Digital Forensics and Incident Response Analyst

Mishcon de Reya
London, UK
4 days ago
Apply on eu.experteer.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Digital Forensics Python (Programming Language) Windows PowerShell Azure Active Directory Security Information and Event Management Scripting

Job description

Experteer Overview In this role you act as a first responder for cyber incidents within an accredited incident response framework. You will investigate, contain and eradicate threats, support clients through incident management, and contribute expertise to internal security and forensics efforts. You’ll work in a lab-based environment with a focus on mobile device forensics, while delivering clear client updates and maintaining high-quality evidence handling. This position offers the chance to shape incident response practices within a renowned, cross-functional security and legal services team. Pay / Benefits * Respond to client-reported cyber incidents as part of the NCSC CIR service, under incident lead guidance * Assess and triage risks from alerts and user reports, escalating per playbooks * Identify improvements to processes or technology and help implement them * Conduct forensic acquisition and analysis across platforms, including mobile devices * Assist with incident management, scoping, decision guidance, containment and eradication * Develop intelligence assessments of incidents and potential threats * Support longer-term remediation and security uplift for clients * Provide specialist technical and forensic guidance to internal teams * Support internal security team with incident response and security posture improvements * Contribute to projects with time and expertise * Deliver high-quality customer experience to clients Tasks * Hands-on experience investigating security incidents in SOC or IR contexts * Ability to conduct technical investigations under an incident lead * Strong knowledge of Windows endpoint environments and M365 security stack * Experience reviewing and analyzing security events and identifying indicators of compromise * Experience extracting and analysing logs from Windows, AD, Azure AD, and M365 * Experience examining Windows hosts for evidence of compromise; familiarity with artefact analysis * Proactive mindset-developing playbooks and approaches to novel incident types * Proficiency in scripting (PowerShell, Python, or similar) for automation * Curiosity about threat landscape and ability to learn quickly with limited guidance * Clear, client-facing communication of technical findings in high-pressure situations Key requirements * flexible working * hybrid working * diverse and inclusive workplace * agile working culture * supportive professional development * international exposure

Requirements

client scoping, decision guidance, containment and eradication * Develop intelligence assessments of incidents and potential threats * Support longer-term remediation and security uplift for clients * Provide specialist technical and forensic guidance to internal teams * Support internal security team with incident response and security posture improvements * Contribute to projects with time and expertise * Deliver high-quality customer experience to clients Tasks * Hands-on experience investigating security incidents in SOC or IR contexts * Ability to conduct technical investigations under an incident lead * Strong knowledge of Windows endpoint environments and M365 security stack * Experience reviewing and analyzing security events and identifying indicators of compromise * Experience extracting and analysing logs from Windows, AD, Azure AD, and M365 * Experience examining Windows hosts for evidence of compromise; familiarity with artefact analysis * Proactive mindset-developing aaaaa aaG_ and approaches to novel incident types * Proficiency in scripting (PowerShell, Python, or similar) for automation * Curiosity about threat landscape and ability to learn quickly with limited guidance * Clear, client-facing communication of technical findings in high-pressure situations Key requirements * flexible working * hybrid working * diverse and inclusive workplace * agile working culture * supportive professional development * international exposure

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on eu.experteer.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

2:03 min

Microsoft integrating native Unix coreutils into Windows environments

Chris Heilmann +2 · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:53 min

Applying software development methodologies to incident response

Tobias Dunn-Krahn · LIVE

1:24 min

Installing premium packages using the Store CLI

Noraa Junker Noraa Junker · Europe 2026 Virtual

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

Videos

See all

Related articles

See all