Associate Consultant, Digital Forensics and Incident Response

Control Risks Group Holdings Ltd
London, UK
3 days ago
Apply on apply.workable.com
Prepare application

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Windows Amazon Web Services Microsoft Azure Bash Shell Cyber Security Computer Programming Computer Networks Computer Forensics Linux Digital Data Digital Forensics Network Topologies
+15 more
Python (Programming Language) Log Analysis Windows PowerShell Cloud Services SQL Databases Forensic Toolkit Data Processing Scripting Computer Networking Systems Mitre Att&ck Information Technology Data Analytics Gsuite Encase Nuix

Job description

We now have an exciting opportunity for an Associate Consultant to join us in London. As an Associate Consultant you will provide technical expertise and consultative solutions in the field of Digital Forensics, Incident Response, Cyber Security and eDiscovery for our clients. Our clients include Law Firms, Fortune 500 multi-nationals, and Government/Law Enforcement. You will be responsible for the preservation of digital data, forensic analysis of digital evidence and providing reporting for our regional and international Discovery & Data Insights teams (DFIR/Legal Technologies/Data Analytics) as well as working closely with our Cyber Response and Crisis Management divisions as well as our Investigations teams.

As an Associate Consultant you will play a crucial role in supporting our team of experienced professionals in serving both internal and external clients through the investigation of data breaches and security incidents.

This is an excellent opportunity for a motivated individual with a passion for digital forensics to gain hands-on experience in the field of DFIR.

Role tasks and responsibilities

  • To collect and preserve digital data using industry-standard tools and techniques
  • To assist with the provision of forensic analysis & cyber security services to our clients
  • To support our Investigation teams across all regions
  • To provide high quality deliverables to our clients in a timely and efficient manner
  • To ensure work is defensible and to an evidential standard as appropriate for tasks
  • To provide expert testimony in court as and when required
  • To be innovative and creative, showing initiative in delivering day to day duties
  • Must be available for international travel (up to 25% of time)
  • Stay up to date with the latest digital forensic techniques, tools and trends, * Control Risks offers a competitively positioned compensation and benefits package that is transparent and summarised in the full job offer.
  • We operate a discretionary global bonus scheme that incentivises, and rewards individuals based on company and individual performance.
  • Control Risks supports hybrid working arrangements, wherever possible, that emphasise the value of in-person time together - in the office and with our clients - while continuing to support flexible and remote working.
  • As an equal opportunities employer, we encourage suitably qualified applicants from a wide range of backgrounds to apply and join us and are fully committed to equal treatment, free from discrimination, of all candidates throughout our recruitment process.

If you require any reasonable adjustments to be made in order to participate fully in the interview process, please let us know and we will be happy to accommodate your needs.

Requirements

  • Experience of performing forensic data acquisitions, involvement in digital investigations alongside maintaining detailed contemporaneous notes
  • Understanding and awareness of multiple operating systems, particularly Microsoft and Linux infrastructure and networking systems, both on-premise and in the cloud, as well as dedicated cloud services such as Microsoft 365, Azure, AWS and Google Workspace
  • Previous use and/or knowledge of common computer forensic tools for data acquisition and analysis (for example, Logicube Falcon, Velociraptor, EnCase, FTK, Nuix, X-Ways, Axiom, IEF, Blacklight, Kali, WinFE, DEFT, Cellebrite, XRY)
  • The ability to use PowerShell scripting, Bash scripts, Python, SQL and data wrangling for log analysis.
  • Demonstrable, technical computer forensics experience/awareness of associated recognised international standards
  • Good understanding of best practice procedures (NPCC, NIST, ISO17025) evidence handling, computer systems and tools of the trade
  • Good understanding of both the MITRE ATT&CK and Cyber Kill chain framework, network topology and EDR solutions

Preferred

  • Experience in performing mobile device acquisitions
  • Wide understanding of programming/scripting skills
  • Excellent presentation skills
  • Experience of providing client-facing communications & consultative service
  • Experience of writing expert reports and witness statements

Essential

  • Excellent written/verbal communication skills
  • Educated to BSc in IT or similar technical degree (or related experience)
  • Knowledge of Microsoft/Apple/Linux products
  • Awareness and understanding of computer networks and infrastructure

Preferred

  • Educated to BSc/MSc (or equivalent) in Computer Forensics
  • Forensic accreditation, for example EnCE, ACE, GCFE
  • Previous internship or work experience in a DFIR/Security Operations role

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on apply.workable.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:21 min

Introduction to automotive security and digital forensics

Martin Schmiedecker · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

43 sec

Software engineering journey and local Manchester roots

Jonathan Tang · Coffee With Developers

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

8:22 min

Simulating a Linux terminal and running Spring Boot

Jakov Semenski · LIVE

Videos

See all

Related articles

See all