Digital Forensics & Incident Response Analyst

A.P. Møller - Maersk A/S

Thatcham

Hybrid

GBP 70,000 - 100,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Flexible remote work arrangements

Job summary

Maersk is seeking an experienced cyber forensics and incident response professional to join our global Cyber team. You will lead digital forensic investigations across Windows, Linux, cloud and OT, and conduct threat hunting to strengthen detection and response capabilities.

You will deliver clear RCA and investigative findings to stakeholders, support uplift projects, and mentor junior colleagues in a dynamic, multinational environment.

Qualifications

  • Minimum 5 years in a SOC, CERT, incident response or forensic investigations.
  • Proven experience conducting enterprise-scale digital forensic investigations on Windows and Linux.
  • Strong knowledge of forensic artefacts including event logs, registry analysis, browser artefacts and file systems.
  • Experience with threat hunting, security operations, incident investigation and SIEM platforms.
  • Hands-on with forensic tools X-Ways, EnCase, Autopsy, TimeSketch and Plaso; cloud forensics and memory analysis is a plus.
  • Ability to communicate complex technical findings clearly in reports and to stakeholders.

Responsibilities

  • Conduct digital forensic investigations across endpoint, cloud and OT environments to support incident response.
  • Perform threat hunting and behavioural analysis to identify threats and malicious activity.
  • Deliver forensic RCA and investigation findings to technical and non-technical stakeholders.
  • Support cyber security uplift projects and embed new capabilities and processes.
  • Collaborate with Cyber Operations to improve detection, monitoring and response capabilities.
  • Act as escalation point for complex investigations and mentor junior team members.

Skills

Digital forensics
Threat hunting
Security operations
Incident investigation
Communication

Tools

X-Ways
EnCase
Autopsy
TimeSketch
Plaso

Job description

Maersk is a global leader in integrated logistics and has been industry pioneers for over a century. Through innovation and transformation, we are redefining the boundaries of possibility, continuously setting new standards for efficiency, sustainability, and excellence.

At Maersk, we believe in the power of diversity, collaboration, and continuous learning, and we work hard to ensure that the people in our organisation reflect and understand the customers we exist to serve.

With over 100,000 employees across 130 countries, we work together to shape the future of global trade and logistics.

Join us as we harness cutting-edge technologies and unlock opportunities on a global scale. Together, let's sail towards a brighter, more sustainable future with Maersk.

What We Offer

This is an exciting career opportunity to work in a multinational, Global 500 company that makes global trade happen. You will be interacting daily with colleagues internationally, giving you the opportunity to develop your professional skills in a global environment. We provide support for you to shape your own career by achieving expertise and learning on the job.

  • Work with cutting-edge cyber security technologies across traditional infrastructure, cloud, operational technology (OT), and emerging AI-driven environments.
  • Benefit from continuous learning opportunities through training, threat-hunting activities, cyber security projects, and Capture the Flag (CTF) exercises.
  • Enjoy flexible remote working arrangements with occasional in-person team activities that support work-life balance.
  • Collaborate with a global team focused on innovation, knowledge sharing, continuous improvement, and operational excellence.
About the Role

Join Maersk's Cyber team and play a key role in a modern incident management and response function that combines digital forensics, threat hunting, detection engineering, and cyber security improvement initiatives. This role offers the opportunity to contribute to complex investigations, strengthen response capabilities, and help shape the future of cyber defence within a globally recognised organisation.

Key Responsibilities
  • Conduct digital forensic investigations across endpoint, cloud, and OT environments to support incident response and recovery activities.
  • Perform threat hunting and behavioural analysis to proactively identify threats and malicious activity across the network.
  • Deliver detailed forensic root cause analysis (RCA) and investigation findings to both technical and non-technical stakeholders.
  • Support cyber security uplift projects and help embed new capabilities, processes, and technologies into operational teams.
  • Collaborate with Cyber Operations teams to continuously improve detection, monitoring, and response capabilities.
  • Support security incident management activities, including triage, investigation, containment, recovery, and post-incident reviews.
  • Act as an escalation point for complex investigations and contribute to the development of cyber response capabilities and junior team members.
What We Are Looking For
  • Continuous improvement mindset: we are looking for someone who brings a thoughtful improvement mindset, curious about how work gets done and motivated to make meaningful, sustainable improvements over time.
  • Proven experience conducting enterprise-scale digital forensic investigations across Windows and Linux operating systems.
  • Strong knowledge of forensic artefacts including event logs, registry analysis, browser artefacts, file systems, persistence mechanisms, lateral movement techniques, and file-less attacks.
  • Experience with threat hunting, security operations, incident investigation, and security technologies such as SIEM platforms, firewalls, and monitoring solutions.
  • Hands-on knowledge of forensic tools such as X-Ways, EnCase, Autopsy, TimeSketch, and Plaso, with familiarity in cloud forensics and memory analysis considered advantageous.
  • Demonstrated ability to communicate complex technical findings clearly through reports, executive summaries, and stakeholder engagement.
  • Minimum of 5 years of experience within a SOC, CERT, incident response, or forensic investigation environment, with the ability to manage competing priorities in fast-paced situations.

#LI-JL2

Maersk is committed to a diverse and inclusive workplace, and we embrace different styles of thinking. Maersk is an equal opportunities employer and welcomes applicants without regard to race, colour, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability, medical condition, pregnancy or parental leave, veteran status, gender identity, genetic information, or any other characteristic protected by applicable law. We will consider qualified applicants with criminal histories in a manner consistent with all legal requirements.

We are happy to support your need for any adjustments during the application and hiring process. If you need special assistance or an accommodation to use our website, apply for a position, or to perform a job, please contact us by emailing accommodationrequests@maersk.com.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

A.P. Moller - Maersk • Maidenhead

Hybrid
GBP 70,000 - 110,000
Flexible remote working arrangements
Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

Damco Spain SL • Maidenhead

Hybrid
GBP 90,000 - 130,000
Flexible remote work
Digital Forensics & Incident Response Analyst
Digital Forensics & Incident Response Analyst

APM Terminals • Maidenhead

Hybrid
GBP 65,000 - 90,000
Cyber Incident Manager
Cyber Incident Manager

A.P. Moller - Maersk • Maidenhead

Hybrid
GBP 90,000 - 130,000
Flexible remote working
In-person team events
Cyber Incident Manager
Cyber Incident Manager

Maersk • Maidenhead

Hybrid
GBP 90,000 - 110,000
Flexible remote working
In-person team events
Work-life balance
Cyber Incident Manager
Cyber Incident Manager

APM Terminals Gothenburg • Maidenhead

Hybrid
GBP 70,000 - 110,000
Flexible remote working
Team events
Work-life balance
Cyber Incident Manager
Cyber Incident Manager

Maersk Line Limited • Maidenhead

Hybrid
GBP 85,000 - 110,000
Flexible remote working
Training platforms and simulations
Threat hunting and detection exposure
Remote Cyber Forensics & Incident Response Specialist
Remote Cyber Forensics & Incident Response Specialist

A.P. Moller - Maersk • Maidenhead

Hybrid
GBP 70,000 - 110,000
Flexible remote working arrangements
Remote Cyber Forensics & Threat Hunting Analyst
Remote Cyber Forensics & Threat Hunting Analyst

Damco Spain SL • Maidenhead

Hybrid
GBP 90,000 - 130,000
Flexible remote work
Remote Digital Forensics & Incident Response Lead
Remote Digital Forensics & Incident Response Lead

APM Terminals • Maidenhead

Hybrid
GBP 65,000 - 90,000