Digital Forensics & Incident Response Analyst

APM Terminals

Maidenhead

Hybrid

GBP 65,000 - 90,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Maersk's Cyber team invites an experienced security professional to join a modern incident management and response function, combining digital forensics, threat hunting, detection engineering, and cyber security improvement.

You will investigate complex incidents across endpoints, cloud, and OT, deliver root cause analyses, support uplift projects, and mentor junior staff within a globally recognised logistics leader.

Qualifications

  • 5+ years in SOC, CERT, IR or forensic investigations.
  • Proficient in Windows and Linux forensics and artefacts.
  • Experience with enterprise SIEM, EDR, and monitoring tools.
  • Strong report writing and stakeholder communication.

Responsibilities

  • Conduct digital forensic investigations across endpoint, cloud, and OT environments to support incident response and recovery activities.
  • Perform threat hunting and behavioural analysis to proactively identify threats and malicious activity across the network.
  • Deliver detailed forensic root cause analysis (RCA) and investigation findings to both technical and non-technical stakeholders.
  • Support cyber security uplift projects and help embed new capabilities, processes, and technologies into operational teams.
  • Collaborate with Cyber Operations teams to continuously improve detection, monitoring, and response capabilities.
  • Support security incident management activities, including triage, investigation, containment, recovery, and post-incident reviews.
  • Act as an escalation point for complex investigations and contribute to the development of cyber response capabilities and junior team members.

Skills

Digital forensics
Threat hunting
Incident response
Security reporting
Communication

Tools

X-Ways
EnCase
Autopsy
TimeSketch
Plaso
SIEM
Firewalls

Job description

Maersk is a global leader in integrated logistics and has been industry pioneers for over a century. Through innovation and transformation, we are redefining the boundaries of possibility, continuously setting new standards for efficiency, sustainability, and excellence. At Maersk, we believe in the power of diversity, collaboration, and continuous learning, and we work hard to ensure that the people in our organisation reflect and understand the customers we exist to serve. With over 100,000 employees across 130 countries, we work together to shape the future of global trade and logistics. Join us as we harness cutting-edge technologies and unlock opportunities on a global scale. Together, let's sail towards a brighter, more sustainable future with Maersk.

What We Offer

This is an exciting career opportunity to work in a multinational, Global 500 company that makes global trade happen. You will be interacting daily with colleagues internationally, giving you the opportunity to develop your professional skills in a global environment. We provide support for you to shape your own career by achieving expertise and learning on the job. Work with cutting-edge cyber security technologies across traditional infrastructure, cloud, operational technology (OT), and emerging AI-driven environments. Benefit from continuous learning opportunities through training, threat-hunting activities, cyber security projects, and Capture the Flag (CTF) exercises. Enjoy flexible remote working arrangements with occasional in-person team activities that support work-life balance. Collaborate with a global team focused on innovation, knowledge sharing, continuous improvement, and operational excellence.

About the Role

Join Maersk's Cyber team and play a key role in a modern incident management and response function that combines digital forensics, threat hunting, detection engineering, and cyber security improvement initiatives. This role offers the opportunity to contribute to complex investigations, strengthen response capabilities, and help shape the future of cyber defence within a globally recognised organisation.

Key Responsibilities

Conduct digital forensic investigations across endpoint, cloud, and OT environments to support incident response and recovery activities. Perform threat hunting and behavioural analysis to proactively identify threats and malicious activity across the network. Deliver detailed forensic root cause analysis (RCA) and investigation findings to both technical and non-technical stakeholders. Support cyber security uplift projects and help embed new capabilities, processes, and technologies into operational teams. Collaborate with Cyber Operations teams to continuously improve detection, monitoring, and response capabilities. Support security incident management activities, including triage, investigation, containment, recovery, and post-incident reviews. Act as an escalation point for complex investigations and contribute to the development of cyber response capabilities and junior team members.

What We Are Looking For

Continuous improvement mindset: we are looking for someone who brings a thoughtful improvement mindset, curious about how work gets done and motivated to make meaningful, sustainable improvements over time. Proven experience conducting enterprise-scale digital forensic investigations across Windows and Linux operating systems. Strong knowledge of forensic artefacts including event logs, registry analysis, browser artefacts, file systems, persistence mechanisms, lateral movement techniques, and file-less attacks. Experience with threat hunting, security operations, incident investigation, and security technologies such as SIEM platforms, firewalls, and monitoring solutions. Hands-on knowledge of forensic tools such as X-Ways, EnCase, Autopsy, TimeSketch, and Plaso, with familiarity in cloud forensics and memory analysis considered advantageous. Demonstrated ability to communicate complex technical findings clearly through reports, executive summaries, and stakeholder engagement. Minimum of 5 years of experience within a SOC, CERT, incident response, or forensic investigation environment, with the ability to manage competing priorities in fast-paced situations.

#LI-JL2

Maersk is committed to a diverse and inclusive workplace, and we embrace different styles of thinking. Maersk is an equal opportunities employer and welcomes applicants without regard to race, colour, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability, medical condition, pregnancy or parental leave, veteran status, gender identity, genetic information, or any other characteristic protected by applicable law. We will consider qualified applicants with criminal histories in a manner consistent with all legal requirements. We are happy to support your need for any adjustments during the application and hiring process. If you need special assistance or an accommodation to use our website, apply for a position, or to perform a job, please contact us by emailing accommodationrequests@maersk.com.

A.P. Moller - Maersk is an integrated container logistics company working to connect and simplify its customer's supply chains. As the global leader in shipping services, the company operates in 130 countries and employs roughly 100,000 people. With simple end-to-end offering of products and digital services, seamless customer engagement and a superior end-to-end delivery network, Maersk enables its customers to trade and grow by transporting goods anywhere - all over the world. For more information click here. All the way.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

A.P. Møller - Maersk A/S • Thatcham

Hybrid
GBP 70,000 - 100,000
Flexible remote work arrangements
Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

A.P. Moller - Maersk • Maidenhead

Hybrid
GBP 70,000 - 110,000
Flexible remote working arrangements
Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

Damco Spain SL • Maidenhead

On-site
GBP 90,000 - 130,000
Flexible remote work
Cyber Incident Manager
Cyber Incident Manager

APM Terminals Gothenburg • Maidenhead

On-site
GBP 70,000 - 110,000
Flexible remote working
Team events
Work-life balance
Cyber Incident Manager
Cyber Incident Manager

A.P. Moller - Maersk • Maidenhead

Hybrid
GBP 90,000 - 130,000
Flexible remote working
In-person team events
Cyber Incident Manager
Cyber Incident Manager

Maersk • Maidenhead

Hybrid
GBP 90,000 - 110,000
Flexible remote working
In-person team events
Work-life balance
Cyber Incident Manager
Cyber Incident Manager

Maersk Line Limited • Maidenhead

Hybrid
GBP 85,000 - 110,000
Flexible remote working
Training platforms and simulations
Threat hunting and detection exposure
Senior Cyber Engineer
Senior Cyber Engineer

APM Terminals • Maidenhead

On-site
GBP 90,000 - 120,000
Remote Cyber Forensics & Incident Response Specialist
Remote Cyber Forensics & Incident Response Specialist

A.P. Moller - Maersk • Maidenhead

Hybrid
GBP 70,000 - 110,000
Flexible remote working arrangements
Remote Cyber Forensics & Threat Hunting Analyst
Remote Cyber Forensics & Threat Hunting Analyst

Damco Spain SL • Maidenhead

Hybrid
GBP 90,000 - 130,000
Flexible remote work