Director, Digital Forensics & Incident Response
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+1 more
Job description
The Digital Forensics & Incident Response (DFIR) team operates within MassMutual’s Cyber Fusion Center, the organization responsible for enterprise-wide threat detection, monitoring, and response. As the DFIR Director, you will lead a global team that safeguards the company by detecting, analyzing, and responding to cyber threats in real time. This is a strategic leadership role accountable for strengthening the company’s forensic capabilities, incident response readiness, and overall cyber resilience.
The Team
You will oversee a globally distributed DFIR team operating in a follow-the-sun model with analysts across the U.S., India, and Romania. The team conducts deep forensic analysis, leads incident response efforts, and supports investigations deriving from a range of stakeholders throughout the company. You will collaborate closely with Security Operations, Threat Intelligence, Offensive Security, Security Engineering, IAM, Network Security, and other cybersecurity functions to ensure cohesive, coordinated defense across the enterprise., * Own and advance all DFIR operations in alignment with MassMutual’s cybersecurity strategy and regulatory obligations.
- Establish strategic priorities, develop long-term capability roadmaps, and champion continuous program improvement.
- Partner with SOC, Threat Intelligence, and Offensive Security leadership to ensure cohesive, enterprise-wide threat defense.
- Oversee DFIR metrics, staffing plans, and budget requirements while guiding strategic investment decisions.
- Drive Incident Response Excellence
- Oversee the response to cybersecurity events and major incidents, ensuring appropriate analysis, prioritization, escalation, and communications.
- Maintain and continually enhance standardized incident handling processes to improve consistency and reduce response times.
- Ensure high-quality executive communication, including incident impact summaries and recommended actions for senior leadership.
- Strengthen Communication & Enterprise Collaboration
- Build and maintain relations with key stakeholders from across the company (to include Law, Compliance, HR, and other security teams).
- Serve as the escalation point for cross-functional coordination during investigations and major events.
- Ensure timely, risk-aware decisions and clear communication of incident impacts and recommended actions., * Continually evaluate and enhance forensic toolsets, processes, and methodologies across endpoint, cloud, and network environments.
- Establish and enforce evidence handling standards, including collection, preservation, and chain-of-custody practices.
- Drive automation to increase analyst efficiency, improve data quality, and streamline response workflows.
- Build and Inspire a High-Performing Global Team
- Lead, mentor, and develop a geographically distributed team of DFIR analysts and managers.
- Create a culture of inclusion, innovation, continuous improvement, and professional growth consistent with MassMutual’s values.
- Support ongoing skill advancement through hands-on exercises, simulations, certifications, and cross-training opportunities., In addition to top-line medical and dental coverage, personalized mental health solutions, on-site and virtual health coaching, and much more, MassMutual reimburses employees up to $1,250 per year for eligible expenses supporting mental, physical, and financial well-being.
Requirements
Do you have experience in Team supervision?, Do you have a Master’s degree?, * Bachelor’s Degree or equivalent professional experience
- 8+ Years of experience in cybersecurity operations, including digital forensics, incident response, threat intelligence, cyber investigations, detection engineering, or related domains-with demonstrated impact improving organizational capabilities.
- 2+ years of experience leading large, globally distributed technical teams in high-pressure operational environments.
- Flexibility to support off hours and weekends on call, * Master’s degree in cybersecurity or related discipline.
- Relevant certifications such as CISSP, GIAC, CISM, OSCP, or similar.
- Experience collaborating with stakeholders such as Audit, Compliance, Risk Management, and external regulators.
- Passion for continuous learning and staying current with emerging threats, forensic techniques, and adversary behaviors.
- Experience leading global DFIR or SOC teams.
- Familiarity with cloud-based forensic and detection technologies (AWS, Azure, GCP).
- Experience maturing DFIR programs through automation, tooling modernization, and data-driven improvements.
- Proven experience leading multidiscipline security teams and driving operational strategy in complex cybersecurity environments.
- Deep understanding of incident response best practices and experience coordinating responses to both small-scale and large-scale incidents.
- Strong background in endpoint and network forensics, log analysis, and forensic tooling.
- Excellent communication and executive reporting skills, including the ability to translate technical analysis for non-technical audiences.
- Demonstrated success developing cybersecurity playbooks, workflows, and security exercises.
- Experience operating in regulated, risk-driven environments with the ability to communicate technical and analytic outcomes to non-technical audiences.
Benefits & conditions
3.73.7 out of 5 stars Remote $156,000 - $204,700 a year - Full-time, Pulled from the full job description
- Tuition reimbursement
- 401(k)
- Health insurance
- Paid time off
- Dental insurance
- Bereavement leave
- Commuter assistance, There’s more to your life than your job and there’s more to your aspirations than a paycheck. We take a holistic view of compensation and benefits that provides the flexibility to create a healthy balance in your life for work, family, and community. We offer the benefits you’d expect, like medical, dental, 401(k), and generous vacation time, but we also offer ones you might not expect, like three paid days for volunteering, a $1,250 annual Well-Being Wallet, and up to 320 hours of caregiver leave.
Explore some of our offerings below.
Paid Time Off
- In addition to generous vacation time, paid holidays, and flexible holidays, MassMutual offers ‘take care’ time to care for yourself or someone you love-whether for physical illness or mental health., In addition to competitive salaries and bonuses, educational assistance programs, and much more, MassMutual offers up to a 10% total 401(k) benefit, consisting of a 5% company match and a 5% annual contribution.
Taking Care
MassMutual offers generous maternity and parental leaves, as well as bereavement leave to mourn the loss of a loved one (and the employee defines ‘loved one’). In addition, we offer up to 320 hours of caregiver leave to help employees support loved ones in times of need.
About the company
MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect:
- Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes
- A collaborative environment where perspectives are welcomed
- Access to learning, development, and internal networks that support continuous growth and skill-building over time
- Employee-led communities and forums that foster connection, learning, and inclusion across the organization
- A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset, MassMutual will accept applications on an ongoing basis until such time as a candidate has been offered employment. The job description includes the main duties of this position, which may evolve over time. You may be required to perform other duties not listed.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. Salary Range: $156,000-$204,700
Award-Winning Culture
MassMutual is guided by a single purpose: We help people secure their future and protect the ones they love. As a company operated for the benefit of our members and participating policyowners, we are defined by mutuality and our vision to provide financial well-being for all Americans. It’s more than our company structure - it’s our way of life. We are a company of people protecting people. Our company exists because people are willing to share risk and resources and rely on each other when it counts.
We strive to build a thriving community where everyone is valued, included, and feels that they belong.
At MassMutual, we Live Mutual.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
From developer to manager – what does it take to become an engineering manager?
Best Companies to work for in London: Top 25 Companies in 2023
Best Paying Remote Jobs