> Markdown version of [/jobs/ext/2838253-nmc-cyber-incident-responder-digital-forensics](https://www.wearedevelopers.com/jobs/ext/2838253-nmc-cyber-incident-responder-digital-forensics). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # NMC Cyber Incident Responder (Digital Forensics) - **Company:** gb Police Digital Services - **Location:** Wigan, UK (Remote available) - **Salary:** £55,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Cyber Security, Digital Forensics, Intrusion Detection and Prevention, Application Data, Security Information and Event Management, Mitre Att&ck, Malware, Cybercrime - **Published:** September 11, 2026 - **Apply:** https://www.totaljobs.com/job/cyber-incident-responder/police-digital-services-job107964941 ## About the Role * Experience conducting digital forensic investigations within enterprise environments. * Experience performing endpoint and memory forensic analysis during cyber security incidents. * Experience investigating ransomware, malware, unauthorised access, and data compromise incidents. * Ability to collect, preserve and analyse digital evidence whilst maintaining evidential integrity. * Strong understanding of Windows internals, operating system artefacts and attacker tradecraft. * Experience communicating technical findings and recommendations to senior stakeholders. * Strong knowledge of incident response lifecycle and cyber investigation methodologies. * Experience analysing logs, EDR telemetry, SIEM data and forensic artefacts to evaluate root cause and impact. ## Description As a member of the National Management Centre (NMC) Cyber Incident Response team, you will lead and support the investigation of cyber security incidents affecting UK policing. This role combines digital forensics, incident response and stakeholder engagement, requiring the ability to identify, contain and investigate sophisticated cyber threats across diverse technology estates. You will conduct forensic examinations of compromised systems, analyse host, network and memory-based evidence, and support the collection and preservation of digital evidence to establish root cause, impact and attacker activity. Working closely with threat intelligence, detection engineering and force stakeholders, you will provide technically sound advice to support incident remediation and organisational decision-making., Incident Response & Investigation * Lead and support investigations into cyber security incidents affecting UK policing, including ransomware, malware outbreaks, unauthorised access, data compromise and insider threat investigations. * Perform detailed forensic analysis of endpoints, servers, cloud environments and associated digital evidence to evaluate the scope, root cause and impact of incidents. * Support incident containment, eradication and recovery activities through evidence-based recommendations. * Develop and maintain investigative methodologies, playbooks and procedures aligned to recognised incident response frameworks. Digital Forensics * Acquire, preserve and analyse digital evidence in accordance with forensic best practice and evidential integrity requirements. * Perform forensic collection activities using appropriate live response techniques. * Analyse operating system artefacts, event logs, registry data, memory captures, network evidence and application data to support investigations. * Produce accurate and defensible investigative findings suitable for operational, legal and executive audiences. * Maintain awareness of emerging forensic tools, techniques and methodologies. Stakeholder Engagement * Act as a trusted advisor to police forces and policing organisations during cyber incidents. * Provide clear technical and strategic briefings to senior stakeholders including Chief Officers, CIOs, Heads of IT, Heads of Cyber Security and other policing partners. * Coordinate with internal and external stakeholders to ensure effective incident management and communication throughout the lifecycle of an investigation. * Support national coordination activities where incidents have cross-force or sector-wide implications. Threat Analysis & Continuous Improvement * Utilise threat intelligence, attacker TTPs and industry frameworks such as MITRE ATT&CK to inform investigations and response activity. * Identify trends, lessons learned and opportunities to improve cyber resilience across UK policing. * Contribute to the development of detection capabilities and response processes through post-incident reviews and technical findings. * Support knowledge sharing, mentoring and capability development across the wider NMC function. ## Related Videos - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Deep Fakes: The Lies We Can’t See](https://www.wearedevelopers.com/videos/1187-deep-fakes-the-lies-we-can-t-see) - [Training Bots on Deliveroo Data, Alexa Can Swear and Mushroom Electronics - Julia Kordick](https://www.wearedevelopers.com/videos/1839-training-bots-on-deliveroo-data-alexa-can-swear-and-mushroom-electronics-julia-kordick) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 111 - npm i -g issues](https://www.wearedevelopers.com/magazine/415-dev-digest-111-npm-i-g-issues) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)