SentinelOne logo
SentinelOnePosted 2 months ago

DFIR Engagement Manager

HybridPrague, Prague, Czechia

Full TimeLargeCybersecurity

Job Summary

Oversee active DFIR investigations from intake through delivery, ensuring exceptional quality, timeliness of deliverables, appropriate resource allocation, and strict adherence to incident response best practices and standard operating procedures. Lead business development and scoping activities, including requirements gathering and contract development, while establishing communication channels with customers, internal teams, breach counsel, and cyber insurance carriers. Direct analytical focus, validate team findings, and manage escalations to maintain investigative momentum throughout the engagement. Maintain oversight of case documentation, evidence handling, and final artifact archival, and lead post-engagement reviews to optimize team workflows. Conduct technical analysis when required, assisting with endpoint forensics, log analysis, and baseline threat hunting, while maintaining flexibility to participate in weekend and holiday on-call schedules.

Required Qualifications

  • 5+ years of hands-on consulting experience in digital forensics and incident response
  • Proven track record of managing complex engagements
  • Expert-level familiarity with industry-standard forensic tools and methodologies
  • Strong project management skills
  • Team leadership skills
  • Excellence in client communication
  • Relationship management skills
  • Experience working with legal teams
  • Experience working with cyber insurance carriers
  • Strong understanding of EDR/XDR platforms
  • Experience with security technologies
  • Demonstrated experience in endpoint-based threat hunting
  • Experience with compromise assessments
  • Experience with cyber threat intelligence platforms and processes
  • Ability to participate in weekend and holiday on-call schedules
  • Only Prague-based employees are required to work from the office at least 2 days//week

Desired Qualifications

  • Experience conducting malware analysis
  • Experience conducting memory forensics
  • Industry certifications such as GCFE, GCFA, CFCE, EnCE, or similar
  • Evident self-starter
  • Intellectual curiosity
  • Ability to adapt to change
  • Active participation in the security community through speaking engagements or publications

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce