> Markdown version of [/jobs/ext/1961518-digital-forensics-and-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/1961518-digital-forensics-and-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensics and Incident Response Analyst - **Company:** Mishcon de Reya - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Data Analysis, Cyber Security, Linux, Digital Data, Digital Forensics, Python (Programming Language), Linux System Administration, Windows PowerShell, Azure Active Directory, EndPointSecurity, Scripting, Office365, Gsuite - **Published:** August 7, 2026 - **Apply:** https://fsr.cvmailuk.com/mishcon/applying.cfm?rcd=6015240&job_Id=78704 ## About the Role * Hands-on experience investigating security incidents, whether as a SOC analyst reviewing and analysing alerts and events, or as part of an incident response team conducting technical investigations. * Ability to conduct technical investigations as part of an incident response team, working under the direction of an incident lead to identify, scope, and document findings clearly. * Strong working knowledge of Windows endpoint environments and the Microsoft 365 security stack, including Defender for Endpoint, Defender for Identity, and Purview. Experience with Mac and Linux environments or Google Workspace is advantageous but not necessary. * Experience reviewing, triaging, and analysing security events and alerts, with the ability to distinguish genuine threats from noise and identify indicators of compromise across endpoint, identity, and cloud telemetry. * Experience extracting and analysing logs from Windows systems, Active Directory, Azure AD, M365 services, and other sources to identify evidence of malicious or anomalous * Experience examining Windows hosts for evidence of compromise, including artefact analysis, persistence mechanisms, lateral movement indicators, and timeline reconstruction. Familiarity with Mac and Linux host examination is advantageous but not necessary. * A proactive mindset: someone who authors and improves playbooks rather than simply following them, and who develops their own approaches to novel or undocumented incident types. * Proficiency with one or more scripting languages (PowerShell, Python, or similar) to automate triage tasks, parse artefacts, and accelerate investigations. * Technical curiosity and a genuine interest in the threat landscape, someone who keeps pace with attacker techniques, emerging TTPs, and defensive tooling, and who can learn quickly and often with limited guidance. * Experience communicating technical findings clearly to clients and stakeholders in high-pressure situations, including the ability to explain complex security events in plain language is desirable. ## Description The Cyber Risk and Complex Investigations team is made up of cyber and investigations specialists who work alongside our legal teams to provide a comprehensive and responsive client service. Our practice works with clients to support them in the prevention of cyber-crime and the management of sophisticated and often complex cyber-attacks and helping them find digital information that supports their needs. We have extensive experience of working on cyber security issues with a range of organisations, from large and complex global entities to mid-sized or small firms, start-ups and private individuals. We help our clients implement the cyber security they need to address their threats, ensuring compliance with regulatory standards. If an incident occurs, we use our expertise and experience to help clients manage the technological, legal and reputational risks. Offering a wider breadth of service and a broader range of solutions than traditional investigators, our team combines cutting edge cyber intelligence skills with innovative investigative techniques, understanding the legal requirement to gather facts and evidence properly, safely and ethically. We assess every investigation to ensure it meets our ethical and quality standards, as well as using a robust review process. The team provides NCSC and CREST accredited security incident response and digital forensics services both internally and to our external clients and we are looking to grow and develop our response team. The Role In this role you will be a key member of our incident response team, acting as a first responder when clients report cyber incidents to us. You will investigate, contain, and eradicate threats as part of our NCSC Cyber Incident Response (CIR) and NCSC Cyber Incident Exercising (CIE) accredited service lines. You will also work alongside our internal security team to assess and respond to internal incidents and security queue items. You must be comfortable receiving and triaging reported incidents, assessing risks quickly and accurately, escalating where necessary, and keeping clients informed throughout. You will operate under the pressure of live incident response conditions, making sound decisions and calmly developing and executing response plans to deliver concrete outcomes. Strong record-keeping and clear client communication are essential throughout. Our incident response and digital forensics team operates a forensics lab to support the delivery of forensic services. You will be trained in digital forensics acquisition and investigation, with a particular focus on mobile device forensics. You will also be called upon regularly to support our internal security team and to provide technical advice and guidance to other internal teams to help them deliver the best possible advice to clients., * Respond to client-reported cyber incidents as part of our NCSC CIR Standard Level accredited incident response service, conducting technical investigation activities under the direction of the incident lead. * Assess risks related to system generated alerts and user reported issues, escalating promptly and in line with established playbooks. * Action or escalate issues promptly and consistently in line with playbooks. * Identify areas of improvement for process or technology and contribute to their implementation. * Conduct forensic acquisition and analysis across a range of platforms and media in both incident response and discrete investigation scenarios, including specialist acquisition and examination of mobile devices. * Assist with incident management, including scoping work, guiding clients through decision making, and supporting containment and eradication. * Develop intelligence assessments of incidents and other potential threats to clients. * Support clients with longer term guidance and support with remediation and security uplift activities. * Provide specialist advice and guidance to internal teams on technical and forensic matters. * Support the internal security team in assessing and responding to internal incidents, managing the security queue, and contributing to the continuous improvement of internal security posture. * Contribute to Projects with both time and expertise. * Provide a high standard of customer experience to our clients. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)