Kroll Logo

Kroll

DFIR Manager, Cyber Risk

Posted 2 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in United Kingdom
Mid level
Remote
Hiring Remotely in United Kingdom
Mid level
The DFIR Manager leads digital forensics and incident response investigations, supporting clients after cyber incidents. Responsibilities include analyzing environments, identifying threats, communicating with stakeholders, and coordinating recovery efforts.
The summary above was generated by AI
Manager, Digital Forensics & Incident Response, Cyber & Data Resilience 

In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate diversity by respecting, including, and valuing one another. As part of One team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel.


Kroll’s Cyber & Data Resilience team is seeking a Digital Forensics & Incident Response (DFIR) Consultant to support organizations through highimpact cyber incidents, investigations, and crisis events. This role is ideal for a practitioner with solid handson DFIR experience who is ready to take greater ownership of investigations, work directly with clients and legal counsel, and contribute to complex, fastmoving response engagements. You will work as part of a global DFIR team responding to incidents such as ransomware, business email compromise, insider threats, data breaches, and advanced intrusions—helping clients contain threats, understand impact, and recover with confidence.

Key Responsibilities:
  • Lead and support digital forensics and incident response investigations across Windows, macOS, Linux, cloud, SaaS, and identity environments 

  • Perform acquisition and analysis across endpoints, servers, cloud, SaaS, identity, and network telemetry while maintaining defensible chain‑of‑custody

  • Identify attacker tradecraft, determine root cause, assess scope and data‑at‑risk, and support threat actor eviction

  • Communicate effectively with all project stakeholders, including clients, outside counsel, insurers and internal teams.
  • Support containment, eradication, and recovery activities in coordination with client security teams and restoration partners 

Required Experience & Skills:
  • 3–5 years of hands‑on experience in digital forensics, incident response, or security operations

  • Experience working across modern environments (EDR/XDR, SIEM, cloud, SaaS, identity platforms)

  • Possess excellent project management skills, with ability to communicate complex technical findings clearly to nontechnical stakeholders

  • Comfortable working under pressure during live incidents, including occasional after‑hours response

Nice to have:
  • Industry certifications such as GCFA, GCFE, GCIH, or similar

  • Experience delivering incident readiness services, such as compromise assessments, IRP/playbook development, tabletops, and cyber range activities

  • Exposure to expert witness support or litigationrelated investigations

#LI-TM1

#LI-Remote

Top Skills

Cloud
Edr/Xdr
Linux
macOS
SaaS
SIEM
Windows

Similar Jobs

12 Hours Ago
Easy Apply
Remote or Hybrid
United Kingdom
Easy Apply
Mid level
Mid level
Artificial Intelligence • Cloud • Security • Software • Cybersecurity
As an Enterprise Sales Engineer, you'll provide technical support during sales processes, deliver presentations to clients, and engage with customers to ensure successful technical evaluations and product integration.
Top Skills: .NetGoJavaNode.jsPHPPythonRuby
12 Hours Ago
Remote
United Kingdom
Entry level
Entry level
Blockchain • Fintech • Analytics • Financial Services • Cryptocurrency • Web3
As a Junior Crypto Trader, you will perform basic trading operations, analyze market trends, and work under a mentor to develop trading skills.
Top Skills: Analytical ToolsMarket DataTrading Tools
12 Hours Ago
In-Office or Remote
London, Greater London, England, GBR
Mid level
Mid level
eCommerce • Marketing Tech • Software • Travel • Hospitality
The Account Executive will handle the end-to-end sales process to onboard affiliates, manage leads, and achieve sales targets to grow PRIMA’s affiliate network in London.
Top Skills: Crm ToolsHubspotSalesforce

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account