Senior Digital Forensics and Incident Response (DFIR) Consultant
Ransomware Recovery
London, UK
11 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English
Job source
Tech stack
Microsoft Windows
Data Analysis
Cyber Security
Digital Forensics
RAID
Network Forensics
Routing
Security Information and Event Management
Virtual Machines
Malware
Cyber Threat Analysis
Storage Technologies
+1 more
Cybercrime
Job description
- Engage on behalf of CYPFER in incident response tasks, interacting with various insurance partners, legal counsel, incident response units, client executives, and technical teams.
- Utilize standard tools and methodologies to collect forensic artifacts and images from affected systems.
- Perform Windows/Unix/Linux forensics and triage, and network forensics to assess compromise and investigations.
- Skilled in malware analysis tools and methodologies.
- Apply mitigation strategies and concepts to remediate identified threats.
- Analyze triage collections/artifacts for indicators of compromise (IoCs) and potentially malicious activity.
- Review logs from host systems and appliances to identify suspicious activities.
- Collect forensic disk and memory images from physical and virtual endpoints and servers.
- Perform forensic analysis of physical systems, virtual machines, and network data.
- Understanding of an incident lifecycle and cyber-kill-chain.
- Familiarity with exfiltration techniques used by threat actors.
- Correlate events and build timelines of events.
- Maintain current knowledge on emerging threats and vulnerabilities.
- Analyze files for IOCs using various techniques.
- Conduct limited threat research based on IOCs collected during investigations.
- Understand obfuscation techniques used to conceal malicious commands and traffic, and lateral movement strategies employed by threat actors.
- Collaborate and share information within and across teams and communicate effectively with client managers and executives.
- Write detailed reports and summarize findings clearly and concisely.
- Participate in a rotating on-call schedule; ability to work on weekends and outside normal business hours as needed.
- This role is remote but requires the ability to travel on short notice to a client site up to 50%. Must maintain flexibility to travel frequently within 24-48 hours’ notice for deployments typically 1-2 weeks in duration.
Requirements
- 5+ years of experience in digital forensics, incident response, or a similar role.
- Strong knowledge of Windows and Unix/Linux operating systems.
- Expertise in threat hunting, network forensics, and EDR / EPP technologies.
- Skilled in forensic acquisition and analysis of physical and virtual systems.
- Advanced understanding of networking, routing, and firewall operations.
- Working knowledge of storage technologies such as RAID, NAS, SAN, Fiber Channel, iSCSI, and NFS.
- Ability to analyze and interpret logs from various sources.
- Familiarity with SIEM and SOAR solutions.
- Ability to perform threat research and analyze current threats.
- Understanding of business email compromise (BEC) cases and investigation techniques.
Business Responsibilities
- Fluent in English.
- Maintain current knowledge of information security, incident response techniques, emerging threats, and tools.
- Work independently and produce high-quality deliverables with minimal supervision.
- Exhibit strong customer service and consulting skills.
- Adhere to client and internal policies, procedures, and security practices.
- Maintain detailed notes and draft updates and reports as required.
- Remain calm, composed, and articulate in tough customer situations.
- Exhibit excellent relationship management and communication skills.
Preferred Skills
- Experience with e-discovery tools and methodologies.
- Proficiency in collecting and analyzing data from mobile devices/cell phones.
- Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar are a plus.
About the company
CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware events. Our team collaborates with prominent global insurance carriers, leading law firms, and Fortune 1000 businesses.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
LM
Luis Minvielle
over 2 years ago
EM
Eli McGarvie
Data Analyst Salary in the UK
about 3 years ago
DC
Daniel Cranney
Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents
11 months ago
LM
Luis Minvielle
Fully Remote Software Engineer Jobs
over 2 years ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
EM
Eli McGarvie
Data Engineer Salary UK
over 3 years ago