Enable job alerts via email!

Senior Incident Responder (DFIR)

Tesco UK

Welwyn Garden City

Hybrid

GBP 50,000 - 70,000

Full time

3 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

Tesco is seeking a Senior Incident Responder for their DFIR team to lead investigations into security incidents. The role involves leveraging technical skills to enhance incident response processes and collaborate across diverse teams while promoting an inclusive culture.

Qualifications

  • 4+ years of relevant experience.
  • Experience with Windows, MacOS, and Unix forensic analysis.
  • Knowledge of security technologies essential.

Responsibilities

  • Conduct forensic analysis to understand security incidents.
  • Support incident managers with root cause analysis.
  • Lead threat hunts and contribute to detection engineering.

Skills

Critical Thinking
Leadership
Forensics Analysis
Scripting (Python, PowerShell)

Tools

EDR
SOAR
SIEM

Job description

Our Digital Forensics and Incident Response (DFIR) team leads the technical investigation and response to security incidents at Tesco. As part of this team, you’ll work alongside our security operations, threat intelligence, and security engineering teams to protect, detect, and respond to security threats across Tesco’s diverse and evolving estate.

You’ll apply your deep technical knowledge and critical thinking ability to investigate and understand the full extent of security incidents and threats. Your ability to distil and clearly convey technical information will allow you to provide key contextual information to decision makers, enabling informed decisions.

As a senior team member, when not investigating security incidents, you’ll leverage your knowledge and experience to improve and automate the team’s workflows, collaborating with other teams to drive innovation in prevention, automation, detection, and response capabilities. Your role as a senior incident responder also involves serving as a role model for engineers and analysts across Security Operations.

Responsibilities include:
  1. Investigation and Response: Conduct host, network, and cloud forensic analysis to understand security incidents and take appropriate actions to contain, remediate, and recover.
  2. Incident Handling: Support incident managers and decision makers with root cause analysis and recommendations for detection and prevention controls.
  3. Technical Projects: Enhance existing processes and develop new methods to deliver DFIR services aligned with evolving technology needs.
  4. Threat Hunting & Detection Engineering: Lead threat hunts to identify anomalous behaviors and contribute to detection engineering programs.
Minimum Requirements:
  • 4+ years of relevant experience.
  • Experience responding to security incidents in large-scale on-premises and cloud environments (preferably Microsoft Azure).
  • Experience with forensic analysis on Windows, MacOS, and Unix systems.
  • Knowledge of security technologies such as EDR, SOAR, and SIEM.
  • Proficiency in at least one scripting language like Python or PowerShell.
  • Strong critical thinking and leadership in investigations.
  • Ability to handle high-pressure situations professionally.
  • Experience with static and dynamic malware analysis is desirable.

Our vision at Tesco is to become every customer's favourite way to shop, whether at home or on the move. Our core purpose is to serve our customers, communities, and planet better every day, acting responsibly and sustainably.

We foster an inclusive culture where everyone can be themselves, celebrating diversity and ensuring equal opportunities. We are proud to be a Disability Confident Leader and committed to accessible recruitment. For support details, please click here.

We offer flexible full-time and part-time roles across various business areas, combining office and remote work. Our offices are spaces for connection, collaboration, and innovation. Internal applicants should discuss flexible arrangements with their Hiring Manager. Everyone is welcome at Tesco.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Digital Forensic & Incident Response Analyst - Remote - Circa 60,000

LT Harper - Cyber Security Recruitment

Greater London

Remote

GBP 50,000 - 75,000

7 days ago
Be an early applicant

Senior Incident Responder (DFIR)

Tesco Technology

Welwyn Garden City

On-site

GBP 60,000 - 90,000

3 days ago
Be an early applicant

Senior Incident Responder (DFIR)

Tesco

Welwyn Garden City

On-site

GBP 50,000 - 75,000

10 days ago

Cyber Security Incident Responder

JR United Kingdom

Colchester

On-site

GBP 45,000 - 70,000

12 days ago

Cyber Security Incident Responder

JR United Kingdom

Reading

Hybrid

GBP 50,000 - 75,000

13 days ago

Cyber Security Incident Responder

JR United Kingdom

Bedford

On-site

GBP 55,000 - 75,000

13 days ago

Cyber Security Incident Responder

JR United Kingdom

High Wycombe

On-site

GBP 45,000 - 70,000

13 days ago

Cyber Security Incident Responder

JR United Kingdom

Hemel Hempstead

On-site

GBP 50,000 - 70,000

13 days ago

Cyber Security Incident Responder

JR United Kingdom

Oxford

On-site

GBP 45,000 - 70,000

13 days ago