Senior Digital Forensics and Incident Response Consultant
2 weeks ago
This position is Hybrid flexible working options.
Please note, you will need to be eligible for SC clearance
NTT DATA is one of the world';s largest global security service providers, partnering with some of the most recognized security technology brands. We';re looking for passionate, curious, and motivated individuals to join our team.
Using your advanced expertise in digital forensics, incident response, and cyber threat investigation, you will lead complex DFIR engagements, conduct advanced forensic analysis across diverse platforms, and provide authoritative guidance during major security incidents. You will work independently on sophisticated investigations, coordinate multi-disciplinary incident response activities, and deliver expert testimony and forensic reporting while mentoring junior investigators and analysts.
What you';ll be doing:Lead complex digital forensic investigations and major incident response engagements. Conduct advanced forensic analysis, coordinate multi-disciplinary IR activities, provide expert testimony, and mentor junior investigators.
KEY RESPONSIBILITIES
- Forensic Investigations & Incident Response
- Lead complex forensic investigations across Windows, Linux, macOS, mobile, and cloud platforms
- Conduct advanced disk, memory, network, and malware forensic analysis
- Lead major IR engagements for sophisticated cyber-attacks and data breaches
- Coordinate multi-team IR activities across technical, legal, and business stakeholders
- Perform threat hunting, containment, eradication, and recovery activities
- Reconstruct attack chains, lateral movement, and APT activities Malware Analysis & Cloud Forensics
- Conduct static/dynamic malware analysis and reverse engineering
- Lead forensic investigations in AWS, Azure, and GCP environments
- Analyze cloud logs, API calls, and container/Kubernetes incidents
- Develop IOCs and detection signatures
- Expert Witness & Legal Support
- Provide expert witness testimony in legal proceedings
- Prepare forensic reports meeting legal and evidentiary standards
- Work with legal teams on e-discovery and regulatory response
- Maintain chain of custody and forensic integrity
- Threat Intelligence
- Analyze threat actor TTPs using MITRE ATT&CK framework
- Conduct threat attribution analysis and identify APT campaigns
Experience: 6+ years in digital forensics/incident response | 3+ years leading complex investigations and major IR engagements | APT or nation-state incident experience
Technical Expertise
- Forensics: EnCase, FTK, X-Ways, Autopsy, Volatility, Wireshark
- Malware: IDA Pro, Ghidra, Cuckoo Sandbox, REMnux
- Mobile: Cellebrite, Magnet AXIOM
- EDR: CrowdStrike, Carbon Black, Microsoft Defender, SentinelOne
- SIEM: Splunk, ELK Stack, Azure Sentinel
- IR Tools: Velociraptor, KAPE, GRR Rapid Response
- Cloud: AWS CloudTrail, Azure Monitor, GCP Cloud Logging
- Deep Knowledge: Windows internals, file systems (NTFS, ext4, APFS), malware techniques, cloud forensics
Mandatory Certification: GCFA or GCFE
Preferred: GREM, CHFI, GCIH, ECIH, or EnCE
KEY COMPETENCIES
Senior-level communication with executives, legal teams, and regulators | Crisis management during high-pressure incidents | Independent problem-solving | Mentoring junior analysts
Who we are:We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.
Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women's Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network.
For more information on Diversity, Equity and Inclusion please click here: Creating Inclusion Together at NTT DATA UK | NTT DATA
what we';ll offer you:We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.
You can find more information about NTT DATA UK & Ireland here:
We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a proud Disability Confident Committed Employer - we are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.
Back to search Email to a friend
-
London, Greater London, United Kingdom NTT DATA Full time £80,000 - £120,000 per yearWe're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.Our...
-
Greater London, United Kingdom Control Risks Full timeAssociate Director, Digital Forensics and Incident Response London, England, United Kingdom We now have an exciting opportunity for an Associate Director to join our Digital Forensics and Incident Response (DFIR) team in London. As the senior member of the EMEA DFIR team with deep digital forensic experience, you will be integral to the wider EMEA practice,...
-
London, London, City of, ECA EP, United Kingdom Cypfer Full time £60,000 - £100,000 per yearCYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware...
-
City Of London, United Kingdom Ransomware Recovery Full timeCYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware...
-
London, Greater London, United Kingdom Control Risks Full time £90,000 - £120,000 per yearWe now have an exciting opportunity for an Associate Director to join our Digital Forensics and Incident Response (DFIR) team in London. As the senior member of the EMEA DFIR team with deep digital forensic experience, you will be integral to the wider EMEA practice, and in turn part of a global practice offering and influencing the direction of our forensic...
-
City Of London, United Kingdom Control Risks Full timeOverviewWe now have an exciting opportunity for an Associate Director to join our Digital Forensics and Incident Response (DFIR) team in London. As the senior member of the EMEA DFIR team with deep digital forensic experience, you will be integral to the wider EMEA practice, and in turn part of a global practice offering and influencing the direction of our...
-
Senior DFIR Lead
2 weeks ago
Greater London, United Kingdom Control Risks Full timeA global consulting firm is seeking an Associate Director for their Digital Forensics and Incident Response team in London. This role involves leading cyber incident investigations, managing high-stress engagements, and developing business strategies. Preferred candidates will have extensive experience in digital forensics and incident response, combined...
-
Digital Forensics and Incident Response
5 days ago
City Of London, United Kingdom Ransomware Recovery Full timeCYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware...
-
Senior DFIR Incident Response Consultant
2 days ago
London, United Kingdom Palo Alto Networks Full time £150 - £200A leading cybersecurity company is seeking a Principal Consultant to oversee incident response engagements.To be considered for an interview, please make sure your application is full in line with the job specs as found below.The role involves direct client interactions, managing forensic investigations, and mentoring team members.Candidates should have...
-
Hybrid Incident Response
2 weeks ago
Greater London, United Kingdom BAE Systems (New) Full timeA leading defense and security company in the UK is looking for an Incident Response Specialist to join their team. The role involves conducting forensic analysis of digital incidents, responding to cyber threats, and writing concise reports. Ideal candidates will have experience with forensic tools and a good understanding of the threat landscape. This...