> Markdown version of [/jobs/ext/3288348-digital-forensics-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/3288348-digital-forensics-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensics & Incident Response Analyst - **Company:** Maersk - **Location:** Maidenhead, UK (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Cloud Computing, Cyber Security, Linux, Digital Forensics, File Systems, Event Logging, Intrusion Detection and Prevention, Security Information and Event Management, Forensic Toolkit, Cyber Threat Analysis, Cybercrime, Operational Systems, Encase, Cyber Warfare - **Published:** September 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e8d80d3322060cc3 ## About the Role * Continuous improvement mindset: we are looking for someone who brings a thoughtful improvement mindset, curious about how work gets done and motivated to make meaningful, sustainable improvements over time. * Proven experience conducting enterprise-scale digital forensic investigations across Windows and Linux operating systems. * Strong knowledge of forensic artefacts including event logs, registry analysis, browser artefacts, file systems, persistence mechanisms, lateral movement techniques, and file-less attacks. * Experience with threat hunting, security operations, incident investigation, and security technologies such as SIEM platforms, firewalls, and monitoring solutions. * Hands-on knowledge of forensic tools such as X-Ways, EnCase, Autopsy, TimeSketch, and Plaso, with familiarity in cloud forensics and memory analysis considered advantageous. * Demonstrated ability to communicate complex technical findings clearly through reports, executive summaries, and stakeholder engagement. Minimum of 5 years of experience within a SOC, CERT, incident response, or forensic investigation environment, with the ability to manage competing priorities in fast-paced situations. * ## Description This is an exciting career opportunity to work in a multinational, Global 500 company that makes global trade happen. You will be interacting daily with colleagues internationally, giving you the opportunity to develop your professional skills in a global environment. We provide support for you to shape your own career by achieving expertise and learning on the job. * Work with cutting-edge cyber security technologies across traditional infrastructure, cloud, operational technology (OT), and emerging AI-driven environments. * Benefit from continuous learning opportunities through training, threat-hunting activities, cyber security projects, and Capture the Flag (CTF) exercises. * Enjoy flexible remote working arrangements with occasional in-person team activities that support work-life balance. Collaborate with a global team focused on innovation, knowledge sharing, continuous improvement, and operational excellence. * About the Role Join Maersk's Cyber team and play a key role in a modern incident management and response function that combines digital forensics, threat hunting, detection engineering, and cyber security improvement initiatives. This role offers the opportunity to contribute to complex investigations, strengthen response capabilities, and help shape the future of cyber defence within a globally recognised organisation., * Conduct digital forensic investigations across endpoint, cloud, and OT environments to support incident response and recovery activities. * Perform threat hunting and behavioural analysis to proactively identify threats and malicious activity across the network. * Deliver detailed forensic root cause analysis (RCA) and investigation findings to both technical and non-technical stakeholders. * Support cyber security uplift projects and help embed new capabilities, processes, and technologies into operational teams. * Collaborate with Cyber Operations teams to continuously improve detection, monitoring, and response capabilities. * Support security incident management activities, including triage, investigation, containment, recovery, and post-incident reviews. Act as an escalation point for complex investigations and contribute to the development of cyber response capabilities and junior team members. *