NMC Cyber Incident Responder (Digital Forensics)

Police Digital Service

Wigan

Hybrid

GBP 50,000 - 61,000

Full time

21 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

28 days annual leave + bank holidays
Excellent pension scheme
Remote GP and wellbeing support
Volunteer day

Job summary

Police Digital Service in the United Kingdom is seeking an NMC Cyber Incident Responder (Digital Forensics) to lead and support investigations of cyber security incidents affecting policing, combining digital forensics, incident response and stakeholder engagement.

You will conduct forensic examinations of compromised systems, analyse host, network and memory evidence, preserve digital evidence and work with threat intelligence and force partners to inform remediation and decision-making.

Qualifications

  • Experience conducting digital forensic investigations within enterprise environments.
  • Experience performing endpoint and memory forensic analysis during cyber security incidents.
  • Experience investigating ransomware, malware, unauthorised access, and data compromise incidents.
  • Ability to collect, preserve and analyse digital evidence whilst maintaining evidential integrity.
  • Strong understanding of Windows internals, artefacts and attacker tradecraft.
  • Experience communicating technical findings to senior stakeholders.
  • Knowledge of incident response lifecycle and cyber investigation methodologies.

Responsibilities

  • Lead and support investigations into cyber security incidents affecting UK policing.
  • Perform detailed forensic analysis of endpoints, servers, cloud environments and digital evidence.
  • Support containment, eradication and recovery activities with evidence-based recommendations.
  • Develop and maintain investigative methodologies and playbooks aligned to incident response frameworks.
  • Acquire, preserve and analyse digital evidence in accordance with forensic best practice.
  • Provide clear technical briefings to senior stakeholders.

Skills

Digital Forensics
Incident Response
Windows Internals
Memory Forensics
Threat Intelligence
Stakeholder Engagement
Documentation

Tools

SIEM
EDR
Forensic Tools

Job description

We are excited you have visited our Careers page. We are seeking talented individuals that are excellent in their field of expertise and are posed with all potential and skills necessary to help us meet future business challenges.

Position not right for you?

Share it with someone you know.

Join Police Digital Service as NMC Cyber Incident Responder (Digital Forensics)

Salary starting at £55,000 per annum

As a member of the National Management Centre (NMC) Cyber Incident Response team, you will lead and support the investigation of cyber security incidents affecting UK policing. This role combines digital forensics, incident response and stakeholder engagement, requiring the ability to identify, contain and investigate sophisticated cyber threats across diverse technology estates.

You will conduct forensic examinations of compromised systems, analyse host, network and memory-based evidence, and support the collection and preservation of digital evidence to establish root cause, impact and attacker activity. Working closely with threat intelligence, detection engineering and force stakeholders, you will provide technically sound advice to support incident remediation and organisational decision-making.

Key Responsibilities
  • Lead and support investigations into cyber security incidents affecting UK policing, including ransomware, malware outbreaks, unauthorised access, data compromise and insider threat investigations.
  • Perform detailed forensic analysis of endpoints, servers, cloud environments and associated digital evidence to evaluate the scope, root cause and impact of incidents.
  • Support incident containment, eradication and recovery activities through evidence-based recommendations.
  • Develop and maintain investigative methodologies, playbooks and procedures aligned to recognised incident response frameworks.
  • Acquire, preserve and analyse digital evidence in accordance with forensic best practice and evidential integrity requirements.
  • Perform forensic collection activities using appropriate live response techniques.
  • Analyse operating system artefacts, event logs, registry data, memory captures, network evidence and application data to support investigations.
  • Produce accurate and defensible investigative findings suitable for operational, legal and executive audiences.
  • Maintain awareness of emerging forensic tools, techniques and methodologies.
Stakeholder Engagement
  • Act as a trusted advisor to police forces and policing organisations during cyber incidents.
  • Provide clear technical and strategic briefings to senior stakeholders including Chief Officers, CIOs, Heads of IT, Heads of Cyber Security and other policing partners.
  • Coordinate with internal and external stakeholders to ensure effective incident management and communication throughout the lifecycle of an investigation.
  • Support national coordination activities where incidents have cross-force or sector-wide implications.
  • Utilise threat intelligence, attacker TTPs and industry frameworks such as MITRE ATT&CK to inform investigations and response activity.
  • Identify trends, lessons learned and opportunities to improve cyber resilience across UK policing.
  • Contribute to the development of detection capabilities and response processes through post-incident reviews and technical findings.
  • Support knowledge sharing, mentoring and capability development across the wider NMC function.
What you need to succeed in the role
  • Experience conducting digital forensic investigations within enterprise environments.
  • Experience performing endpoint and memory forensic analysis during cyber security incidents.
  • Experience investigating ransomware, malware, unauthorised access, and data compromise incidents.
  • Ability to collect, preserve and analyse digital evidence whilst maintaining evidential integrity.
  • Strong understanding of Windows internals, operating system artefacts and attacker tradecraft.
  • Experience communicating technical findings and recommendations to senior stakeholders.
  • Strong knowledge of incident response lifecycle and cyber investigation methodologies.
  • Experience analysing logs, EDR telemetry, SIEM data and forensic artefacts to evaluate root cause and impact.

For a full list of responsibilities and criteria, please refer to the Candidate Pack.

Why Join us?
  • Balance is important and we want you to take time off to recharge - we offer 28 days’ annual leave plus bank holidays, rising to 30 days after 5 years of service. Holiday Purchase also available
  • We care about your well-being - we have an EAP that offers not just welfare benefits but also retail discounts
  • Plan for the future - we offer an excellent pension scheme and life assurance cover
  • Put your mind at rest regarding your health - offering remote GP, mental health and physiotherapy appointments via video consultation
  • Family - Enhanced maternity and paternity pay along with a flexible return to work
  • Community - one paid day off per year for volunteering

We are committed to equal opportunity for all and will not discriminate on any grounds. We encourage applications from people from the widest possible span of experience. We particularly welcome applications from Black, Asian and Minority Ethnic (BAME) candidates and people with disabilities.

Working Arrangements

At the NMC, you will benefit from hybrid working, getting the advantages of both face-to-face team engagement and home working. NMC employees have the opportunity to work in our modern office environment for in-person collaboration, alongside the opportunity to work from home 2 days a week.

This is a Monday-Friday shift-based role.

All applicants must be eligible for NPPV3 and SC clearances. Successful applicants will require NPPV3 clearance to have been approved before starting with PDS.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

NMC Cyber Incident Responder (Digital Forensics)
NMC Cyber Incident Responder (Digital Forensics)

PDS Cyber Services • Wigan

Hybrid
GBP 55,000 - 65,000
28 days annual leave + bank holidays
Remote GP and mental health support
Excellent pension scheme and life-asso
+1
NMC Cyber Detect Analyst
NMC Cyber Detect Analyst

Police Digital Service • Wigan

Hybrid
GBP 41,000 - 50,000
Annual leave and holiday buy
Pension and life assurance
Remote GP and wellbeing support
+3
NMC Cyber Detect Analyst
NMC Cyber Detect Analyst

PDS Cyber Services • Wigan

Hybrid
GBP 41,000 - 50,000
28 days annual leave + bank holidays (
EAP with welfare benefits and retail‑s
Pension scheme and life assurance
+2
NMC Cyber Detect Analyst
NMC Cyber Detect Analyst

National Enabling Programmes (a programme of the Police Digital Service) • Greater Manchester

Hybrid
GBP 41,000 - 50,000
28 days annual leave
EAP and discounts
Pension scheme
+2
NMC Cyber Detect Analyst
NMC Cyber Detect Analyst

Police Digital Service • Lancashire

Hybrid
GBP 45,000 - 52,000
28 days leave
Bank holidays
Pension scheme
+1
NMC Cyber Security Detection Engineer
NMC Cyber Security Detection Engineer

Police Digital Service • Wigan

Hybrid
28 days of annual leave
Flexible working hours
Well-being programs
+4
NMC Senior Cyber Threat Hunter
NMC Senior Cyber Threat Hunter

Women in Data® • Wigan

Hybrid
28 days annual leave plus bank holidays
Flexible working hours
Employee Assistance Program (EAP)
NMC Cyber Security Engineer
NMC Cyber Security Engineer

Women in Data® • Wigan

Hybrid
Digital Forensic Unit Technician (NEROCU)
Digital Forensic Unit Technician (NEROCU)

Northumbria • Sunderland

On-site
GBP 29,000 - 30,000
26 days leave
Car lease scheme
Flexible working
+4
Cyber Security Operations Specialist - 2 positions available
Cyber Security Operations Specialist - 2 positions available

Police Digital Service • Greater London

Remote
GBP 60,000 - 69,000
28 days annual leave plus bank holidays
Flexible working hours
Employee Assistance Program
+2