Engagement Manager

USD 132,000-160,000 per year
SENIOR
✅ Remote

Tech Stack

Communication @ 6 Leadership @ 7 Project Management @ 6 Security @ 7

Details

SentinelOne's Digital Forensics and Incident Response (DFIR) team delivers rapid, expert breach response to global enterprises facing active cyber threats, including ransomware, business email compromise, identity compromise, zero-day exploitation, advanced persistent threat activity, and cloud/SaaS breaches.

As an Engagement Manager, you will own the full lifecycle of DFIR investigations, from scoping and staffing through budget management and delivery. You will serve as the primary point of contact between DFIR analysts and stakeholders, including account teams, customer executives, breach counsel, and cyber insurance carriers. The role requires the ability to move between technical detail and executive-level conversations during high-stakes incidents.

The role is available in the United States for candidates in the Pacific, Mountain, Alaska, or Hawaii time zones. U.S. citizenship and FedRAMP eligibility are required to support occasional investigations for FedRAMP customers.

Responsibilities

  • Oversee active DFIR investigations end-to-end, ensuring exceptional quality, timely deliverables, and appropriate resource allocation.
  • Staff analysts onto engagements based on scope, skill set, and availability, and monitor team capacity to keep workloads balanced.
  • Lead scoping and business development activities, including incident intake, requirements gathering, and SOW and tri-party development.
  • Manage each engagement's retainer-hour budget, track usage against scope, and coordinate uplift or overage discussions with customers and account teams.
  • Establish and own communication channels across investigation stakeholders, including internal teams, customers, external breach counsel, and cyber insurance carriers.
  • Own escalations end-to-end and resolve technical or operational challenges.
  • Oversee case documentation, evidence handling, and chain of custody.
  • Manage retention and deletion timelines at engagement closure, including customer requests for early deletion.
  • Work with each case's technical lead to shape investigative direction, validate findings, and ensure workstreams meet customer expectations and reporting standards.
  • Ensure strict adherence to standard operating procedures and incident response best practices.
  • Manage timely and accurate status updates and recommendations for customers and stakeholders throughout each engagement.
  • Provide hands-on surge support and conduct technical analysis as needed to maintain investigative momentum when team capacity requires it.
  • Lead post-engagement reviews and process improvement initiatives to optimize team workflows.
  • Participate in a rotating on-call schedule for weekends and holidays to support active incident response.

Requirements

  • At least 5 years of hands-on consulting experience in digital forensics and incident response, including engagement or project management experience in a cybersecurity consulting or incident response services delivery role.
  • Bachelor's or Master's degree in Digital Forensics, Cybersecurity, Computer Science, or a related technical field, or equivalent practical self-study.
  • Industry certifications such as GCFE, GCFA, GREM, CFCE, EnCE, or similar.
  • Proven experience managing complex, multi-stakeholder incident response engagements.
  • Excellent client communication and relationship management skills, including comfort working with executive stakeholders, legal counsel, and insurance carriers.
  • Ability to translate complex technical findings into business impact for non-technical stakeholders.
  • Expert-level experience with industry-standard forensic tools and methodologies.
  • Strong understanding of and experience with EDR/XDR platforms and security technologies.
  • Strong staffing, resource-coordination, and team leadership skills.
  • Self-starter with intellectual curiosity and the ability to adapt to change.
  • U.S. citizenship and FedRAMP eligibility.

Nice to Have

  • Experience conducting malware analysis and memory forensics.
  • Experience in endpoint-based threat hunting and compromise assessments.
  • Experience working with cyber threat intelligence platforms and processes.
  • Active participation in the security community through speaking engagements or publications.

Benefits

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)
  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave and grandparent leave
  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary benefits, including hospital, accident, and critical illness coverage
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance
  • Home office allowance
  • Mobile phone reimbursement
  • Wellness coach and wellness/gym reimbursement
  • Fertility coverage
  • Adoption and surrogacy reimbursement

Compensation

The U.S. base salary range is $132,000–$160,000 USD. The range may vary based on the candidate's location, and a different pay range may apply in some locations.

More jobs at SentinelOne

Similar jobs