Incident Response Lead (DFIR) - Hybrid - Can be based anywhere in the UK - Up to £110k
The opportunity:
Do you want to lead the response to incidents that matter nationally?
A Cyber Consultancy is looking for an Incident Response Lead to join its Cyber Response Services team, reporting directly to the head of cyber response. This is a hands-on operational leadership role with a clear route into service line leadership. The team cover industries such as government, critical infrastructure and large enterprise, from ransomware through to advanced network intrusions. You will lead case managers and practitioners, stay technical in the forensics, and have a real say in how the practice grows.
Your benefits:
Up to £110k salary
Funded certifications and a structured training programme
Exposure to nationally significant incidents across government and CNI
Defined progression into senior leadership of a fast-growing capability
Hybrid working from London or Manchester hubs
Pension contribution and private healthcare [confirm]
Your responsibilities as an Incident Response Lead will be to:
- Manage and coordinate a portfolio of cyber security incidents for clients, working closely with the head of cyber response
- Lead a team of case managers and practitioners through the full incident lifecycle: scoping, triage, containment, evidence preservation, eradication and recovery
- Carry out and quality-assure digital forensics on disk, volatile memory, network traffic and log data
- Own the commercial side of engagements, including scoping, costing, financial management and risk
- Help clients stand up or mature their own IR capability through playbooks, maturity assessments and tabletop exercises
- Drive the development of in-house cyber response tooling, lab environments and operating procedures
- Mentor junior team members and shape the team's learning and development
- Contribute to bids and proposals, and maintain a current view of the threat landscape for clients
- Take part in an on-call rotation and be ready to travel at short notice, sometimes for two to three weeks at a time
As an Incident Response Lead you will ideally have:
- Significant experience managing complex cyber security incidents end to end, including leading a rapid deployment incident response team
- Strong digital forensics competency, with advanced experience of tools such as X-Ways, EnCase, FTK, AXIOM/IEF or Cellebrite, and of preserving cloud data and encrypted evidence
- Technical depth in at least one of network and log analysis, Linux or Mac forensics, memory forensics, malware reverse engineering or mobile forensics
- A working programming skillset (Python preferred) and solid knowledge of enterprise Windows, Active Directory and Linux environments
- Excellent written and verbal communication, with the ability to guide senior non-technical stakeholders through a live incident
- Certifications such as CCIM, GCIH, CRIA, CCNIA, CCHIA, GCFA or GNFA are highly desirable, as are CISSP, CISM or CISA
- Current SC or DV clearance, or eligibility and willingness to obtain it
If you are interested in this role, please contact me at [email protected]