Digital Forensics and Incident Response

3 days ago


City Of London, United Kingdom Ransomware Recovery Full time

CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware events. Our team collaborates with prominent global insurance carriers, leading law firms, and Fortune 1000 businesses. Responsibilities Engage on behalf of CYPFER in incident response tasks, interacting with various insurance partners, legal counsel, incident response units, client executives, and technical teams. Utilize standard tools and methodologies to collect forensic artifacts and images from affected systems. Assist with Windows forensics and triage to assess compromise and investigations. Familiarity with malware analysis tools and methodologies. Apply mitigation strategies and concepts to remediate identified threats. Analyze triage collections/artifacts for indicators of compromise (IOCs) and potentially malicious activity. Review logs from host systems and appliances to identify suspicious activities. Collect forensic disk and memory images from physical and virtual endpoints and servers. Understanding of an incident lifecycle and cyber-kill-chain. Correlate events and build timelines of events. Maintain current knowledge on emerging threats and vulnerabilities. Analyze files for IOCs using various techniques. Technical Requirements 2+ years of experience in digital forensics, incident response, or a similar role. Knowledge of Windows and Unix/Linux operating systems. Understanding of the functionality of EDR / EPP technologies. Familiarity with forensic acquisition and analysis of physical and virtual systems. Working knowledge of storage technologies such as RAID, NAS, SAN, Fiber Channel, iSCSI, and NFS. Ability to analyze and interpret logs from various sources. Ability to perform threat research and analyze current threats. Understanding of business email compromise (BEC) cases and investigation techniques. Participate in a rotating on-call schedule; ability to work on weekends and outside normal business hours as needed. This role is remote but requires the ability to travel on short notice to a client site up to 50%. Must maintain flexibility to travel frequently within 24-48 hours' notice for deployments typically 1-2 weeks in duration. Business Responsibilities Maintain current knowledge of information security, incident response techniques, emerging threats, and tools. Work independently and produce high-quality deliverables with minimal supervision. Exhibit strong customer service and consulting skills. Adhere to client and internal policies, procedures, and security practices. Maintain detailed notes and draft updates and reports as required. Remain calm, composed, and articulate in tough customer situations. Exhibit excellent relationship management and communication skills. Preferred Skills Understand obfuscation techniques used to conceal malicious commands and traffic, and lateral movement strategies employed by threat actors. Familiarity with exfiltration techniques used by threat actors. Knowledge of SIEM and SOAR solutions. Experience with e-discovery tools and methodologies. Proficiency in collecting and analyzing data from mobile devices/cell phones. Industry certifications such as MCFE, ENCE, ACE, GCFA, GCIH, GNFA, GCFE or similar are a plus. Compensation package includes a base salary, medical benefits and multiple bonus opportunities. CYPFER is an equal opportunity employer. If you need accommodation during the interview process or beyond, we welcome applicants from all backgrounds and perspectives. We thank you for your interest in joining the CYPFER team; while we welcome all applicants, only those selected for an interview will be contacted. #J-18808-Ljbffr



  • City Of London, United Kingdom Control Risks Full time

    OverviewWe now have an exciting opportunity for an Associate Director to join our Digital Forensics and Incident Response (DFIR) team in London. As the senior member of the EMEA DFIR team with deep digital forensic experience, you will be integral to the wider EMEA practice, and in turn part of a global practice offering and influencing the direction of our...


  • London Area, United Kingdom GIOS Technology Full time £60,000 - £90,000 per year

    We are looking forDigital Forensics and Incident Response (DFIR) Consultantfor our client's project based atLondon, UK - HybridCore Responsibilities:Engage on behalf of OUR CLIENT in incident response tasks, interacting with various insurance partners, legal counsel, incident response units, client executives, and technical teams.Utilize standard tools and...


  • London, London, City of, ECA EP, United Kingdom Cypfer Full time £60,000 - £100,000 per year

    CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware...


  • City Of London, United Kingdom Ransomware Recovery Full time

    CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware...


  • London, Greater London, United Kingdom NTT DATA Full time £80,000 - £120,000 per year

    We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.Our...


  • City Of London, United Kingdom The Security Event Full time

    A leading cybersecurity company is seeking an Incident Response Specialist to join their global team. The role involves leading investigations into cyber-attacks, conducting forensic analysis across various operating systems, and mentoring team members. The ideal candidate has solid experience with forensic tools and a strong understanding of the threat...


  • Greater London, United Kingdom Control Risks Full time

    Associate Director, Digital Forensics and Incident Response London, England, United Kingdom We now have an exciting opportunity for an Associate Director to join our Digital Forensics and Incident Response (DFIR) team in London. As the senior member of the EMEA DFIR team with deep digital forensic experience, you will be integral to the wider EMEA practice,...


  • London, Greater London, United Kingdom Control Risks Full time £90,000 - £120,000 per year

    We now have an exciting opportunity for an Associate Director to join our Digital Forensics and Incident Response (DFIR) team in London. As the senior member of the EMEA DFIR team with deep digital forensic experience, you will be integral to the wider EMEA practice, and in turn part of a global practice offering and influencing the direction of our forensic...


  • Greater London, United Kingdom BAE Systems (New) Full time

    A leading defense and security company in the UK is looking for an Incident Response Specialist to join their team. The role involves conducting forensic analysis of digital incidents, responding to cyber threats, and writing concise reports. Ideal candidates will have experience with forensic tools and a good understanding of the threat landscape. This...

  • Senior DFIR Lead

    2 weeks ago


    Greater London, United Kingdom Control Risks Full time

    A global consulting firm is seeking an Associate Director for their Digital Forensics and Incident Response team in London. This role involves leading cyber incident investigations, managing high-stress engagements, and developing business strategies. Preferred candidates will have extensive experience in digital forensics and incident response, combined...