An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Forensic Focus Limited is seeking an experienced incident responder to lead end-to-end cybersecurity incident response activities, from triage to recovery, across endpoints, networks, cloud and applications. You will analyse logs, perform digital forensics, communicate with stakeholders, and contribute to SOAR automation and playbook development, guiding decision-makers under pressure.
This is a leadership role within a formal CIRT structure, requiring clear translation of complex findings into
This position leads end-to-end cybersecurity incident response activities, covering triage, investigation, containment, eradication, and recovery. Day-to-day work includes analysing logs across endpoints, networks, cloud, and applications, performing digital forensics across multiple device types, communicating with stakeholders, and contributing to SOAR automation and playbook development.
Candidates require strong log analysis skills spanning EDR telemetry, network traffic, cloud audit trails, and application logs, alongside hands‑on digital forensics experience covering endpoints, servers, mobile devices, and cloud environments. Critical thinking, clear communication of technical concepts, and familiarity with SOAR platforms are essential to this role.
This role suits an experienced incident responder ready to take a leadership position within a formal CIRT structure. Someone who is comfortable guiding decision‑makers under pressure, conducting thorough root cause analysis, and translating complex technical findings into actionable recommendations for both technical and non-technical stakeholders will thrive here.