates with equitable hiring practices. The starting salary range is $85,000-116,000, not including any bonus, incentive commission, or benefits. The range displayed on each job posting reflects the defined starting salary range for the position across the United States. Within the range, pay offered is determined by a variety of factors that include but are not limited to job-related skills, experience, and relevant education or training.
Commission eligible: No
FLSA Status: Exempt
Your Recruiter will be able to discuss further details related to commission, bonuses, or other specific salary information related to this position.
Former and Current Employees: To qualify for this position, former employees must be eligible for rehire, and current employees must be in good standing.
Employment and Application Statements
FRSecure, LLC is committed to the principles of equal employment. We comply with all federal, state, and local laws providing equal employment opportunities, and all other employment laws and regulations. It is our intent to maintain a work environment that is free of harassment, discrimination, or retaliation because of race, color, creed, religion, national origin, sex, sexual orientation (including transgender status, gender identity or expression), pregnancy (including childbirth, lactation, or related conditions), marital status, disability, public assistance, age, and familial status, genetic information, local commissions activity, veteran status, uniformed servicemember status, or any other status protected by federal, state, or local laws.
FRSecure is dedicated to the fulfillment of this policy in regard to all aspects of employment, including but not limited to recruiting, hiring, placement, transfer, training, promotion, rates of pay, and other compensation, termination, and all other terms, conditions, and privileges of employment.
FRSecure is committed to the full inclusion of all qualified individuals. As part of this commitment, FRSecure will ensure that persons with disabilities are provided reasonable accommodations for the hiring process. If a reasonable accommodation is needed to complete a job application, interview, or otherwise participate in the hiring process, please contact the Human Resources team at hr@frsecure.com.
About FRSecure
Sourced by ZipRecruiter
Industry
Network security
Company size
11 - 50 Employees
Headquarters location
Minnetonka, MN, US
Year founded
2008