> Markdown version of [/jobs/ext/1963495-cyber-incident-response](https://www.wearedevelopers.com/jobs/ext/1963495-cyber-incident-response). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Response - **Company:** LT Harper - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cyber Security, Desktop Computing, Linux, Digital Forensics, Log Files, Windows Servers, Network Segmentation, Software Vulnerability Management, Cyber Threat Analysis, Firewalls (Computer Science) - **Published:** August 7, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/x/42989376/ ## About the Role What they are looking forAcross all three roles:A broad understanding of the cyber security threat landscapeStrong technical grounding in computers and networksProven experience of cyber security incidents and the response measures around themExcellent written and verbal communication, including with technical and non-technical stakeholdersSC or DV clearance, or eligibility and willingness to obtain itRole specific:DFIR: hands-on forensic analysis and incident management. CCIM, GCIH or CPIA welcome but not requiredCyber Defence: consulting capability first and engineering second, with experience in government, defence or healthcare preferredCyber Manager, Response and Recovery: strong cyber IR understanding, hands-on Windows Server, Active Directory, Linux, networking and cloud (Azure, AWS, Microsoft 365) at systems administrator level, plus ransomware, AD compromise or large-scale infrastructure recovery experience. Degrees and certifications are treated as evidence of competence rather than as a gate. If you meet most but not all of the above, it is still worth a conversation.PackageSalary £55 - £85k base - Excellent benefitsInvestment in security certifications and structured trainingAccess to nationally significant incidents, with exposure across government and critical infrastructureA defined route into senior cyber response and recovery leadershipThis would suit someone who wants to work on complex incidents at the point clients need help most, and who enjoys translating technical detail into clear advice for both technical and senior audiences.Please message me directly if you would like to discuss any of the three roles, or feel free to share this with someone in your network. ## Description Cyber Response / Incident Response, 3 x roles (DFIR, Recovery and Remediation, Security Operations Consulting)Salary: £55 - £85k base - Excellent benefitsLocation: London or ManchesterWorking pattern: hybrid, around 60% of the week with clients or in the office, 40% elsewhere, including from home + on callClearance: current SC or DV clearance, or eligibility and willingness to obtain it. I'm supporting a growing global consultancy that is looking to hire three people into its cyber response practice, one of a small number of UK Tier 1 incident response providers. The rolesDFIR. You will deliver digital forensics and incident response on live cases, acting as junior case manager on smaller incidents and as part of a wider team on larger ones. Forensics across disk, volatile memory, network packets and log files. Between incidents, you will help clients build their own response capability through runbooks and playbooks, maturity assessments and table-top exercises.Cyber Defence (Security Operations). You will advise clients on incident management, vulnerability management and threat intelligence. Work includes designing operating models for threat intelligence teams, building attack surface monitoring at scale, and advising on Frontier AI use cases in cyber defence, largely with public sector, government, defence and healthcare clients at senior stakeholder level.Cyber Manager, Response and Recovery. You will lead recovery workstreams after major incidents: Active Directory recovery and hardening, removing attacker persistence, patching and vulnerability remediation, network segmentation and firewall redesign, isolated recovery environments, backup validation and restore sequencing. You will convert incident findings into phased recovery and security improvement roadmaps. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [The Software Bug All Stars - and what we can learn from them](https://www.wearedevelopers.com/videos/423-the-software-bug-all-stars-and-what-we-can-learn-from-them) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)