NMC Cyber Incident Responder (Digital Forensics)

PDS Cyber Services

Wigan

Hybrid

GBP 55,000 - 65,000

Full time

21 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

28 days annual leave + bank holidays
Remote GP and mental health support
Excellent pension scheme and life-asso
One paid volunteering day per year

Job summary

PDS Cyber Services in the United Kingdom is recruiting an NMC Cyber Incident Responder (Digital Forensics) to lead and support investigations into cyber security incidents affecting UK policing. The role combines digital forensics, incident response and stakeholder engagement to identify, contain and investigate threats.

You will conduct forensic examinations of compromised systems, analyse evidence across endpoints, servers and cloud, and guide remediation efforts.

Qualifications

  • Experience conducting digital forensic investigations within enterprise environments.
  • Experience performing endpoint and memory forensic analysis during cyber security incidents.
  • Experience investigating ransomware, malware, unauthorised access, and data compromise incidents.
  • Ability to collect, preserve and analyse digital evidence whilst maintaining evidential integrity.
  • Strong understanding of Windows internals, operating system artefacts and attacker tradecraft.
  • Experience communicating technical findings to senior stakeholders.
  • Strong knowledge of incident response lifecycle and cyber investigation methodologies.
  • Experience analysing logs, EDR telemetry, SIEM data and forensic artefacts to evaluate root cause and impact.

Responsibilities

  • Lead and support investigations into cyber security incidents across UK policing.
  • Perform forensic analysis of endpoints, servers, cloud to evaluate scope and impact.
  • Support containment, eradication and recovery with evidence-based recommendations.
  • Develop methodologies, playbooks and procedures aligned to incident response frameworks.
  • Acquire, preserve and analyse digital evidence with evidential integrity.
  • Analyse OS artefacts, logs, memory, network data to support investigations.
  • Produce findings for operational, legal and executive audiences.
  • Stay updated on emerging forensic tools and techniques.

Skills

Digital forensics
Incident response
Windows internals
Memory forensics
Evidence handling
Stakeholder communication
Threat intelligence awareness
Analytical thinking

Job description

Join Police Digital Service as NMC Cyber Incident Responder (Digital Forensics)

Salary starting at £55,000 per annum

As a member of the National Management Centre (NMC) Cyber Incident Response team, you will lead and support the investigation of cyber security incidents affecting UK policing. This role combines digital forensics, incident response and stakeholder engagement, requiring the ability to identify, contain and investigate sophisticated cyber threats across diverse technology estates.

You will conduct forensic examinations of compromised systems, analyse host, network and memory-based evidence, and support the collection and preservation of digital evidence to establish root cause, impact and attacker activity. Working closely with threat intelligence, detection engineering and force stakeholders, you will provide technically sound advice to support incident remediation and organisational decision-making.

Key Responsibilities

  • Lead and support investigations into cyber security incidents affecting UK policing, including ransomware, malware outbreaks, unauthorised access, data compromise and insider threat investigations.
  • Perform detailed forensic analysis of endpoints, servers, cloud environments and associated digital evidence to evaluate the scope, root cause and impact of incidents.
  • Support incident containment, eradication and recovery activities through evidence-based recommendations.
  • Develop and maintain investigative methodologies, playbooks and procedures aligned to recognised incident response frameworks.
  • Acquire, preserve and analyse digital evidence in accordance with forensic best practice and evidential integrity requirements.
  • Perform forensic collection activities using appropriate live response techniques.
  • Analyse operating system artefacts, event logs, registry data, memory captures, network evidence and application data to support investigations.
  • Produce accurate and defensible investigative findings suitable for operational, legal and executive audiences.
  • Maintain awareness of emerging forensic tools, techniques and methodologies.

Stakeholder Engagement

  • Act as a trusted advisor to police forces and policing organisations during cyber incidents.
  • Provide clear technical and strategic briefings to senior stakeholders including Chief Officers, CIOs, Heads of IT, Heads of Cyber Security and other policing partners.
  • Coordinate with internal and external stakeholders to ensure effective incident management and communication throughout the lifecycle of an investigation.
  • Support national coordination activities where incidents have cross-force or sector-wide implications.
  • Utilise threat intelligence, attacker TTPs and industry frameworks such as MITRE ATT&CK to inform investigations and response activity.
  • Identify trends, lessons learned and opportunities to improve cyber resilience across UK policing.
  • Contribute to the development of detection capabilities and response processes through post-incident reviews and technical findings.
  • Support knowledge sharing, mentoring and capability development across the wider NMC function.

What you need to succeed in the role

  • Experience conducting digital forensic investigations within enterprise environments.
  • Experience performing endpoint and memory forensic analysis during cyber security incidents.
  • Experience investigating ransomware, malware, unauthorised access, and data compromise incidents.
  • Ability to collect, preserve and analyse digital evidence whilst maintaining evidential integrity.
  • Strong understanding of Windows internals, operating system artefacts and attacker tradecraft.
  • Experience communicating technical findings and recommendations to senior stakeholders.
  • Strong knowledge of incident response lifecycle and cyber investigation methodologies.
  • Experience analysing logs, EDR telemetry, SIEM data and forensic artefacts to evaluate root cause and impact.

For a full list of responsibilities and criteria, please refer to the Candidate Pack.

Why Join us?

  • Balance is important and we want you to take time off to recharge - we offer 28 days' annual leave plus bank holidays, rising to 30 days after 5 years of service. Holiday Purchase also available
  • We care about your well-being - we have an EAP that offers not just welfare benefits but also retail discounts
  • Plan for the future - we offer an excellent pension scheme and life assurance cover
  • Put your mind at rest regarding your health - offering remote GP, mental health and physiotherapy appointments via video consultation
  • Family - Enhanced maternity and paternity pay along with a flexible return to work
  • Community - one paid day off per year for volunteering

We are committed to equal opportunity for all and will not discriminate on any grounds. We encourage applications from people from the widest possible span of experience. We particularly welcome applications from Black, Asian and Minority Ethnic (BAME) candidates and people with disabilities.

Working Arrangements

At the NMC, you will benefit from hybrid working, getting the advantages of both face-to-face team engagement and home working. NMC employees have the opportunity to work in our modern office environment for in-person collaboration, alongside the opportunity to work from home 2 days a week.

This is a Monday-Friday shift-based role.

All applicants must be eligible for NPPV3 and SC clearances. Successful applicants will require NPPV3 clearance to have been approved before starting with PDS.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

NMC Cyber Detect Analyst
NMC Cyber Detect Analyst

PDS Cyber Services • Wigan

Hybrid
GBP 41,000 - 50,000
28 days annual leave + bank holidays (
EAP with welfare benefits and retail‑s
Pension scheme and life assurance
+2
NMC Cyber Detect Analyst
NMC Cyber Detect Analyst

Police Digital Service • Wigan

Hybrid
GBP 41,000 - 50,000
Annual leave and holiday buy
Pension and life assurance
Remote GP and wellbeing support
+3
NMC Cyber Detect Analyst
NMC Cyber Detect Analyst

National Enabling Programmes (a programme of the Police Digital Service) • Greater Manchester

Hybrid
GBP 41,000 - 50,000
28 days annual leave
EAP and discounts
Pension scheme
+2
NMC Cyber Detect Analyst
NMC Cyber Detect Analyst

Police Digital Service • Lancashire

Hybrid
GBP 45,000 - 52,000
28 days leave
Bank holidays
Pension scheme
+1
NMC Cyber Security Detection Engineer
NMC Cyber Security Detection Engineer

Police Digital Service • Wigan

Hybrid
28 days of annual leave
Flexible working hours
Well-being programs
+4
NMC Senior Cyber Threat Hunter
NMC Senior Cyber Threat Hunter

Women in Data® • Wigan

Hybrid
28 days annual leave plus bank holidays
Flexible working hours
Employee Assistance Program (EAP)
NMC Cyber Security Engineer
NMC Cyber Security Engineer

Women in Data® • Wigan

Hybrid
Senior Digital Forensic Investigator (NEROCU)
Senior Digital Forensic Investigator (NEROCU)

Northumbria Police • Sunderland

On-site
GBP 43,000 - 50,000
26 days' leave (increasing to 30 days)
Public sector pension scheme
Flexi time
+3
Cyber Security Operations Specialist - 2 positions available
Cyber Security Operations Specialist - 2 positions available

Police Digital Service • Greater London

Remote
GBP 60,000 - 69,000
28 days annual leave plus bank holidays
Flexible working hours
Employee Assistance Program
+2
Digital Forensic Unit Technician (NEROCU)
Digital Forensic Unit Technician (NEROCU)

Northumbria • Sunderland

On-site
GBP 29,000 - 30,000
26 days leave
Car lease scheme
Flexible working
+4