Incident Response Lead (DFIR)

LT Harper Recruitment Group

United Kingdom

Hybrid

GBP 99,000 - 121,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Pension contribution
Private healthcare
Structured training programme

Job summary

LT Harper Recruitment Group is partnering with a Cyber Consultancy to recruit an Incident Response Lead (DFIR) for hybrid work across the UK. You will lead case managers and practitioners, oversee incident lifecycles from scoping to recovery, and stay hands-on in forensics while shaping service growth.

You will manage complex incidents end-to-end, with exposure to government, critical infrastructure and large enterprises, and potentially travel for engagements.

Qualifications

  • Significant experience managing cyber security incidents end to end.
  • Strong digital forensics competency with professional tools.
  • Technical depth in at least one focus area (network/logs, memory, malware, or mobile forensics).
  • Working programming skillset (Python preferred) and Windows/Linux knowledge.
  • Excellent written and verbal communication for stakeholders.
  • Certifications such as CCIM, GCIH, CRIA, CCNIA, CCHIA, GCFA or CISA are desirable.
  • Current SC or DV clearance, or eligibility and willingness to obtain it.

Responsibilities

  • Manage and coordinate a portfolio of cyber security incidents for clients.
  • Lead a team through scoping, containment, evidence preservation, eradication and recovery.
  • Carry out and quality-assure digital forensics on disk, memory, network data and logs.
  • Own the commercial side of engagements including scoping, costing and risk.
  • Help clients mature their IR capability through playbooks and tabletop exercises.
  • Drive development of in-house response tooling, labs and procedures.
  • Mentor junior team members and contribute to bids and proposals.
  • Take part in on-call rotation and travel as needed.

Skills

Digital forensics
Incident response leadership
Network & log analysis
Python scripting
Windows/Linux admin
Communication skills
Security clearance
Threat intelligence

Tools

X-Ways
EnCase
FTK
AXIOM/IEF
Cellebrite

Job description

Incident Response Lead (DFIR) - Hybrid - Can be based anywhere in the UK - Up to £110k
The opportunity:

Do you want to lead the response to incidents that matter nationally?

A Cyber Consultancy is looking for an Incident Response Lead to join its Cyber Response Services team, reporting directly to the head of cyber response. This is a hands-on operational leadership role with a clear route into service line leadership. The team cover industries such as government, critical infrastructure and large enterprise, from ransomware through to advanced network intrusions. You will lead case managers and practitioners, stay technical in the forensics, and have a real say in how the practice grows.

Your benefits:

Up to £110k salary

Funded certifications and a structured training programme

Exposure to nationally significant incidents across government and CNI

Defined progression into senior leadership of a fast-growing capability

Hybrid working from London or Manchester hubs

Pension contribution and private healthcare [confirm]

Your responsibilities as an Incident Response Lead will be to:
  • Manage and coordinate a portfolio of cyber security incidents for clients, working closely with the head of cyber response
  • Lead a team of case managers and practitioners through the full incident lifecycle: scoping, triage, containment, evidence preservation, eradication and recovery
  • Carry out and quality-assure digital forensics on disk, volatile memory, network traffic and log data
  • Own the commercial side of engagements, including scoping, costing, financial management and risk
  • Help clients stand up or mature their own IR capability through playbooks, maturity assessments and tabletop exercises
  • Drive the development of in-house cyber response tooling, lab environments and operating procedures
  • Mentor junior team members and shape the team's learning and development
  • Contribute to bids and proposals, and maintain a current view of the threat landscape for clients
  • Take part in an on-call rotation and be ready to travel at short notice, sometimes for two to three weeks at a time
As an Incident Response Lead you will ideally have:
  • Significant experience managing complex cyber security incidents end to end, including leading a rapid deployment incident response team
  • Strong digital forensics competency, with advanced experience of tools such as X-Ways, EnCase, FTK, AXIOM/IEF or Cellebrite, and of preserving cloud data and encrypted evidence
  • Technical depth in at least one of network and log analysis, Linux or Mac forensics, memory forensics, malware reverse engineering or mobile forensics
  • A working programming skillset (Python preferred) and solid knowledge of enterprise Windows, Active Directory and Linux environments
  • Excellent written and verbal communication, with the ability to guide senior non-technical stakeholders through a live incident
  • Certifications such as CCIM, GCIH, CRIA, CCNIA, CCHIA, GCFA or GNFA are highly desirable, as are CISSP, CISM or CISA
  • Current SC or DV clearance, or eligibility and willingness to obtain it
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Incident Response - Senior Manager
Cyber Incident Response - Senior Manager

LT Harper Recruitment Group • Greater London

On-site
GBP 90,000 - 130,000
Incident Response Lead (DFIR)
Incident Response Lead (DFIR)

Forensic Focus Limited • United Kingdom

Hybrid
GBP 90,000 - 110,000
Incident Response Consultant - Systems Integrator
Incident Response Consultant - Systems Integrator

Hamilton Barnes Associates Limited • England

Hybrid
GBP 40,000 - 50,000
Mentorship
Exposure to advanced tools
Flexible working arrangement
DFIR Managing Consultant
DFIR Managing Consultant

NCC Group plc • Manchester

On-site
GBP 60,000 - 80,000
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response

Cyber UK • Greater London, Manchester

Hybrid
GBP 60,000 - 80,000
Lead DFIR Incident Response – Hybrid UK
Lead DFIR Incident Response – Hybrid UK

LT Harper Recruitment Group • Greater London, Manchester

Hybrid
GBP 99,000 - 121,000
Pension contribution
Private healthcare
Senior / Lead Incident Response Engineer
Senior / Lead Incident Response Engineer

Arcus Search • Greater London

Hybrid
GBP 90,000 - 150,000
Senior DFIR Incident Response Lead – Hybrid
Senior DFIR Incident Response Lead – Hybrid

Forensic Focus Limited • United Kingdom

On-site
GBP 90,000 - 110,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Bonhill Partners • Greater London

Hybrid
GBP 72,000 - 120,000
Senior Incident Responder / IR Consultant - Bristol
Senior Incident Responder / IR Consultant - Bristol

TieTalent • Bristol

Hybrid
GBP 60,000 - 80,000
Bonus
Good benefits