> Markdown version of [/jobs/ext/3354435-senior-incident-response-dfir-consultant-engagement-lead](https://www.wearedevelopers.com/jobs/ext/3354435-senior-incident-response-dfir-consultant-engagement-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Incident Response DFIR Consultant - Engagement Lead - **Company:** Zurich Insurance Group - **Location:** Columbus, OH, United States (Remote available) - **Experience:** Expert - **Salary:** $100,200.0 - $164,100.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Linux, Digital Forensics, Forensics Tools (Digital Forensics Software), Log Analysis, Network Forensics, Time Tracking Software, Malware, Cyber Threat Analysis, Encase - **Published:** September 16, 2026 - **Apply:** https://www.columbusjobsite.com/job.asp?id=3394865360&tx=HT7367TTZ&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelors degree and 5 or more years experience in the Cyber Security domainOR * Zurich Cybersecurity Technician Apprentice, including Cyber Security Certification and 6 or more years experience in the Cyber Security domainOR * High School Diploma or Equivalent and 7 or more years experience in the Cyber Security domain Preferred Functional/Technical Skills Qualifications: * Digital Forensics & Incident Response - Proficiency Level Advanced * Threat Intelligence & Malware Analysis - Proficiency Level Intermediate * Client Communication & Stakeholder Management - Proficiency Level Advanced * Windows/Linux Operating System Forensics - Proficiency Level Advanced * Network Forensics & Log Analysis - Proficiency Level Intermediate * Cloud Security (Azure/AWS/M365) - Proficiency Level Intermediate * Forensic Tool Proficiency (EnCase, FTK, X-Ways, Volatility, Binalyze etc.) - Proficiency Level Advanced * Ransomware & Business Email Compromise (BEC) Investigations - Proficiency Level Advanced * Report Writing & Executive Communication - Proficiency Level Advanced * Project Management - Proficiency Level Intermediate * Threat Actor Communications Experience Your pay at Zurich is based on your role, location, skills, and experience. We follow local laws to ensure fair compensation. You may also be eligible for bonuses and merit increases. If your expectations are above the listed range, we still encourage you to apply-your unique background matters to us.The pay range shown is a national average and may vary by location. The proposed Salary range for this position is $100,200.00 - $164,100.00, with short-term incentive bonus eligibility set at 15%. ## Description As a Senior DFIR Consultant, you will act as an incident response engagement lead, focusing on delivering expert consulting and digital forensics services to external clients during urgent cyber security incidents. You will lead complex investigations, will provide strategic guidance during security breaches, and will drive incident containment and recovery efforts. Strong candidates will showcase delivering exceptional client service and build long-term client relationships. This role requires building trust with key partners, including C-level executives, IT leaders, legal counsel, and insurance partners while managing these complex relationships during crisis situations., * Lead incident response engagements for external clients, conducting digital forensics investigations, malware analysis, and threat actor attribution to identify scope, impact, and root cause of security incidents. * Provide 24/7 on-call incident response services, remotely connecting to contain active threats, preserve evidence, and minimize business disruption. * Conduct comprehensive forensic examinations of compromised systems, networks, and cloud environments using industry-standard tools and methodologies to support client remediation and potential legal proceedings. * Deliver executive-level briefings and written reports to clients, translating complex technical findings into business impact assessments and actionable recommendations. * Coordinate with client stakeholders including IT teams, legal counsel, insurance carriers, law enforcement, and executive leadership to manage incident response activities and communication strategies. * Provide expert guidance on ransomware negotiations, business email compromise investigations, insider threat cases, and advanced persistent threat incidents. * Mentor junior consultants and analysts, providing technical guidance and quality assurance on client deliverables. * Maintain detailed case documentation, time tracking, and engagement status reporting to ensure accurate billing and project management. * Partner with insurance brokers, managed service providers, and law firms to provide incident response services as part of cyber insurance claims and breach response protocols. * Stay current on emerging threats, attack techniques, and forensic methodologies through continuous research and professional development. * Contribute to thought leadership initiatives including blog posts, conference presentations, and client education materials. * Business travel, as required Additional Business Accountabilities: * Develop scopes of work and cost estimates for incident response engagements, ensuring projects are appropriately resourced and profitably delivered. * Identify opportunities for expanded client engagements based on investigation findings, security gaps, and client needs. * Support business development activities including client presentations, capability demonstrations, and proposal development for new and existing clients. * Ensure all client deliverables meet quality standards and are delivered within agreed timelines and budgets.