Digital Forensics and Incident Response, Senior Manager

Booz Allen HamiltonWashington, DC
$142,900 - $266,000Remote

About The Position

Serve as a member of the Digital Forensics and Incident Response leadership team, responsible for the strategic direction, operational performance, client delivery, and continued growth of multiple incident response teams. Oversee complex digital forensic investigations and cybersecurity incident response engagements, ensuring investigations are conducted effectively, consistently, and in alignment with client, legal, regulatory, and business requirements. Serve as a senior advisor during high-severity incidents and communicate with client executives, legal counsel, cyber insurance carriers, regulators, and other key stakeholders. Lead and develop team leads and senior personnel, including responsibility for career management, employee development, performance management, and disciplinary actions. Promote a culture of accountability, collaboration, technical excellence, and strong client service. Maintain and strengthen relationships with cyber insurance carriers, insurance brokers, breach counsel, law firms, and corporate clients. Support new business opportunities, help expand existing relationships, and contribute to the continued growth of the DFIR practice. Oversee the performance and operations of two or more incident response teams, including team leads and senior technical personnel. Maintain DFIR policies, standards, procedures, investigative methodologies, and documentation requirements. Provide senior level oversight for high-severity cybersecurity incidents and complex forensic investigations. Serve as the senior escalation point for major incidents, sensitive matters, client concerns, and investigative decisions. Review significant findings, investigative reports, executive briefings, timelines, and client deliverables. Communicate material findings, risks, limitations, and recommendations to executive, legal, technical, and non-technical audiences. Provide career management, employee development, performance feedback, and professional coaching. Address performance and conduct concerns, including corrective and disciplinary actions in coordination with Human Resources and executive leadership. Contribute to revenue, pipeline, account growth, and broader practice-development objectives. Collaborate with Legal, Human Resources, Privacy, Compliance, and Risk teams during sensitive investigations. Ensure investigative activities comply with applicable legal, privacy, contractual, and regulatory requirements. Identify opportunities to improve investigative processes, automation, service offerings, and technical capabilities. Represent the organization at client meetings, industry events, conferences, and other market-facing activities.

Requirements

  • 7+ years of experience in digital forensics, incident response, cybersecurity investigations, or cyber risk
  • 3+ years of experience leading incident response teams or forensic investigation teams
  • Experience managing multiple teams, team leads, senior technical personnel, or a geographically distributed workforce
  • Experience leading complex cybersecurity incidents involving executive, legal, insurance, or regulatory stakeholders and serving as a senior advisor during ransomware, data breach, business email compromise, or insider threat
  • Experience with employee development, career management, performance management, and disciplinary actions
  • Experience developing and maintaining client relationships within the cyber insurance, legal, incident response, or cybersecurity markets
  • Knowledge of digital forensic methodologies, evidence preservation, chain of custody, investigative documentation, and defensible reporting
  • Ability to identify new opportunities, expand client relationships, contribute to business growth, and communicate technical findings and business risks to executives, boards, legal counsel, insurers, and other senior stakeholders
  • Ability to travel up to 25% of the time and work outside standard business hours as required
  • Bachelor’s degree in Cybersecurity, Computer Science, Business Administration, or Digital Forensics

Nice To Haves

  • Experience building or expanding a digital forensics or incident response practice
  • Experience working with cyber insurance carriers, claims teams, insurance brokers, breach counsel, and insured organizations
  • Experience with pipeline management, utilization, profitability, and engagement economics
  • Experience negotiating statements of work, master services agreements, retainers, pricing structures, or preferred-provider arrangements
  • Experience developing thought leadership, executive briefings, conference presentations, or market-facing content
  • Ability to demonstrate client relationships and develop and grow a portfolio of business
  • Master’s degree in Cybersecurity, Computer Science, Business Administration, Digital Forensics, or a related field
  • CISSP, CISM, GCFA, GCIH, GREM, GNFA, EnCE, CFCE, CCE, or a comparable certification

Responsibilities

  • Serve as a member of the Digital Forensics and Incident Response leadership team, responsible for the strategic direction, operational performance, client delivery, and continued growth of multiple incident response teams.
  • Oversee complex digital forensic investigations and cybersecurity incident response engagements, ensuring investigations are conducted effectively, consistently, and in alignment with client, legal, regulatory, and business requirements.
  • Serve as a senior advisor during high-severity incidents and communicate with client executives, legal counsel, cyber insurance carriers, regulators, and other key stakeholders.
  • Lead and develop team leads and senior personnel, including responsibility for career management, employee development, performance management, and disciplinary actions.
  • Promote a culture of accountability, collaboration, technical excellence, and strong client service.
  • Maintain and strengthen relationships with cyber insurance carriers, insurance brokers, breach counsel, law firms, and corporate clients.
  • Support new business opportunities, help expand existing relationships, and contribute to the continued growth of the DFIR practice.
  • Oversee the performance and operations of two or more incident response teams, including team leads and senior technical personnel.
  • Maintain DFIR policies, standards, procedures, investigative methodologies, and documentation requirements.
  • Provide senior level oversight for high-severity cybersecurity incidents and complex forensic investigations.
  • Serve as the senior escalation point for major incidents, sensitive matters, client concerns, and investigative decisions.
  • Review significant findings, investigative reports, executive briefings, timelines, and client deliverables.
  • Communicate material findings, risks, limitations, and recommendations to executive, legal, technical, and non-technical audiences.
  • Provide career management, employee development, performance feedback, and professional coaching.
  • Address performance and conduct concerns, including corrective and disciplinary actions in coordination with Human Resources and executive leadership.
  • Contribute to revenue, pipeline, account growth, and broader practice-development objectives.
  • Collaborate with Legal, Human Resources, Privacy, Compliance, and Risk teams during sensitive investigations.
  • Ensure investigative activities comply with applicable legal, privacy, contractual, and regulatory requirements.
  • Identify opportunities to improve investigative processes, automation, service offerings, and technical capabilities.
  • Represent the organization at client meetings, industry events, conferences, and other market-facing activities.

Benefits

  • health, life, disability, financial, and retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service