DFIR / Incident Response Manager
Location: Remote within Canada
Employment Type: Full-time, Permanent The Opportunity
We are seeking a hands-on DFIR / Incident Response Manager to lead external clients through active cyber incidents, including ransomware attacks, business email compromise, data breaches, malware infections, and other high-severity security events.
This role requires someone who can act as a primary responder and incident lead , taking ownership of an engagement from the initial breach notification through containment, investigation, eradication, recovery, and post-incident review. You will work directly with client leadership, technical teams, legal counsel, breach coaches, and cyber insurance providers to coordinate an effective response during high-pressure situations.
This is not a traditional SOC management or detection engineering position. The successful candidate will have direct experience responding to active breaches and leading client-facing DFIR engagements.
Key Responsibilities
- Act as the primary responder, incident lead, or incident commander during active client incidents.
- Lead the full incident response lifecycle, including triage, containment, forensic investigation, eradication, recovery, and post-incident review.
- Manage end-to-end response activities for ransomware attacks, business email compromise, malware incidents, account compromise, data breaches, and unauthorized access.
- Conduct hands-on digital forensic investigations across endpoints, networks, cloud platforms, identity environments, and Microsoft 365.
- Determine the initial attack vector, affected systems, threat actor activity, scope of compromise, persistence mechanisms, and potential data exposure.
- Coordinate technical response activities across internal teams, client stakeholders, and third-party service providers.
- Provide transparent updates, recommendations, and executive briefings throughout active incidents.
- Develop incident timelines, forensic findings, root cause analyses,
and post-incident reports.
- Guide clients through containment, system restoration, credential resets, remediation, and security hardening.
- Work alongside legal counsel, breach coaches, cyber insurance providers, and other stakeholders during breach investigations.
- Lead or support tabletop exercises, cyber crisis simulations, and incident response readiness engagements.
- Develop and improve incident response plans, playbooks, escalation procedures, and supporting documentation.
- Mentor incident responders and provide technical oversight during complex investigations.
- Participate in an on-call rotation and remain available for time-sensitive security incidents when required.
Required Experience
- Hands-on experience in digital forensics and incident response , with responsibility for active cyber incidents.
- Experience leading external clients through the full incident response lifecycle .
- Direct experience leading or playing a primary role in ransomware response and recovery engagements.
- Experience investigating business email compromise, identity compromise, malware, unauthorized access, and data exposure.
- Experience acting as an incident lead, incident commander, engagement lead, or primary responder.
- Experience conducting forensic investigations using endpoint, network, identity, cloud, and security telemetry.
- Experience communicating technical findings and business risk to executive and non-technical stakeholders.
- Experience producing investigation reports, incident timelines, root cause analyses, and remediation recommendations.
- Background within a DFIR consultancy,
cybersecurity consulting firm, MSSP, breach response provider, or incident response services environment.
- Ability to manage several technical and stakeholder workstreams during high-pressure incidents.
Preferred Experience
- Experience working with breach coaches, legal counsel, cyber insurance carriers, and regulatory stakeholders.
- Experience leading tabletop exercises and executive cyber crisis simulations.
- Experience investigating Microsoft 365, Entra ID, Azure, AWS, Active Directory, and hybrid environments.
- Knowledge of forensic evidence collection, preservation, chain of custody, and forensic analysis procedures.
- Experience deploying EDR technology during active incidents and using it to support containment and investigation.
- Experience with tools such as CrowdStrike Falcon, Microsoft Defender, SentinelOne, Microsoft Sentinel, Splunk, EnCase, Magnet AXIOM, Velociraptor, Volatility, or similar platforms.
- Relevant certifications such as GCIH, GCFA, GCFE, GNFA, GREM, EnCE, CISSP, or comparable credentials.
What You Bring
- The ability to remain calm and provide direction during high-pressure breach situations.
- Strong technical investigation and problem-solving skills.
- Clear client-facing communication and executive presentation skills.
- The ability to lead engagements while remaining hands-on with technical response activities.
- Strong judgment when balancing containment, business continuity, evidence preservation, and recovery requirements.
- A collaborative approach to working with clients, legal teams, insurers, technical responders, and executive stakeholders.
Why Join? This position offers the opportunity to lead complex DFIR engagements for organizations globally while working remotely. You will play a central role in helping clients contain active threats, understand what occurred, recover critical operations, and strengthen their security following an incident.
📌 Incident Responder Manager (Canada)
🏢 Hays
📍 Canada