> Markdown version of [/jobs/ext/2019413-digital-forensics-and-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/2019413-digital-forensics-and-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensics and Incident Response Analyst - **Company:** Mishcon de Reya - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Digital Forensics, Python (Programming Language), Windows PowerShell, Azure Active Directory, Security Information and Event Management, Scripting - **Published:** August 11, 2026 - **Apply:** https://eu.experteer.com/career/view-jobs/digital-forensics-and-incident-response-analyst-london-grossbritannien-58876522 ## About the Role client scoping, decision guidance, containment and eradication * Develop intelligence assessments of incidents and potential threats * Support longer-term remediation and security uplift for clients * Provide specialist technical and forensic guidance to internal teams * Support internal security team with incident response and security posture improvements * Contribute to projects with time and expertise * Deliver high-quality customer experience to clients Tasks * Hands-on experience investigating security incidents in SOC or IR contexts * Ability to conduct technical investigations under an incident lead * Strong knowledge of Windows endpoint environments and M365 security stack * Experience reviewing and analyzing security events and identifying indicators of compromise * Experience extracting and analysing logs from Windows, AD, Azure AD, and M365 * Experience examining Windows hosts for evidence of compromise; familiarity with artefact analysis * Proactive mindset-developing aaaaa aaG_ and approaches to novel incident types * Proficiency in scripting (PowerShell, Python, or similar) for automation * Curiosity about threat landscape and ability to learn quickly with limited guidance * Clear, client-facing communication of technical findings in high-pressure situations Key requirements * flexible working * hybrid working * diverse and inclusive workplace * agile working culture * supportive professional development * international exposure ## Description Experteer Overview In this role you act as a first responder for cyber incidents within an accredited incident response framework. You will investigate, contain and eradicate threats, support clients through incident management, and contribute expertise to internal security and forensics efforts. You'll work in a lab-based environment with a focus on mobile device forensics, while delivering clear client updates and maintaining high-quality evidence handling. This position offers the chance to shape incident response practices within a renowned, cross-functional security and legal services team. Pay / Benefits * Respond to client-reported cyber incidents as part of the NCSC CIR service, under incident lead guidance * Assess and triage risks from alerts and user reports, escalating per playbooks * Identify improvements to processes or technology and help implement them * Conduct forensic acquisition and analysis across platforms, including mobile devices * Assist with incident management, scoping, decision guidance, containment and eradication * Develop intelligence assessments of incidents and potential threats * Support longer-term remediation and security uplift for clients * Provide specialist technical and forensic guidance to internal teams * Support internal security team with incident response and security posture improvements * Contribute to projects with time and expertise * Deliver high-quality customer experience to clients Tasks * Hands-on experience investigating security incidents in SOC or IR contexts * Ability to conduct technical investigations under an incident lead * Strong knowledge of Windows endpoint environments and M365 security stack * Experience reviewing and analyzing security events and identifying indicators of compromise * Experience extracting and analysing logs from Windows, AD, Azure AD, and M365 * Experience examining Windows hosts for evidence of compromise; familiarity with artefact analysis * Proactive mindset-developing playbooks and approaches to novel incident types * Proficiency in scripting (PowerShell, Python, or similar) for automation * Curiosity about threat landscape and ability to learn quickly with limited guidance * Clear, client-facing communication of technical findings in high-pressure situations Key requirements * flexible working * hybrid working * diverse and inclusive workplace * agile working culture * supportive professional development * international exposure ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [AI Space Factories, Hacking Self-Driving Cars & Detecting Deepfakes](https://www.wearedevelopers.com/videos/1812-ai-space-factories-hacking-self-driving-cars-detecting-deepfakes) - [Fake or News: Translating Dog Barks, Notepad Gets an Upgrade and Michelin-Star Robots - Paul Tregoing](https://www.wearedevelopers.com/videos/1802-fake-or-news-translating-dog-barks-notepad-gets-an-upgrade-and-michelin-star-robots-paul-tregoing) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)