Zurich Insurance Group

Senior Incident Response Consultant, DFIR

Zurich Insurance Group$100K — $164K *
US-AnywhereRemote in Missouri, US
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 5+ years in IT or equivalent experience
  • Cyber Security Certification and 6+ years in IT
  • High School Diploma with 7+ years in IT
  • Proficiency in MS Office
  • Understanding of Cyber Security Operations

Responsibilities

  • Lead incident response for external clients and conduct digital forensics
  • Provide 24/7 emergency response, including onsite or remote deployment
  • Conduct forensic examinations of systems and networks
  • Deliver executive briefings and translate technical findings into business insights
  • Coordinate incident response with multiple stakeholders
  • Offer guidance on ransomware negotiations and sophisticated threats
  • Develop proactive incident response services for clients

Benefits

  • Comprehensive health and wellness benefits for employees and families
  • Flexible scheduling for client emergencies
  • Access to professional development and continuous research
  • Encouragement of thought leadership initiatives such as blog writing and presentations
  • Varied work location options including remote and hybrid arrangements
Full Job Description
In this role you make work virtual within the U.S. and extend up to 20% travel.

As a Senior Incident Response Consultant, you will deliver expert incident response and digital forensics services to external clients experiencing cyber security incidents. Leads complex investigations, provides strategic guidance during security breaches, and drives incident containment and recovery efforts. Maintains 75% billable utilization while delivering exceptional client service and building long-term client relationships. The job's core deliverables rely on delivering expert consulting services to external clients during high-stress security incidents. Requires building trust with C-level executives, IT leaders, legal counsel, and insurance partners while managing complex multi-stakeholder relationships during crisis situations.

Key Accountabilities:

  • Lead incident response engagements for external clients, conducting digital forensics investigations, malware analysis, and threat actor attribution to identify scope, impact, and root cause of security incidents.
  • Provide 24/7 on-call emergency response services, rapidly deploying to client sites or remotely connecting to contain active threats, preserve evidence, and minimize business disruption.
  • Conduct comprehensive forensic examinations of compromised systems, networks, and cloud environments using industry-standard tools and methodologies to support client remediation and potential legal proceedings.
  • Deliver executive-level briefings and written reports to clients, translating complex technical findings into business impact assessments and actionable recommendations.
  • Coordinate with client stakeholders including IT teams, legal counsel, insurance carriers, law enforcement, and executive leadership to manage incident response activities and communication strategies.
  • Provide expert guidance on ransomware negotiations, business email compromise investigations, insider threat cases, and advanced persistent threat incidents.
  • Develop and deliver incident response retainer services, conducting proactive readiness assessments, tabletop exercises, and security program evaluations for client organizations.
  • Mentor junior consultants and analysts, providing technical guidance and quality assurance on client deliverables.
  • Maintain detailed case documentation, time tracking, and engagement status reporting to ensure accurate billing and project management.
  • Partner with insurance brokers, managed service providers, and law firms to provide incident response services as part of cyber insurance claims and breach response protocols.
  • Stay current on emerging threats, attack techniques, and forensic methodologies through continuous research and professional development.
  • Contribute to thought leadership initiatives including blog posts, conference presentations, and client education materials.
  • Business Travel, as required (may be extensive during active incidents) as well as extended hours during Active Incidents/24x7 On-call Rotation, flexible scheduling to accommodate client emergencies and time-sensitive investigations, as required.


Additional Business Accountabilities:

  • Develop scopes of work and cost estimates for incident response engagements, ensuring projects are appropriately resourced and profitably delivered.
  • Identify opportunities for expanded client engagements based on investigation findings, security gaps, and client needs.
  • Support business development activities including client presentations, capability demonstrations, and proposal development for new and existing clients.
  • Ensure all client deliverables meet quality standards and are delivered within agreed timelines and budgets.


Basic Qualifications:

  • Bachelors degree and 5 or more years experience in the Information Technology area
    OR
  • Zurich Cybersecurity Technician Apprentice, including Cyber Security Certification and 6 or more years experience in the Information Technology area
    OR
  • High School Diploma or Equivalent and 7 or more years experience in the Information Technology area
    AND
  • MS Office experience
    AND
  • Knowledge of Cyber Security Operations


Preferred Functional/Technical Skills Qualifications:

  • Digital Forensics & Incident Response - Proficiency Level Advanced
  • Threat Intelligence & Malware Analysis - Proficiency Level Intermediate
  • Client Communication & Stakeholder Management - Proficiency Level Advanced
  • Windows/Linux System Forensics - Proficiency Level Advanced
  • Network Forensics & Log Analysis - Proficiency Level Intermediate
  • Cloud Security (Azure/AWS/M365) - Proficiency Level Intermediate
  • Forensic Tool Proficiency (EnCase, FTK, X-Ways, Volatility, etc.) - Proficiency Level Advanced
  • Ransomware & BEC Investigations - Proficiency Level Advanced
  • Report Writing & Executive Communication - Proficiency Level Advanced
  • Project Management - Proficiency Level Intermediate


Your pay at Zurich is based on your role, location, skills, and experience. We follow local laws to ensure fair compensation. You may also be eligible for bonuses and merit increases. If your expectations are above the listed range, we still encourage you to apply-your unique background matters to us. The pay range shown is a national average and may vary by location. The proposed Salary range for this position is $100,200.00 - $164,100.00, with short-term incentive bonus eligibility set at 15%.

We offer competitive pay and comprehensive benefits for employees and their families. [Learn more about Total Rewards here.]

Location(s): AM - Missouri Virtual Office, AM - Remote Work (US)
Remote Working: Hybrid
Schedule: Full Time
Employment Sponsorship Offered: No

Linkedin Recruiter Tag: #LI-AW1 #LI-ASSOCIATE #LI-REMOTE

About Zurich Insurance Group

Zurich Insurance Group is a Swiss insurance company founded in 1872. It is one of the world's largest insurance companies, operating in over 215 countries and territories. Zurich provides a wide range of insurance products and services, including property and casualty insurance, life insurance, and pensions. The company is committed to sustainability and has set ambitious targets to reduce its carbon footprint and promote renewable energy. Zurich is also actively involved in supporting local communities through various charitable initiatives.
Learn more about Zurich Insurance Group
Size
52,930 employees
Industry
NASDAQ

Similar Jobs

More Jobs at Zurich Insurance Group

More Information Technology Jobs

Find similar Senior Incident Response Consultant, DFIR jobs: