> Markdown version of [/jobs/ext/241427-incident-response-dfir-case-manager-cybersecurity](https://www.wearedevelopers.com/jobs/ext/241427-incident-response-dfir-case-manager-cybersecurity). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Incident Response (DFIR) Case Manager - Cybersecurity - **Company:** FRSecure LLC - **Location:** Edina, MN, United States (Remote available) - **Experience:** Experienced - **Salary:** $85,000.0 - $116,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Cyber Security, Computer Forensics, Networking Hardware, Microsoft Office, Productivity Software, Security Information and Event Management, Data Logging, Cloud Platform System, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Cybercrime - **Published:** May 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=73cff25e8b31f25c ## About the Role Do you have experience in Productivity software?, * 3-5 years of information security experience * 3-5 years of experience with Active Directory, Systems Administration, Exchange Administration, M365 and/or other cloud environments * 3-5 years of experience in presenting information security concepts * GCIH, GCFA, ECIH certifications preferred * Prior experience in threat hunting and/or incident handling * Prior experience in management of EDR and/or SIEM technologies * Experience with firewalls and network devices best practices and logging * Solid understanding of computer systems administration in large environments * Demonstrated analytical skills to interpret data, identify trends, and ensure accuracy in all deliverables * Ability to clearly convey complex information to diverse audiences and actively listen to understand needs and provide effective solutions * Proven customer service skills with a customer-focused mindset, including the ability to build relationships, resolve issues effectively, and deliver a positive, responsive client experience * Ability to communicate highly technical topics to non-technical people effectively * Ability to handle and work with large amounts of data * Proficient with all Microsoft Office Suite products ## Description Position Summary: The Incident Response (DFIR) Case Manager is responsible for providing support to clients when they have become or suspect they may be the victim of a cyber-attack. This is done by conducting high quality and timely incident response investigations in environments of varying security maturity including identification and containment phases and advising clients regarding recovery and remediation steps to assist them in returning to normal business operations. Our Incident Response Case Managers have a blend of proactive project responsibilities, such as leading tabletops and plan coaching, as well as triage and case work. Working Location: This position is available on a full-time remote basis in the following states: Arizona, Colorado, Florida, Georgia, Idaho, Illinois, Kansas, Kentucky, Massachusetts, Michigan, Minnesota, Montana, North Carolina, Ohio, Pennsylvania, South Dakota, Tennessee, Texas, Washington, and Wisconsin. Only candidates located in the United States will be considered. Office headquarters and operational business hours are based in Edina, MN (Central Time). Application Deadline: June 5, 2026 What Your Day Looks Like as an Incident Response (DFIR) Case Manager: * Performing a forensic review of client systems for artifacts and indicators of compromise (IOCs) to further identify, contain, and eradicate malware and/or malicious intruders * Conducting triage, threat-hunting, and case management for incident response clients * Documenting detailed evidence, findings, and create a report output * Meeting with clients during the planning, information sharing, and technical support stages * Creating and delivering proactive projects to clients including tabletop exercises, plan coaching, assessments * Conducting regular calls with clients to consult on incident response programs * Continue education by researching and investigating developments in cyber forensics/attack methodologies; increase existing skillset to handle these matters * Attending and participating in regular internal meetings * Participating in on-call rotation, providing timely and effective support to clients, ensuring adherence to service level agreements (SLAs) and resolving issues within established response and resolution times * Performing periodic after-hours and weekends on-call work Working Hours: Standard working hours for this position are between 8:00am-5:00pm in the time zone in which the employee is based, with the expectation that there may be client calls, project/task responsibilities, meetings, or other company obligations in which the employee will need to work outside of these hours, as standard business hours are 8:00am-5:00pm Central Time. This position also includes on-call responsibilities. On-call duty will be 1 week in duration with the on-call assignment being dependent upon the number of Case Managers on the team. During the on-call rotation, the employee will be required to monitor an email inbox for incoming CSIRT requests as well as answer incoming calls to the CSIRT after-hours hotline and perform incident triage duties. Travel: There is minimal travel associated with this position, typically less than 5-10%. Occasional travel includes conferences or on-site client projects as needed, as well as any team or company activities. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)