Cyber Incident Response
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
Cyber Response / Incident Response, 3 x roles (DFIR, Recovery and Remediation, Security Operations Consulting)Salary: £55 - £85k base - Excellent benefitsLocation: London or ManchesterWorking pattern: hybrid, around 60% of the week with clients or in the office, 40% elsewhere, including from home + on callClearance: current SC or DV clearance, or eligibility and willingness to obtain it. I’m supporting a growing global consultancy that is looking to hire three people into its cyber response practice, one of a small number of UK Tier 1 incident response providers. The rolesDFIR. You will deliver digital forensics and incident response on live cases, acting as junior case manager on smaller incidents and as part of a wider team on larger ones. Forensics across disk, volatile memory, network packets and log files. Between incidents, you will help clients build their own response capability through runbooks and playbooks, maturity assessments and table-top exercises.Cyber Defence (Security Operations). You will advise clients on incident management, vulnerability management and threat intelligence. Work includes designing operating models for threat intelligence teams, building attack surface monitoring at scale, and advising on Frontier AI use cases in cyber defence, largely with public sector, government, defence and healthcare clients at senior stakeholder level.Cyber Manager, Response and Recovery. You will lead recovery workstreams after major incidents: Active Directory recovery and hardening, removing attacker persistence, patching and vulnerability remediation, network segmentation and firewall redesign, isolated recovery environments, backup validation and restore sequencing. You will convert incident findings into phased recovery and security improvement roadmaps.
Requirements
What they are looking forAcross all three roles:A broad understanding of the cyber security threat landscapeStrong technical grounding in computers and networksProven experience of cyber security incidents and the response measures around themExcellent written and verbal communication, including with technical and non-technical stakeholdersSC or DV clearance, or eligibility and willingness to obtain itRole specific:DFIR: hands-on forensic analysis and incident management. CCIM, GCIH or CPIA welcome but not requiredCyber Defence: consulting capability first and engineering second, with experience in government, defence or healthcare preferredCyber Manager, Response and Recovery: strong cyber IR understanding, hands-on Windows Server, Active Directory, Linux, networking and cloud (Azure, AWS, Microsoft 365) at systems administrator level, plus ransomware, AD compromise or large-scale infrastructure recovery experience. Degrees and certifications are treated as evidence of competence rather than as a gate. If you meet most but not all of the above, it is still worth a conversation.PackageSalary £55 - £85k base - Excellent benefitsInvestment in security certifications and structured trainingAccess to nationally significant incidents, with exposure across government and critical infrastructureA defined route into senior cyber response and recovery leadershipThis would suit someone who wants to work on complex incidents at the point clients need help most, and who enjoys translating technical detail into clear advice for both technical and senior audiences.Please message me directly if you would like to discuss any of the three roles, or feel free to share this with someone in your network.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.apply4u.co.ukGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
IT Salaries in UK
Is Software Engineering Over-Saturated?
The Most Popular IT Jobs on the Market
Data Analyst Salary in the UK