Incident Response Lead - Cloud & Forensics (Hybrid)

Starling

Cardiff

Hybrid

GBP 55,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Private Medical Insurance
Life insurance 4x salary
Perkbox membership
Cycle to Work

Job summary

Starling is seeking a passionate Incident Responder to join the Security Operations team and protect customers, assets and systems with 24/7 coverage. You will report to the Information Security Lead - SecOps Response and own incident handling from detection through recovery.

The role requires 3+ years in cyber incident response and digital forensics, strong communication skills, and the ability to mentor colleagues. We offer hybrid working across UK offices, including Cardiff.

Qualifications

  • 3+ years experience in a cyber incident response and digital forensics function.
  • Experience in handling incidents.
  • Experience in cloud forensics (GCP, AWS).
  • Experience in endpoint and server forensics (Windows, MacOS, Linux).
  • Experience in network forensics.
  • Experience with forensics data acquisition, disk forensics and memory forensics.
  • Experience in supporting and planning Tabletop Exercises.
  • Understanding of network, cloud and operating system security controls.
  • Excellent communication skills to explain complex concepts to diverse audiences.
  • Demonstrated teamwork and collaboration in multi‑functional teams.
  • Strong time management, problem-solving and interpersonal skills.
  • Eagerness to learn and apply knowledge to security challenges.
  • Willingness to mentor colleagues.

Responsibilities

  • Conduct incident response activities to investigate and contain cyber security incidents.
  • Develop and maintain incident response and readiness processes.
  • Analyse logs from cloud, endpoint, and network sources to identify root cause and containment steps.
  • Plan and participate in Tabletop Exercises.
  • Document notes, analysis findings, containment steps, and causes of incidents.
  • Collaborate with other teams to analyse, contain, eradicate and recover from incidents.
  • Present investigation findings to technical and non-technical audiences.
  • Support detection engineering and threat hunting within SecOps.

Skills

Incident response
Digital forensics
Threat hunting
Communication
Teamwork
Time management
Mentoring

Tools

GCP
AWS
Forensic tools

Job description

Starling is seeking a passionate Incident Responder to join the Security Operations team and protect customers, assets and systems with 24/7 coverage. You will report to the Information Security Lead - SecOps Response and own incident handling from detection through recovery.

The role requires 3+ years in cyber incident response and digital forensics, strong communication skills, and the ability to mentor colleagues. We offer hybrid working across UK offices, including Cardiff.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid InfoSec Incident Response Analyst | Cloud Forensics
Hybrid InfoSec Incident Response Analyst | Cloud Forensics

JOBS247 INC LTD • Southampton

Hybrid
GBP 60,000 - 90,000
25 days holiday
Company enhanced pension
Buy/sell up to five extra days off
Incident Response Analyst - 24/7 Security Operations
Incident Response Analyst - 24/7 Security Operations

Starling • Greater London

Hybrid
GBP 65,000 - 90,000
25 days holiday
Birthday leave
Pension scheme
+3
Incident Responder – 24/7 Cyber Defense Expert
Incident Responder – 24/7 Cyber Defense Expert

Starling • Southampton

Hybrid
GBP 60,000 - 90,000
Private Medical Insurance
Life insurance
Cycle to Work
Cyber Incident Responder – 24/7 SecOps (Hybrid)
Cyber Incident Responder – 24/7 SecOps (Hybrid)

Starling • Manchester

Hybrid
GBP 70,000 - 110,000
Life insurance
Pension plan
Private Medical Insurance
+8
Cyber Incident Response Lead (Hybrid)
Cyber Incident Response Lead (Hybrid)

Royal London • Alderley Edge

Hybrid
GBP 70,000 - 100,000
28 days annual leave
Pension scheme
Private medical insurance
Lead Incident Response Engineer (Hybrid)
Lead Incident Response Engineer (Hybrid)

Checkout Ltd • Greater London

Hybrid
GBP 70,000 - 90,000
Flexible hybrid working model
Opportunities for growth and recognition
Cyber Incident Response Lead — Hybrid
Cyber Incident Response Lead — Hybrid

Royal London Mutual Insurance Society • Alderley Edge

Hybrid
GBP 90,000 - 110,000
28 days annual leave
Private medical insurance
Employer pension contribution up to 14
Information Security Analyst – SecOps Response
Information Security Analyst – SecOps Response

JOBS247 INC LTD • Southampton

Hybrid
GBP 60,000 - 90,000
25 days holiday
Company enhanced pension
Buy/sell up to five extra days off
Senior Incident Response Lead Hybrid Remote UK
Senior Incident Response Lead Hybrid Remote UK

Nettitude Group • Birmingham

Hybrid
GBP 80,000 - 120,000
Lead Incident Response Analyst
Lead Incident Response Analyst

IntaPeople: STEM Recruitment • Cardiff

Hybrid
GBP 55,000
Bespoke learning plans
Bonus plan