More jobs:
Job Description & How to Apply Below
Lead Incident Response Consultant | Remote (UK)
We are partnering with an ambitious Managed Security Service Provider established in Scotland with operations across EMEA and North America. They are a Microsoft Security Partner with NCSC status and have received several prestigious awards. The organization values its people and aims to protect organizations against cyber‑attacks.
Be the person organisations trust when everything’s on fire. When a serious cyber incident hits, you’ll lead the investigation, find the truth fast, guide the response, and help customers come out stronger.
What you’ll do Incident investigation & analysis (hands‑on, high‑impact)- Lead complex incident investigations across diverse technologies and environments.
- Participate in an on‑call rota with out‑of‑hours response as required.
- Perform advanced forensics across Windows, Linux, macOS and multi‑cloud environments (host, network, and memory).
- Analyse logs, network traffic, disk images, and volatile artefacts to establish attacker intent, actions, timeline, and impact.
- Identify adversary tools, tactics, and procedures (TTPs) and translate findings into clear next steps.
- Collect and preserve evidence to defensible standards, maintaining documentation and chain‑of‑custody.
- Stay current on emerging threats, malware families, and evolving threat actor behaviours.
- Work confidently with customer stakeholders including technical teams, legal, and executive leadership during incidents.
- Improve detection, escalation, containment, and response processes—internally and for customers.
- Collaborate with Threat Intelligence to enrich and ope rationalise investigative findings.
- Communicate findings and recommendations clearly to both technical and non‑technical audiences.
- Link technical findings to business risk, enabling better decision‑making at leadership level.
- Support privacy/security risk mitigation activities with internal and external teams.
- Deliver IR Readiness Assessments of customer plans, playbooks, and response capability.
- Provide executive and board‑level briefings and training on cyber security and incident response.
- Facilitate tabletop exercises that genuinely test and improve readiness.
- Mentor junior IR team members through coaching, technical guidance, and quality assurance—raising the bar across the function.
- Advanced forensic analysis across Windows, Linux, macOS, and cloud platforms.
- Memory forensics (static and dynamic).
- Strong network traffic and log analysis skills (firewall, endpoint, web, identity/authentication, cloud telemetry).
- Deep understanding of enterprise security controls:
Active Directory, identity systems, and network architectures. - Proficiency with EDR and SIEM platforms for investigations and threat hunting.
- Experience with Microsoft‑aligned security stacks.
- Ability to extract IOCs, identify attacker behaviour patterns, and map findings to TTPs.
- Evidence handling to defensible standards, including chain‑of‑custody.
- Comfortable building scripts, playbooks, or tooling to automate/improve investigation workflows.
- Work with a collaborative and forward‑thinking cybersecurity team.
- Competitive salary of circa £80k – £95k.
- Flexible working arrangements (remote/hybrid).
- 35 days holiday.
- Employee Assistance Programme.
- Opportunities for career growth and professional development.
Ready to apply? Send us your CV or reach out directly to learn more. Let’s help build a safer digital future together.
#J-18808-LjbffrNote that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×