Job Title:
Associate Director, Incident Response and Forensics
Company: CSL Behring
Location: King of Prussia, PA
Created: 2026-02-10
Job Type: Full Time
Job Description:
CSL is looking for ahighly technical anddetail-orientedleader in the DFIR spacethat specializes in digitalforensics,malware analysis,threatdetection,and the fast-pacedexcitement ofsupporting incident responseactivities.As the leader of our Digital Forensics and eDiscovery team, you will be responsible to support and grow a global team, own the strategy and direction for thepeople, processes, and technologyto fulfill your mission,andpartner deeply with our Security Operations,Data Loss Prevention, and Threat Intelligenceteams to help CSL defend itself fromcyberattacks. You will direct the adoptionof new tools and technologies to further your goals.The position holder:Leads a global team to apply security incident handling processesfor CSL tosuccessfullysupportthe cybersecurityand information securityincident response process to:PrepareforIdentifyContainEradicateRecoverfrom cybersecurity eventsThe role willlead a global team ofdigital forensics, incident responseand eDiscovery analyststhat will:Work closely with the Director, Security Operations to develop and implementacybersecurity threat analysisstructure of common attack techniques to evaluate an attacker's spread through aCSLsystem, platformandornetwork.Develop andmaintaina continuous upskilling program for your team to increase skills and overall capability maturityIdentifyand implement toolstodetermineattack typesandchooseappropriate defensesand response tactics for eachDerive Indicators of Compromise (IOCs) frommaliciousactivityto strengthen incident response,threat detection, andintelligence effortsConduct in-depth forensic analysisof various operating systemsExamine traffic using common network protocols toidentifypatterns of activity or specific actions thatwarrantfurther investigationDetect and huntforadversary tools, tactics, andprocedures (TTPs) across an enterprise environmentPartnerwithCompliance, Legal,Privacy, and other teams to perform internal investigationspertaining toeDiscovery mattersDemonstrates thought leader-level abilities with, and/or a proven record ofsuccessdirecting efforts in the following areas: Network Analysis ComputerMemory Analysis Endpoint Analysis Cyber Incident Lifecycle NIST 800-61 Lead and supervise teams to create an atmosphere of trust and seek diverse views to encourage improvement and innovation, answer questions and provide direction to less-experienced staff, coach staff including providingtimelymeaningful written and verbal feedbackReports toExecutive Director, Enterprise Monitoring & Cyber ResilienceDirect Reports This rolewill manage a team of Forensics,eDiscovery,Incident Responseand Threat HuntingSMEs andmayhaveProject Managers,Project Coordinators, Security Architects, and vendorsor managed service providersas directand indirectreportsbased onsecurityproject portfolio.Main Responsibilities and Accountabilities:Participatesin thehiring,growth,and development of juniorincident response staff in the areas of threat hunting, forensic analysis,eDiscovery,litigation hold,incident resolution and return to operations. Mentors and directsspecially assignedincident responseproject managers and their teamsand program management staff,and actively role modelsexpected project managementand leadershipbehaviors and processes designed to improve project results and the performance of the team.Position Qualifications and Experience Requirements:Required:College degree, preferably in a related technical subject; or advanced degree in business or industry-related subject or equivalent related work experiencein cybersecurity and manufacturing.Preferred: Anadvanced degree (MS) in a relevant discipline (or equivalent)including cybersecurity,managementinformation systems, and related technologies related to manufacturing cybersecurity.Project management certification / training desirable/ CISSP, CISM, CISO,GIAC-GCED,GIAC-GCIH, and/orGIAC-CFEcertification preferred.Essential Experience:8+yearsdemonstratedexperience leading global, multi-functionalDigital Forensics/CybersecurityIncident Responseteams(bio-pharma manufacturingenvironmentpreferred but notmandatory)Strong leadership, consultative, communication, and conflict management skills to influence project leaders and stakeholders, including non-specialists, at all levels in the organization and achieve teamobjectiveswhilemaintaininga positive team environment.The ability to train, mentor, and develop project managers in project management methodologies and their application; the ability to manage in a matrix environment.The ability to work on complex problems where analysis ofsituationor data requires an in-depth evaluation ofvarious factorsto achievebestresults.The ability to clearly communicate complex issues to senior management so that critical issues are understood quickly and can be addressedimmediately.Strong strategic planning, quantitative, and decision analysis capabilities.Strong project management and integration skills; ability to coordinate all aspects of a project or program.Demonstrated experience in developing, managing, and controllingcross functionalproject budgets.8+years experience usinga formalproject managementmethodology,techniquesand tools.Proficiencyand use of enterprise computer applications including the Microsoft suite of products and project managementsoftware.Desired Experience:Experience in biopharmaceutical industryExperience in crafting enterprise incident response programs for a global company process and technicaldefinition.About CSL BehringCSL Behring is a global biotherapeutics leader driven by our promise to save lives. Focused on serving patients needs by using the latest technologies, we discover, develop and deliver innovative therapies for people living with conditions in the immunology, hematology, cardiovascular and metabolic, respiratory, and transplant therapeutic areas. We use three strategic scientific platforms of plasma fractionation, recombinant protein technology, and cell and gene therapy to support continued innovation and continually refine ways in which products can address unmet medical needs and help patients lead full lives.CSL Behring operates one of the worlds largest plasma collection networks, CSL Plasma. Our parent company, CSL, headquartered in Melbourne, Australia, employs 32,000 people, and delivers its lifesaving therapies to people in more than 100 countries.To learn more about CSL, CSL Behring, CSL Seqirus and CSL Vifor visit and CSL Plasma at BenefitsFor more information on CSL benefits visit How CSL Supports Your Well-being | CSL.You Belong at CSLAt CSL, Inclusion and Belonging is at the core of our mission and who we are. It fuels our innovation day in and day out. By celebrating our differences and creating a culture of curiosity and empathy, we are able to better understand and connect with our patients and donors, foster strong relationships with our stakeholders, and sustain a diverse workforce that will move our company and industry into the future.To learn more about inclusion and belonging visit Opportunity EmployerCSL is an Equal Opportunity Employer. If you are an individual with a disability and need a reasonable accommodation for any part of the application process, please visit IndustriesOther