Cyber Response & Recovery Manager – German Speaker

Cyber UK

Manchester

Hybrid

GBP 70,000 - 110,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

KPMG is seeking a Cyber Response & Recovery Manager (Reactive DFIR) to lead incident response cases within the CRS Team of the Cyber Advisory practice. You will manage investigations, perform forensics, and guide clients in threat containment and recovery while growing into a leadership role.

Role requires current SC or DV clearance or eligibility, with travel potential and on-call duties. Ideal candidates have strong technical and people skills to mentor junior staff and deliver high-quality

Qualifications

  • Proven incident management experience across diverse cyber security incidents.
  • Strong digital forensics background with incident response leadership.
  • Willingness to travel and be on-call on rotation.
  • Excellent communication and stakeholder-management skills.

Responsibilities

  • Lead and coordinate cyber security incidents for clients as a case manager.
  • Perform digital forensics analyses on disk, memory, network data and logs.
  • Develop and refine in-house cyber-response tools and playbooks.
  • Assess client incident response maturity and help stand up capabilities.
  • Manage engagements end-to-end including scoping, budgeting, and deliverables.

Skills

Incident response
Digital forensics
Case management
Leadership
Security awareness

Education

Master's degree in Information Security
Cybersecurity degree or equivalent

Tools

Python
X-Ways
EnCase
FTK
Cellebrite
Windows/Linux

Job description

Cyber Response & Recovery Manager (Reactive DFIR)This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance.

About the role

The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice.Your specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases.This is a hands-on incident response role and an opportunity to join a high performing team that works with a wide variety of clients, as KPMG are one of just nine Tier 1 responders in the UK. As such, you will gain a huge amount of experience in a short space of time and will also have the opportunity to be put through a range of security certifications.In this role we are looking for a person who can demonstrate strong technical background, experience in incident response and digital forensics and is looking to grow into an incident response leadership role as part of a growing team. You will be expected to lead a number of incident response cases as a case manager, as well as have the opportunity to work with, and learn from, the service leadership as part of your continuous development.When not responding to incidents, you may be helping our clients to build their in-house incident response capabilities, which could include: building and developing cyber-response tools, authoring and adapting runbooks/playbooks, assessing the incident response maturity, assisting in table-top cyber-scenario exercises. When not engaged in client work, you will be helping to develop our own delivery capability, including operational efficiency, standard operating procedures, team learning and development, tooling and platforms, lab development and orchestration.Candidates should have a proven track record of incident management, with a strong competency in digital forensics. KPMG will provide training and coaching to help you continually improve both your management and technical skills. Strong technical competency and experience of managing a range of complex cyber incidents; from ransomware to advanced network intrusions is a pre-requisite.Our clients expect that cyber-incidents will be tackled with urgency, therefore, there is an expectation that you will be flexible in terms of working hours and be on call (on a rotation basis). In addition, you should be prepared to travel on short notice for periods up to 2 or 3 weeks at a time.Above all, KPMG is looking for someone who is passionate about helping our clients with their cyber security challenges, often at a time of critical need. In return, we are committed to helping you to enjoy the role and develop your skills and career within the KPMG with the objective of progressing into a senior leadership role.

Why join us?
  • One of only nine UK Tier 1 incident response providers
  • Access to nationally significant incidents
  • Exposure across government and critical infrastructure
  • Investment in certifications and training
  • Opportunity to shape a rapidly growing capability
What will you be doing?
  • Manage and co-ordinate cyber security incidents for our clients, working closely the cyber response leadership team.
  • Digital forensics of relevant incident data (disk, volatile memory, network packets, log files).
  • Maintaining a current view of the cyber threat, and being able to advise clients on the threat landscape and attacks which may be relevant to them.
  • Manage the development of KPMG’s in house cyber-response tools.
  • Assess client incident response capability maturity.
  • Help stand-up or improve clients’ own incident response capabilities.
  • Project management of engagements to deliver high quality work in a timely manner, including:
  • Scoping and costing of engagements
  • Financial management of projects
  • Engagement and risk management
  • Production and review of deliverables to a high standard.
  • Liaising with clients on delivery, implementation and project issues.
  • Ability to generate well-structured responses to bids and requests for proposals.
The Person

You should have a strong background in cyber-security and incident response. For example: You should be able to guide a client through an unstructured incident response process (such as an advanced network intrusion) – managing resources and defining objectives at each stage of the incident response process; scoping and triage, containment, evidence preservation and extraction, eradication, recovery, forensic analysis and investigation.

  • Fluent German speaker and ability to draft reports in German.
  • A broad understanding of the cyber security threat landscape.
  • Strong technical background in computers and networks, and programming skills.
  • Significant and proven experience of dealing with cyber security incidents and associated response measures.
  • Experience of managing a rapid deployment incident response team.
  • Excellent interpersonal, written and communication skills.
  • Understanding of a wide range of information security and IT methodologies, principles, technologies and techniques.
  • A genuine interest and desire to develop and mention junior team members.
  • Strong attention for detail and the ability to manage multiple simultaneous cases.

Skills we’d love to see/Amazing Extras:The successful candidate will demonstrate competency in computing and networks as well as in cyber-security either by having the relevant work experience, completed a degree or obtained industry relevant certification. Therefore the qualifications below should be seen as means to demonstrate competency and not as a requirement. The desired skill and qualification is provided below:

  • Excellent communication skills (both written and oral) and project management skills.
  • Strong IT and network skills – knowledge of common enterprise technologies – Windows and Windows Active Directory, Linux, Cisco, etc.
  • Working programming skill-set to be able to author and develop tools. Most in-house security tools in KPMG are written in Python, but we accept that a competent programmer will be able to transfer skillsets across languages.
  • Technical proficiency in at least one of these areas: network security/traffic/log analysis; Linux and/or Mac/Unix operating system forensics; Linux/Unix disk forensics (ext2/3/4, HFS+, and/or APFS file systems), advanced memory forensics, static and dynamic malware analysis / reverse engineering, advanced mobile device forensics
  • Advanced experience in industry computer forensic tools such as X-Ways, EnCase, FTK, Internet Evidence Finder (IEF) / AXIOM, TZWorks, and/or Cellebrite
  • Advanced experience in preservation of digital evidence (including experience preserving cloud data and handling encryption such as BitLocker, FileVault, and/or LUKS)
  • Experience with and understanding of enterprise Windows security controls
  • (Preferred) Degree level qualified, MSc in Information Security, IT or relevant STEM subjects.
  • (Preferred) General information security certificates such CISSP, CISM or CISA.
  • (Preferred) Incident management certifications such as:
  • CREST certified incident manager (CCIM).
  • GIAC Certified Incident Handler (GCIH)
  • (Preferred) Digital forensics certificates such as:
  • CREST certified registered intrusion analyst (CRIA),
  • CREST certified network intrusion analyst (CCNIA),
  • CREST certified host intrusion analyst (CCHIA),
  • CREST certified malware reverse engineer (CCMRE),
  • GIAC Certified (Network) Forensic Analyst (GCFA, GNFA)
Location:

Our core hubs for this role are either:

  • London (Canary Wharf); or
  • Manchester (St Peter’s Square).

You must be within commutable distance to one of these locations. Current KPMG policy is 60% of the week with clients or our offices, 40% elsewhere (that can include working from home).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Response and Recovery - Assistant Manager (Reactive)
Cyber Response and Recovery - Assistant Manager (Reactive)

KPMG Careers • Greater London

Hybrid
GBP 70,000 - 90,000
Access to security certifications
Hybrid work model
Exposure to national incidents
Cyber Response & Recovery – Manager (Remediation focus)
Cyber Response & Recovery – Manager (Remediation focus)

Cyber UK • United Kingdom

Hybrid
GBP 90,000 - 130,000
Senior Consultant, Digital Forensics and Incident Response
Senior Consultant, Digital Forensics and Incident Response

Control Risks • Greater London

On-site
GBP 90,000 - 130,000
Hybrid working arrangements
Senior Consultant, Digital Forensics and Incident Response
Senior Consultant, Digital Forensics and Incident Response

Control Risks • City Of London

Hybrid
GBP 90,000 - 130,000
Hybrid working
Consultant, Digital Forensics and Incident Response
Consultant, Digital Forensics and Incident Response

Control Risks • City Of London

Hybrid
GBP 70,000 - 110,000
Hybrid working arrangements
Global bonus scheme
Equal opportunity employer
Consultant, Digital Forensics and Incident Response
Consultant, Digital Forensics and Incident Response

Control Risks • Greater London

On-site
GBP 65,000 - 100,000
Hybrid working arrangements
Global bonus scheme
Equal opportunities employer
+1
Consultant, Digital Forensics and Incident Response
Consultant, Digital Forensics and Incident Response

Control-Risks • Greater London

Hybrid
GBP 70,000 - 110,000
Hybrid working
Global bonus scheme
Career development and training
Senior Consultant | Cybersecurity - Incident Response
Senior Consultant | Cybersecurity - Incident Response

FTI Consulting • Greater London

On-site
GBP 50,000 - 80,000
Associate Consultant, Digital Forensics and Incident Response
Associate Consultant, Digital Forensics and Incident Response

Control-Risks • Greater London

Hybrid
GBP 55,000 - 85,000
Hybrid working
Discretionary global bonus
Graduate Consultant, Cyber Incident Response: One Year Fixed Term Contract
Graduate Consultant, Cyber Incident Response: One Year Fixed Term Contract

Control Risks Group • Greater London

Hybrid
GBP 28,000 - 34,000