Digital Forensics and Incident Response Advisory - Manager
About the Role
We currently have an exciting career opportunity for a Manager to join the Cybersecurity and Digital Trust team in our Risk Advisory practice. This position is considered hybrid which means team members are expected to be thoughtful and intentional in how they create opportunities for in-person collaboration. While the cadence of in-office presence is determined at the team level, our professionals are encouraged to be in the office/together in person on average 3 days a week.
Your Team
Join a diverse team of fun-loving, energetic professionals with decades of experience managing security, technology, and privacy risks in nearly every industry sector who have a passion for creating tailored solutions that go beyond technology offerings or tools and help clients reduce cost of compliance while mitigating risks.
Why CohnReznick?
At CohnReznick, we're united by a common mission to create opportunity, value, and trust for our clients, our people, and our communities. Whether it's working alongside your peers to solve a client challenge, or volunteering together at the local food bank, there are so many ways to find your "why" at the firm. We believe it's important to balance work with everyday life – and make time for enjoyment and fun. We invest in a robust Total Rewards package that includes everything from generous PTO, a flexible work environment, expanded parental leave, extensive learning & development, and even paid time off for employees to volunteer.
Responsibilities
- Be part of the incident response and forensics team for complex cybersecurity incidents, including advanced persistent threats (APTs), ransomware, data breaches, and insider threats
- Perform computer/digital forensics work on real investigations using various digital forensic tools and techniques
- Lead and mentor staff along the way
- Assist in developing forensic tools and techniques and support other projects in the Cybersecurity and Digital Trust practice
- Help build and lead the incident response team and assist with developing new business
- Create forensic images of computers, cell phones and other electronic devices under investigation
- Perform deep-dive forensic analysis of endpoints (Windows, macOS, Linux), servers, and mobile devices to determine the root cause, scope, and impact of an intrusion. This includes disk, memory, and artifact analysis
- Serve as the lead on incidents, managing resources, presenting findings and effectively advising the client
- Monitor your own work and that of your team on assignments, ensuring high quality and value is delivered to the client
- Assist in briefing clients and attorneys
- Mentor junior analysts, providing technical guidance, and contributing to the overall skill development of the team
- Remediate impacted systems though building computers/servers, configuring servers, firewalls and other key network infrastructure
- Monitor servers and network infrastructure for anomalies and assist in diagnosis
- Lead vulnerability scanning and remediation efforts
- Conduct and lead cybersecurity assessments using various industry benchmarks and frameworks
- Assist in developing new service lines and bring them to market
Qualifications
- 6+ years of experience in hands-on technology roles, with a proven track record of service delivery
- 4+ years of experience in digital forensics and incident response
- Proficiency with DFIR tools such as KAPE, Velociraptor, Volatility, Elasticsearch, SentinelOne, Falcon, EnCase and others
- Mastery of operating system internals and forensic artifacts (Windows, Linux, or macOS)
- Deep understanding of M365 security and forensics analysis techniques
- Problem solving skills and ability to learn quickly
- Strong business writing and communication skills
- Strong work ethic and desire to meet client demands
- The ability to multi-task in a dynamic team environment
- Ability to author detailed, high-quality technical reports for various audiences, including technical teams, executive leadership, and legal counsel
- Clearly articulate complex technical findings to non-technical stakeholders
- Willingness to assist on non-DFIR engagements
- Bachelor's degree in Computer Science, Engineering, Information Technology, Information Systems, or a related field required
- Relevant industry certifications (e.g., CISSP, GCFE, EnCE, ACE, CEH) are a plus
- Experience administering Microsoft Windows, Windows Server and Microsoft 365 environments
- Experience with AWS security & incident response
Pay
In Virginia, the salary range for a Manager is $100,000 to $180,000. Salary is one component of the CohnReznick total rewards package, which includes a discretionary performance bonus, generous paid time off, expanded and inclusive parental benefits, and access to best-in-class learning and development platforms, to name a few.
Schedule
Occasional domestic and possibly international travel may be involved, sometimes with short notice. Government security clearance is not required but a private background check and screening will be conducted.