×
Register Here to Apply for Jobs or Post Jobs. X

Corporate Forensic Analyst

Job in Edinburgh, City of Edinburgh Area, EH1, Scotland, UK
Listing for: CYFOR group
Full Time position
Listed on 2026-07-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Digital Media & Production
Job Description & How to Apply Below

Corporate Forensic Analyst
Location: Remote/Hybrid (UK-based)

The Role

Due to our continued growth, we are looking for an experienced Corporate Forensic Analyst to join the CYFOR Secure Incident Response team.

The successful candidate will primarily focus on corporate forensic investigations involving dead-box analysis across computers, mobile devices, cloud platforms and email environments. The role is centred around the forensic investigation and evidential analysis side of cyber security incidents, supporting clients through structured and defensible digital forensic examinations.

You will also work closely with the wider Incident Response team, supporting investigations into business email compromise (BEC), ransomware and other cyber incidents where forensic analysis is required. While the role is not primarily an incident response position, there will be opportunities to assist live investigations and support broader response activities where appropriate.

The ideal candidate will have experience conducting forensic examinations across Windows systems, mobile devices and cloud-based environments, with excellent attention to detail, strong reporting skills and a professional client-facing approach. You will also demonstrate integrity, flexibility and the ability to manage sensitive investigations with discretion.

In return, you'll receive a salary commensurate with experience; plus training, overtime and excellent career prospects. You'll enjoy a varied and highly fulfilling role, working with great colleagues in a fantastic atmosphere.

This is a unique opportunity to join a highly successful business that truly focuses on its main asset, its team members.

Main Responsibilities
  • Conduct forensic examinations of desktop computers, laptops, servers and mobile devices using forensically sound methodologies.
  • Acquire, preserve and analyse digital evidence from Windows systems, mobile devices, cloud platforms and email environments while maintaining evidential integrity.
  • Perform dead-box forensic investigations involving deleted data recovery, user activity analysis, timeline reconstruction and artefact examination.
  • Investigate cloud and email platforms including Microsoft 365, Exchange Online and associated audit logs to identify suspicious or malicious activity.
  • Support investigations into ransomware, business email compromise (BEC), insider threats, data theft and unauthorised access incidents.
  • Use forensic and case management tooling including Magnet Axiom and Salesforce throughout investigations and evidence handling workflows.
  • Produce high-quality forensic reports suitable for internal stakeholders, legal teams, law enforcement and corporate clients.
  • Assist with expert witness statements and provide court attendance when required.
  • Support the Incident Response team during active cyber incidents where forensic expertise is required.
  • Maintain accurate chain of custody documentation and evidence handling procedures throughout investigations.
  • Deliver clear and concise updates to clients and stakeholders throughout engagements.
  • Assist with forensic triage and evidence collection during onsite and remote engagements when required.
  • Contribute to the continuous improvement of forensic methodologies, processes and internal capabilities.
  • Keep up to date with emerging threats, forensic techniques and evolving technologies across endpoint, mobile and cloud ecosystems.
  • Support knowledge sharing and mentoring activities across the wider team where appropriate.
Skills and Experience
  • Minimum 3 years’ experience in digital forensics or cyber investigations.
  • Experience conducting dead-box forensic investigations across Windows systems and mobile devices.
  • Experience collecting, preserving and analysing digital evidence using industry-standard forensic methodologies.
  • Experience using Magnet Axiom, Encase or X-Ways and other digital forensic tooling.
  • Knowledge of Microsoft 365, Exchange Online and cloud-based investigations.
  • Ability to analyse forensic artefacts and reconstruct user and system activity timelines.
  • Understanding of ransomware and business email compromise investigations.
  • Experience producing detailed technical and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary