Enable job alerts via email!

VP - Digital Forensics & Incident Response (DFIR) Manager

Nicoll Curtin Technology

London

Hybrid

GBP 76,000 - 90,000

Full time

6 days ago
Be an early applicant

Job summary

A leading financial services organization is seeking a VP – Digital Forensics & Incident Response Manager to lead its DFIR team. This hands-on role will focus on enhancing incident response capabilities, coordinating investigations, and driving threat detection maturity. Candidates should possess proven experience in managing DFIR teams and strong knowledge of forensic analysis. The position offers a competitive salary of up to GBP90,000 along with hybrid working arrangements.

Benefits

Hybrid/flexible working arrangements
Opportunity to build and lead a DFIR capability
Supportive culture with work-life balance

Qualifications

  • Proven experience managing DFIR or cyber incident response teams.
  • Strong understanding of incident response and forensic analysis.
  • Experience working in financial services or a regulated environment.

Responsibilities

  • Lead the DFIR function and oversee incident response activities.
  • Develop and implement incident response methodologies.
  • Conduct forensic investigations across systems and networks.
  • Coordinate cross-functional security incident responses.

Skills

Managing DFIR or cyber incident response teams
Technical knowledge of IR and forensic analysis
Understanding of security monitoring frameworks
Hands-on experience with SIEM tools
Knowledge of CIS benchmarks and cloud security

Tools

Wireshark
SIEM
VMware

Job description

Role: VP – Digital Forensics & Incident Response (DFIR) Manager

Location: London (Hybrid working available)

Salary: Up to GBP90,000 + benefits

Sector: Cyber Security/Financial Services

Overview

A leading financial services organisation is seeking a VP–level DFIR Manager to lead its Digital Forensics and Incident Response (DFIR) team. This is a hands–on leadership role focused on incident response, threat detection, and forensics within a complex, regulated environment.

You'll be responsible for advancing the organisation's incident response capabilities, leading investigations, and driving threat detection maturity through development of use cases, threat intelligence, and vulnerability management.

Key Responsibilities

  • Lead the DFIR function, overseeing incident detection, investigation, and response activities.
  • Develop and implement IR methodologies (MITRE ATT&CK, Kill Chain, Threat Modelling, Diamond Model).
  • Conduct forensic investigations on systems, networks, and endpoints.
  • Refine threat hunting and threat intelligence capabilities.
  • Support and mature security monitoring use cases (SIEM, packet inspection, IOCs).
  • Coordinate cross–functional security incident response with SOC, Threat Intelligence, and Red/Blue teams.
  • Engage with technical and business teams on cyber risk reduction strategies.
  • Contribute to vulnerability management and remediation plans.

Required Skills & Experience

  • Proven experience managing DFIR or cyber incident response teams.
  • Deep technical knowledge of IR and forensic analysis (eg Wireshark, packet capture, host–based artifacts).
  • Strong understanding of security monitoring frameworks (MITRE ATT&CK, NIST, etc.).
  • Experience working in financial services or a regulated environment preferred.
  • Hands–on experience with SIEM tools, network forensics, and endpoint detection.
  • Knowledge of CIS benchmarks, cloud security, IAM, DLP, and vulnerability management.
  • Familiarity with Windows, Linux/Unix, networking, and virtualisation (VMware).

Certifications (preferred):

GCIA, GCIH, GCFA or equivalent.

What's on Offer

  • Up to GBP90,000 base salary
  • Hybrid/flexible working arrangements
  • Opportunity to build and lead a growing DFIR capability in a major enterprise setting
  • Supportive, inclusive culture with emphasis on work–life balance
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.