Digital Forensics and Incident Response Analyst

Mishcon de Reya LLP

Greater London

On-site

GBP 65,000 - 90,000

Full time

47 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Mishcon de Reya LLP in London is seeking an Incident Response Specialist to join the Cyber Risk and Complex Investigations team. You will investigate, contain and eradicate threats as part of our CIR/CIE services, triaging incidents and delivering concrete outcomes under pressure.

You will collaborate with the internal security team, develop guidance for clients, and help improve playbooks while maintaining clear client communication and a high standard of service.

Qualifications

  • Hands-on experience investigating security incidents.
  • Ability to document findings clearly under supervision.
  • Strong knowledge of Windows endpoint environments and the Microsoft 365 security stack.
  • Experience analyzing logs from Windows systems, Active Directory, Azure AD, and M365 services.
  • Proactive mindset with the ability to improve playbooks and approaches.

Responsibilities

  • Respond to client-reported cyber incidents as part of CIR/CIE, conducting technical investigations under the incident lead.
  • Assess risks from system alerts and user-reported issues; escalate per playbooks.
  • Conduct forensic acquisition and analysis across platforms, including mobile devices.
  • Support incident management, guiding clients through decisions and containment.
  • Develop intelligence assessments and guidance for clients; support remediation and security uplift.

Skills

Incident response
Security investigations
Windows / M365
Endpoint forensics
Scripting: PowerShell / Python
Communication under pressure

Tools

Defender for Endpoint
Defender for Identity

Job description

The Department
The Cyber Risk and Complex Investigations team is made up of cyber and investigations specialists who work alongside our legal teams to provide a comprehensive and responsive client service.

Our practice works with clients to support them in the prevention of cyber-crime and the management of sophisticated and often complex cyber-attacks and helping them find digital information that supports their needs.

We have extensive experience of working on cyber security issues with a range of organisations, from large and complex global entities to mid-size or small firms, start-ups and private individuals. We help our clients implement the cyber security they need to address their threats, ensuring compliance with regulatory standards. If an incident occurs, we use our expertise and experience to help clients manage the technological, legal and reputational risks.

Offering a wider breadth of service and a broader range of solutions than traditional investigators, our team combines cutting edge cyber intelligence skills with innovative investigative techniques, understanding the legal requirement to gather facts and evidence properly, safely and ethically. We assess every investigation to ensure it meets our ethical and quality standards, as well as using a robust review process.

The team provides NCSC and CREST accredited security incident response and digital forensics services both internally and to our external clients and we are looking to grow and develop our response team.

The Role
In this role you will be a key member of our incident response team, acting as a first responder when clients report cyber incidents to us. You will investigate, contain, and eradicate threats as part of our NCSC Cyber Incident Response (CIR) and NCSC Cyber Incident Exercising (CIE) accredited service lines. You will also work alongside our internal security team to assess and respond to internal incidents and security queue items.

You must be comfortable receiving and triaging reported incidents, assessing risks quickly and accurately, escalating where necessary, and keeping clients informed throughout. You will operate under the pressure of live incident response conditions, making sound decisions and calmly developing and executing response plans to deliver concrete outcomes. Strong record-keeping and clear client communication are essential throughout.

Our incident response and digital forensics team operates a forensics lab to support the delivery of forensic services. You will be trained in digital forensics acquisition and investigation, with a particular focus on mobile device forensics. You will also be called upon regularly to support our internal security team and to provide technical advice and guidance to other internal teams to help them deliver the best possible advice to clients.

Responsibilities
  • Respond to client-reported cyber incidents as part of our NCSC CIR Standard Level accredited incident response service, conducting technical investigation activities under the direction of the incident lead.
  • Assess risks related to system generated alerts and user reported issues, escalating promptly and in line with established playbooks.
  • Action or elevate issues promptly and consistently in line with playbooks.
  • Identify areas of improvement for process or technology and contribute to their implementation.
  • Conduct forensic acquisition and analysis across a range of platforms and media in both incident response and discrete investigation scenarios, including specialist acquisition and examination of mobile devices.
  • Assist with incident management, including scoping work, guiding clients through decision making, and supporting containment and eradication.
  • Develop intelligence assessments of incidents and other potential threats to clients.
  • Support clients with longer term guidance and support with remediation and security uplift activities.
  • Provide specialist advice and guidance to internal teams on technical and forensic matters.
  • Support the internal security team in assessing and responding to internal incidents, managing the security queue, and contributing to the continuous improvement of internal security posture.
  • Contribute to Projects with both time and expertise.
  • Provide a high standard of customer experience to our clients.
Skills/Experience
  • Hands-on experience investigating security incidents, whether as a SOC analyst reviewing and analysing alerts and events, or as part of an incident response team conducting technical investigations.
  • Ability to conduct technical investigations as part of an incident response team, working under the direction of an incident lead to identify, scope, and document findings clearly.
  • Strong working knowledge of Windows endpoint environments and the Microsoft 365 security stack, including Defender for Endpoint, Defender for Identity, and Purview. Experience with Mac and Linux environments or Google Workspace is advantageous but not necessary.
  • Experience reviewing, triaging, and analysing security events and alerts, with the ability to distinguish genuine threats from noise and identify indicators of compromise across endpoint, identity, and cloud telemetry.
  • Experience extracting and analysing logs from Windows systems, Active Directory, Azure AD, M365 services, and other sources to identify evidence of malicious or anomalous
  • Experience examining Windows hosts for evidence of compromise, including artefact analysis, persistence mechanisms, lateral movement indicators, and timeline reconstruction. Familiarity with Mac and Linux host examination is advantageous but not necessary.
  • A proactive mindset: someone who authors and improves playbooks rather than simply following them, and who develops their own approaches to novel or undocumented incident types.
  • Proficiency with one or more scripting languages (PowerShell, Python, or similar) to automate triage tasks, parse artefacts, and accelerate investigations.
  • Technical curiosity and a genuine interest in the threat landscape, someone who keeps pace with attacker techniques, emerging TTPs, and defensive tooling, and can learn quickly and often with limited guidance.
  • Experience communicating technical findings clearly to clients and stakeholders in high-pressure situations, including the ability to explain complex security events in plain language is desirable.

Please note that this job profile is not an exhaustive list of duties but merely an outline of the key components of the role. You may be required by your line manager to take on additional responsibilities when requested.

About
About Mishcon de Reya Group

The Mishcon de Reya Group is an independent, international professional services business with law at its heart, employing over 1400 people with over 650 lawyers. It includes the law firm Mishcon de Reya LLP and a collection of leading consultancy businesses that complement the firm's legal services.

Mishcon de Reya LLP is based in London, Oxford, Cambridge, Singapore, Hong Kong and UAE. The firm services an international community of clients and provides advice in situations where the constraints of geography often do not apply. The work the firm undertakes is cross-border, multi-jurisdictional and complex, centred around three increasingly entwined and connected sectors: the Innovation Economy, Private Wealth and Capital, and Real Estate. The firm is known as a disputes powerhouse with a formidable capacity firmwide for dispute resolution.

The Mishcon de Reya Group includes consultancy businesses MDR Discover, MDR Mayfair (in London, Singapore and Dubai), MDR ONE, and MDRi (in Hong Kong). The Group also includes MDR Lab, which invests in the most promising early-stage legaltech companies as well as the Mishcon Academy, its in-house place of learning and platform for thought leadership.

In 2024, the Group announced its first strategic acquisition in the alternative legal services market, flexible legal resourcing business Flex Legal. It also acquired a majority stake in Somos, a global group actions management business.

We strive to create a fully diverse and inclusive workplace where all our people are empowered to fulfil their potential. We are proud of our agile working culture and are always happy to talk flexible working.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Digital Forensics and Incident Response Analyst
Digital Forensics and Incident Response Analyst

Mishcon de Reya Group • City Of London

On-site
GBP 65,000 - 90,000
Business Development & Growth Executive (Campaigns & Activations) - 12 Month FTC
Business Development & Growth Executive (Campaigns & Activations) - 12 Month FTC

Mishcon de Reya LLP • Greater London

On-site
GBP 42,000 - 65,000
Business Development and Growth Executive (Content)
Business Development and Growth Executive (Content)

Mishcon de Reya LLP • Greater London

On-site
GBP 40,000 - 52,000
Technology Senior Solution Architect
Technology Senior Solution Architect

Mishcon de Reya LLP • Greater London

Hybrid
GBP 90,000 - 150,000
Brand and Marketing Manager
Brand and Marketing Manager

Mishcon de Reya LLP • Greater London

On-site
GBP 60,000 - 90,000
Flexible working
Technology Solution Architect
Technology Solution Architect

Mishcon de Reya LLP • Greater London

Hybrid
GBP 90,000 - 120,000
Digital Marketing Data Executive
Digital Marketing Data Executive

Mishcon de Reya LLP • Greater London

On-site
GBP 55,000 - 75,000
Data Protection Officer
Data Protection Officer

Mishcon de Reya LLP • Greater London

On-site
GBP 90,000 - 130,000
Service Management Architect
Service Management Architect

Mishcon de Reya LLP • Greater London

On-site
GBP 70,000 - 110,000
Hybrid working
Managing Associate (5-6 PQE)
Managing Associate (5-6 PQE)

Mishcon de Reya LLP • Greater London

On-site
GBP 95,000 - 160,000