We are looking for a senior DFIR professional to build and operationalise an enterprise forensic capability. Combining forensic expertise with programme delivery, architecture, supplier management and major-incident leadership, you will ensure digital evidence can be acquired quickly, handled defensibly, analysed securely and translated into clear containment and recovery decisions.
What you will own
· Strategy and readiness. Set standards, assess maturity and evidence gaps, and prioritise improvements.
· Operating model and partners. Define responsibilities; lead supplier selection, retainers, SLAs and mobilisation.
· Architecture and tooling. Shape secure acquisition, transfer, analysis and evidence storage, including kits, workstations and licences.
· Runbooks and evidence handling. Create chain-of-custody procedures and playbooks across identity, endpoints, networks, cloud and critical platforms.
· Exercises and assurance. Run tabletops, acquisition tests and end-to-end simulations; track KPIs and remediation.
What you bring
· Enterprise DFIR experience. Significant cyber experience with responsibility for incident response, digital forensics or forensic readiness.
· Capability building. A record of improving DFIR operating models, architecture, investigation processes or services.
· Technical depth. Knowledge of Windows/Linux, endpoint, identity, network and cloud evidence; SIEM/EDR; volatile and persistent acquisition.
· Forensic tooling. Familiarity with tools such as EnCase, FTK, Magnet AXIOM, Velociraptor, KAPE or Volatility.
· Partner and stakeholder leadership. Experience evaluating suppliers and aligning security, infrastructure, legal/privacy, crisis and senior stakeholders.
· Certifications. GCFA, GCFE, GCIH, EnCE, CCE or CISSP is valued.