Cloud Cyber Incident Response Manager

Booz Allen Hamilton

McLean (VA)

On-site

USD 180,000 - 260,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Booz Allen Hamilton seeks a Cloud Cyber Incident Response Manager to lead and grow our cloud DFIR teams across multiple engagements. You will direct investigations, coordinate with legal and executives, and drive strategic incident response initiatives.

You will mentor senior staff, foster a culture of technical excellence, and collaborate with cross-functional teams to expand client relationships and service offerings.

Qualifications

  • Bachelor-level degree in a relevant field is required or equivalent experience.
  • Experience leading incident response and digital forensics teams.
  • Proven ability to communicate complex findings to executives.

Responsibilities

  • Provide strategic direction for cloud DFIR across multiple teams and clients.
  • Oversee investigations, ensure regulatory and contract compliance, and deliver to executives.
  • Develop and manage senior personnel, career development, and performance.
  • Represent the firm in client meetings, industry events, and market-facing activities.
  • Identify opportunities to expand services and grow the DFIR practice.

Skills

Leadership
Incident response
Digital forensics
Client relationship management
Strategic direction
People management
Executive communication

Education

Bachelor's degree in Cybersecurity, CS, Business Administration, or Digital Forensics

Tools

Elastic
Splunk
AWS Athena

Job description

Cloud Cyber Incident Response Manager The Opportunity:

Serve as a member of the cloud cyber incident response leadership team, responsible for the strategic direction, operational performance, client delivery, and continued growth of multiple incident response teams. Oversee complex digital forensic investigations and cybersecurity incident response management across cloud environments, ensuring investigations are conducted effectively, consistently, and in alignment with client, legal, regulatory, and business requirements. Serve as a senior advisor during high-severity incidents and communicate with client executives, legal counsel, cyber insurance carriers, regulators, and other key stakeholders. Lead and develop team leads and senior personnel, including responsibility for career management, employee development, performance management, and disciplinary actions. Promote a culture of accountability, collaboration, technical excellence, and strong client service. Maintain and strengthen relationships with breach counsel, law firm s, and corporate clients. Support new business opportunities, help expand existing relationships, and contribute to the continued growth of the DFIR practice. Oversee the performance and operations of incident response teams, including team leads and senior technical personnel. Establish and maintain DFIR policies, standards, procedures, investigative methodologies, and documentation requirements. Provide senior-level oversight for high-severity cybersecurity incidents and complex forensic investigations. Serve as the senior escalation point for major incidents, sensitive matters, client concerns, and investigative decisions. Review significant findings, investigative reports, executive briefings, timelines, and client deliverables. Communicate material findings, risks, limitations, and recommendations to executive, legal, technical, and non-technical audiences. Provide career management, employee development, performance feedback, and professional coaching. Address performance and conduct concerns, including corrective and disciplinary actions in coordination with Human Resources and senior leadership. Contribute to revenue, pipeline, account growth, and broader practice development objectives. Collaborate with legal, Human Resources, privacy, compliance, and risk teams during sensitive investigations. Ensure investigative activities comply with applicable legal, privacy, contractual, and regulatory requirements. Identify opportunities to improve investigative processes, automation, service offerings, and technical capabilities. Represent the organization at client meetings, industry events, conferences, and other market-facing activities. Due to the nature of work performed within this facility, U.S. citizen ship is required .

You Have:
  • 7+ years of experience in digital forensics, incident response, cybersecurity investigations, or cyber risk
  • 3+ years of experience leading incident response teams, forensic investigation teams, or cybersecurity functions
  • Experience managing multiple teams, senior technical personnel, or a geographically distributed workforce, and leading complex cybersecurity incidents involving executive, legal, insurance, or regulatory stakeholders
  • Experience serving as a senior advisor during significant cyber incidents such as ransomware, data breach, or business email compromise
  • Experience with employee development, career management, performance management, and disciplinary actions
  • Experience developing and maintaining client relationships within the cyber insurance, legal, incident response, or cybersecurity markets, and investigating incidents in cloud platforms, including AWS, Azure, or GCP
  • Knowledge of digital forensic met hodologies, evidence preservation, chain of custody, investigative documentation, and defensible reporting
  • Ability to develop scripts and utilize log and data analysis platforms, including Elastic, Splunk, or AWS Athena
  • Ability to identify new opportunities, expand client relationships, contribute to business growth, and communicate technical findings and business risks to executives, boards, legal counsel, insurers, and senior stakeholders
  • Bachelor's degree in Cybersecurity, CS, Business Administration, or Digital Forensics
Nice If You Have:
  • Experience building or expanding a digital forensics or incident response practice
  • Experience building client relationships
  • Experience working with cyber insurance carriers, claims teams, insurance brokers, breach counsel, and insured organizations
  • Experience with pipeline management, utilization, profitability, and e nga gement economics
  • Experience negotiating statements of work, master services agreements, retainers, pricing structures, or preferred-provider arrangements
  • Experience developing thought leadership, executive briefings, conference presentations, or market-facing content
  • Ability to develop and grow a portfolio of business
  • Master's degree in Cybersecurity, CS, Business Admin
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response Lead & Forensics Expert
Senior Incident Response Lead & Forensics Expert

Compunnel, Inc. • Jersey City (NJ)

On-site
USD 100,000 - 130,000
Incident Response & DFIR Lead
Incident Response & DFIR Lead

Greenhouse Software, Inc. • United States

Remote
USD 120,000 - 210,000
Vacation days
Sick leave
Public holidays
+5
Cyber Defense Incident Responder - Associate Director
Cyber Defense Incident Responder - Associate Director

Ernst & Young Advisory Services Sdn Bhd • Hoboken (NJ)

On-site
USD 140,000 - 210,000
Incident Responder
Incident Responder

SOClogix • Catonsville (MD)

Hybrid
USD 100,000 - 145,000
Health, dental, and vision insurance
401(k) with company match
Unlimited PTO
+1
Digital Forensics and Incident Response (DFIR) Specialist
Digital Forensics and Incident Response (DFIR) Specialist

Zoho • United States

On-site
USD 140,000 - 210,000
Senior Digital Forensics and Incident Response Analyst
Senior Digital Forensics and Incident Response Analyst

SentinelOne, Inc. • United States

On-site
USD 140,000 - 210,000
Medical, dental, and vision coverage
Employee assistance program
Gym reimbursement
+4
Director, DFIR (Remote)
Director, DFIR (Remote)

Surefire Cyber Inc. • Northern (KY)

Remote
USD 150,000 - 190,000
Competitive pay
PTO
Medical & dental coverage
+2
Senior DFIR Investigator & Incident Response Leader
Senior DFIR Investigator & Incident Response Leader

Prescient Comply • Chicago (IL)

On-site
USD 80,000 - 110,000
Incident Response Analyst - Americas
Incident Response Analyst - Americas

The Carlyle Group • Washington

On-site
USD 120,000 - 180,000
Incident Response Manager
Incident Response Manager

Fortuna Cysec • Atlanta (GA)

On-site
USD 100,000 - 150,000