Cyber Incident Response

LT Harper
London, UK
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Cyber Security Desktop Computing Linux Digital Forensics Log Files Windows Servers
+4 more
Network Segmentation Software Vulnerability Management Cyber Threat Analysis Firewalls (Computer Science)

Job description

Cyber Response / Incident Response, 3 x roles (DFIR, Recovery and Remediation, Security Operations Consulting)Salary: £55 - £85k base - Excellent benefitsLocation: London or ManchesterWorking pattern: hybrid, around 60% of the week with clients or in the office, 40% elsewhere, including from home + on callClearance: current SC or DV clearance, or eligibility and willingness to obtain it. I’m supporting a growing global consultancy that is looking to hire three people into its cyber response practice, one of a small number of UK Tier 1 incident response providers. The rolesDFIR. You will deliver digital forensics and incident response on live cases, acting as junior case manager on smaller incidents and as part of a wider team on larger ones. Forensics across disk, volatile memory, network packets and log files. Between incidents, you will help clients build their own response capability through runbooks and playbooks, maturity assessments and table-top exercises.Cyber Defence (Security Operations). You will advise clients on incident management, vulnerability management and threat intelligence. Work includes designing operating models for threat intelligence teams, building attack surface monitoring at scale, and advising on Frontier AI use cases in cyber defence, largely with public sector, government, defence and healthcare clients at senior stakeholder level.Cyber Manager, Response and Recovery. You will lead recovery workstreams after major incidents: Active Directory recovery and hardening, removing attacker persistence, patching and vulnerability remediation, network segmentation and firewall redesign, isolated recovery environments, backup validation and restore sequencing. You will convert incident findings into phased recovery and security improvement roadmaps.

Requirements

What they are looking forAcross all three roles:A broad understanding of the cyber security threat landscapeStrong technical grounding in computers and networksProven experience of cyber security incidents and the response measures around themExcellent written and verbal communication, including with technical and non-technical stakeholdersSC or DV clearance, or eligibility and willingness to obtain itRole specific:DFIR: hands-on forensic analysis and incident management. CCIM, GCIH or CPIA welcome but not requiredCyber Defence: consulting capability first and engineering second, with experience in government, defence or healthcare preferredCyber Manager, Response and Recovery: strong cyber IR understanding, hands-on Windows Server, Active Directory, Linux, networking and cloud (Azure, AWS, Microsoft 365) at systems administrator level, plus ransomware, AD compromise or large-scale infrastructure recovery experience. Degrees and certifications are treated as evidence of competence rather than as a gate. If you meet most but not all of the above, it is still worth a conversation.PackageSalary £55 - £85k base - Excellent benefitsInvestment in security certifications and structured trainingAccess to nationally significant incidents, with exposure across government and critical infrastructureA defined route into senior cyber response and recovery leadershipThis would suit someone who wants to work on complex incidents at the point clients need help most, and who enjoys translating technical detail into clear advice for both technical and senior audiences.Please message me directly if you would like to discuss any of the three roles, or feel free to share this with someone in your network.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.apply4u.co.uk

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:11 min

Enhancing manual debugging through model-assisted log analysis

Michael Niebisch Michael Niebisch · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all