Director, Incident Response
KPMG Advisory is at the forefront of transformation, offering excellent opportunities for career advancement and expertise development. Our professionals thrive in a collaborative, team-driven culture with access to world-class training, leading market tools, and a wealth of learning and career development opportunities. We prioritize our people, fostering personal and professional growth while providing flexibility and inspiration to expand capabilities.
About the role
KPMG is seeking a Director, Incident Response to join its Advisory Practice. This role involves leading enterprise cyber incident response engagements, advising executive leadership during crises, and driving operational excellence within high-performing teams. The position supports business growth through client relationship management, solution development, and trusted advisory leadership.
Responsibilities
- Lead enterprise cyber incident response engagements, overseeing containment, investigation, recovery, remediation, and post-incident resilience efforts.
- Advise executive leadership, boards, and key stakeholders during incidents, providing strategic guidance, crisis management, and cross-functional coordination.
- Direct incident investigations, root cause analysis, and remediation initiatives while advancing incident response methodologies, playbooks, and service offerings.
- Oversee, mentor, and quality-control high-performing incident response teams, driving operational excellence, service delivery, performance metrics, and continuous improvement.
- Partner across cybersecurity, risk, privacy, and forensics teams while supporting business growth through client relationship management, solution development, and trusted advisory leadership.
- Act with integrity, professionalism, and personal responsibility to uphold KPMG's respectful and courteous work environment.
Requirements
- Minimum ten years of recent experience in incident response, threat management, digital forensics, security operations, or related cybersecurity disciplines.
- Seven years leading incident response teams and large-scale response engagements.
- CISSP, GCIH, GCFA, GCFE, CISM, or similar certifications preferred.
- Bachelor's degree in business or a related field from an accredited college/university preferred; minimum of a high school diploma or GED required plus twelve years of relevant experience in incident response.
- Strong presence in the digital forensics and incident response market, including conference speaking experience and established relationships within the law firm and insurance sectors (highly preferred).
- Proven experience leading complex cyber incident investigations and response engagements using industry frameworks such as NIST and SANS.
- Expertise across digital forensics, SIEM, EDR/XDR platforms, automation tools, and Windows, Linux, macOS, cloud (Azure, AWS, GCP), networking, and IT/OT environments.
- Demonstrated success building and maturing incident response and cyber resilience programs.
- Strong executive presence, stakeholder management, and the ability to lead multiple high-priority engagements while supporting client relationships and business growth.
- 33% travel requirement.
- Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future (no sponsorship available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT, or any other employment-based visa).
Pay
California Salary Range: $169,005 - $370,530. Salary is determined based on relevant factors including applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications, and market considerations.
Benefits
- Comprehensive medical, dental, and vision coverage.
- Disability and life insurance.
- 401(k) plans.
- Robust suite of personal well-being benefits to support mental health.
- Personal Time Off per fiscal year, based on job classification, standard work hours, and years of service.
- Two annual breaks where employees are not required to use Personal Time Off: one at year-end and one around the July 4th holiday.
- Paid holidays as per the annual KPMG holiday calendar.