> Markdown version of [/jobs/ext/2316924-cyber-incident-responder](https://www.wearedevelopers.com/jobs/ext/2316924-cyber-incident-responder). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Incident Responder - **Company:** CYFOR - **Location:** Middleton, UK (Remote available) - **Experience:** Experienced - **Salary:** £40,000.0 - £50,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cyber Security, Digital Forensics, Intrusion Detection Systems, Microsoft Office, Open Source Technology, Google Cloud, Cloud Platform System, Office365, Mitre Att&ck, Cyber Threat Analysis, SC Clearance, Cybercrime, SentinelOne Expertise, Service Stack - **Published:** August 4, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=3e65259e14e28d08 ## About the Role The ideal candidate will have at least 2 years' experience responding to and investigating a range of cyber incidents and demonstrate in-depth knowledge of common cyber incident types and threat actor methodologies. You'll have a deep technical knowledge of incident response, digital forensics, M365, cloud environments and investigations processes, along with excellent client facing skills and a can-do attitude. You'll also be able to demonstrate flexibility, commitment and integrity., Please note that this role will require NPPV3 clearance in addition to National security clearance to SC level. Applicants MUST have been continuously resident in the United Kingdom for the last 5 years. If you do not hold an active SC clearance, please familiarise yourself with the vetting process before applying., · Experience collecting forensic evidence from compromised systems. · Experience investigating cyber incidents to understand malicious activity. · Proven understanding of the Cyber Kill Chain, MITRE ATT&CK and other information security defence and intelligence frameworks. · Comprehensive knowledge of incident handling, threat hunting and threat intelligence. · Ability to correlate events from various sources to create incident timelines. · Experience in cloud-based infrastructure including Microsoft Azure and Office 365, Amazon AWS, and Google Cloud. · Excellent client facing skills, with the ability to communicate at all levels, adapting the style of communication to meet the needs of the audience. · An excellent attitude and the willingness to learn and study for certifications. · Ability to effectively plan and coordinate projects. · Excellent written and verbal communication skills, · An investigative mindset with a high level of attention to detail · Demonstrate a flexible approach to work and a high level of self-motivation. · Ability to exercise discretion and confidentiality. Desirable Skills · Previous exposure to enterprise scale infrastructure and technology stacks. · Appropriate incident response certifications (E.g., CREST Intrusion Analyst or Incident Manager) · Experience deploying and monitoring endpoint protection (e.g. SentinelOne) across a variety of systems during incident response, * Cyber Incident Response: 2 years (required) ## Description · Perform emergency incident response for customers; including containment (credential resets, network quarantine and EDR rollouts) to prevent further compromise and gathering of relevant forensic evidence. · Investigate forensic evidence from compromised devices and networks to determine the root-cause of incidents and understand the actions taken by threat actors. · Acquire and investigate server logs, firewall logs, intrusion detection system alerts, traffic logs and host system logs to determine what data has been impacted during a cyber incident using open-source tools and industry standard forensics software. · Conduct forensic acquisitions from relevant servers and workstations · Analyse malware to understand and communicate its impact on systems and data · Delivering high quality technical investigation and forensic reports to clients · Deliver regular, high-quality updates to clients throughout an investigation You will also be required to travel at short notice for Cyber Incident response. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)