Incident response investigator

WithSecure

Greater London

On-site

GBP 70,000 - 110,000

Full time

11 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Freedom
Experienced colleagues
Global visibility

Job summary

WithSecure is seeking a Senior Incident Response Investigator to lead investigations for clients and produce high-quality reports. You will work on targeted attacks across large enterprise networks, with exposure to diverse OS environments and complex security architectures.

The role involves incident readiness support, report writing for technical and executive audiences, and mentoring junior staff while helping drive practice area growth.

Qualifications

  • CISSP qualification or equivalent experience.
  • Experience investigating targeted attacks across large enterprise networks.
  • Experience with client-server infrastructures, security architectures, logging and alerting across multiple OS.
  • Experience networking and network forensics down to packet level.
  • Detailed knowledge of file systems FAT, NTFS, HFS+ and EXT2/3/4; indicators of compromise.
  • Knowledge of Windows/Linux OS X internals and key system artifacts.
  • Ability to articulate Incident Response phases per NIST.
  • Familiarity with MITRE ATT&CK for Enterprise.
  • Knowledge of memory analysis.
  • Ability to report findings clearly to technical and senior management.

Responsibilities

  • Performing investigations for WithSecure clients and producing high quality reports to present findings and guidance.
  • Maintaining target utilization on client chargeable projects whilst working as a Senior Incident Response Investigator.
  • Producing output to highlight the technical competence of the company to a standard that can be published.
  • Supporting your practice area in successful delivery and growth.
  • Mentoring juniors along with supporting key business objectives through advice and guidance based on current industry trends.

Skills

CISSP
Targeted attacks
Client-server infra
OS logging/alerting
Network forensics
File system analysis
Windows internals
NIST IR
MITRE ATT&CK
Memory analysis
Clear reporting

Job description

WithSecure™ delivers research-led cyber security to defend organizations, society and people from real-world attacks and build resilience into their approach. Our people are a mix of technical and creative experts – diverse, talented, and passionate people – working tirelessly to help us advance the industry with new ways of thinking. They lead their own development, in and out of the office. They call the shots when it comes to building a place to call home in our organization.


WithSecure™ protects businesses all over the world from modern threats. We do this through a Co-security approach born from first-hand knowledge that no one can solve every cyber security problem alone. Every single day, our diverse, growing team fights against online extortion, threats to national infrastructure, the unlawful spread of sensitive information, and everything in-between. The best part about working for WithSecure is our people! We are a community of dedicated and passionate professionals that take workplace happiness seriously. If you’re looking for something that’s more than just a job – we’d love to hear from you.


The role also requires the ability to clearly communicate to a range of audiences from technical practitioners through to executive boards. This requires the ability to identify technical issues and describe them in the language of the business leaders you are engaged with.
A successful candidate should have an experience of both enterprise IT platforms and information security. They will be required to understand the motivations and methods adopted by a wide range of threat sources with a good understanding of how exploitation of systems occurs.
In addition, supporting Incident Readiness activities (such as Tabletop sessions, Client Training, and Playbook creation), when not actively supporting investigations.

Key Responsibilities
  • Performing investigations for WithSecure clients and producing high quality reports to present findings and guidance.
  • Maintaining target utilization on client chargeable projects whilst working as a Senior Incident Response Investigator.
  • Producing output to highlight the technical competence of the company to a standard that can be published.
  • Supporting your practice area in successful delivery and growth.
  • Mentoring juniors along with supporting key business objectives though advice and guidance based on current industry trends.
  • What are we looking for?
    • CISSP qualification or equivalent experience
    • Experience with investigating targeted attacks across large enterprise networks
    • Demonstrable experience of client-server infrastructures, security architectures and related logging and alerting across multiple operating systems
    • Demonstrable experience networking with the ability to perform network forensic analysis down to packet level
    • Demonstrable detailed knowledge of file-system analysis including FAT, NTFS, HFS+ and/or EXT2/3/4 and ability to find and extract common disk-based indicators of compromise
    • Knowledge of Windows, Linux and/or OS X internals and able to demonstrate knowledge of key system artefacts for each platform
    • Able to articulate the phases of Incident Response as defined by NIST
    • Familiarity MITRE ATT&CK Matrix for Enterprise framework
    • Knowledge of and experience in memory analysis
    • Ability to report key findings in a clear and concise manner both at technical and senior management level
Bonus points
  • Experience in Malware Analysis to a minimum level of behavioral analysis
  • Familiarity with one or more scripting language such as Python, Ruby, PowerShell or Bash is desirable
  • Experience of common cloud technologies
  • Vendor independent qualification in Incident Response and Forensics such as GIAC, IISFA, IACIS, ISFCE, ECCouncil or CREST certifications (e.g. CFCE, CCE, CIFI, CHFI, ECIH, GCIH, GCIA, GCFA, GCFE, GREM, GCED, Intrusion Analyst, Network or Host Intrusion Analyst or Malware Reverse Engineer)
  • Vendor specific qualification such as AccessData Certified Examiner (ACE), Encase Certified Examiner (EnCE) certification or X-Ways Professional in Evidence Recovery Techniques (X-PERT)
  • DV-clearance
  • Chartered Cyber Security Professional-status (ChCSP)
What will you get from us
  • Freedom – you will have the opportunity to define new ways of working how we engage with our customers, and how product value gets represented.
  • You will work together with experienced and enthusiastic colleagues, and within WithSecure you will find some of the best minds in the cyber security industry.
  • Your work will be clearly visible and recognised – all over the world and across our business units.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident response investigator
Incident response investigator

WithSecure • City Of London

On-site
GBP 90,000 - 130,000
Freedom to innovate
Collaborative team
Global exposure
Senior Consultant, Digital Forensics and Incident Response
Senior Consultant, Digital Forensics and Incident Response

Control Risks • City Of London

On-site
GBP 90,000 - 130,000
Hybrid working
Senior Consultant, Digital Forensics and Incident Response
Senior Consultant, Digital Forensics and Incident Response

Control Risks • Greater London

On-site
GBP 90,000 - 130,000
Hybrid working arrangements
Senior DFIR Consultant
Senior DFIR Consultant

NCC Group • Manchester

On-site
GBP 50,000 - 70,000
Flexible working arrangements
Comprehensive benefits package
Learning and development opportunities
Incident Response Analyst
Incident Response Analyst

Hamilton Barnes ? • United Kingdom

Remote
GBP 45,000 - 55,000
Senior Incident Response Investigator
Senior Incident Response Investigator

WithSecure • Greater London

On-site
GBP 70,000 - 110,000
Freedom
Experienced colleagues
Global visibility
Senior Incident Response Investigator & Mentor
Senior Incident Response Investigator & Mentor

WithSecure • City Of London

On-site
GBP 90,000 - 130,000
Freedom to innovate
Collaborative team
Global exposure
Consultant, Digital Forensics and Incident Response
Consultant, Digital Forensics and Incident Response

Control Risks • City Of London

On-site
GBP 70,000 - 110,000
Hybrid working arrangements
Global bonus scheme
Equal opportunity employer
Senior Consultant | Cybersecurity - Incident Response
Senior Consultant | Cybersecurity - Incident Response

FTI Consulting • Greater London

On-site
GBP 50,000 - 80,000
Senior Incident Response Consultant, Rapid Response
Senior Incident Response Consultant, Rapid Response

Sophos Group • Oxford

On-site
GBP 90,000 - 125,000