Senior Digital Forensics and Incident Response Consultant

2 weeks ago


King William Street London ECN United Kingdom Ntt Data Full time £70,000 - £108,000 per year
The team you';ll be working with:

This position is Hybrid flexible working options.

Please note, you will need to be eligible for SC clearance

NTT DATA is one of the world';s largest global security service providers, partnering with some of the most recognized security technology brands. We';re looking for passionate, curious, and motivated individuals to join our team.

Using your advanced expertise in digital forensics, incident response, and cyber threat investigation, you will lead complex DFIR engagements, conduct advanced forensic analysis across diverse platforms, and provide authoritative guidance during major security incidents. You will work independently on sophisticated investigations, coordinate multi-disciplinary incident response activities, and deliver expert testimony and forensic reporting while mentoring junior investigators and analysts.

What you';ll be doing:

Lead complex digital forensic investigations and major incident response engagements. Conduct advanced forensic analysis, coordinate multi-disciplinary IR activities, provide expert testimony, and mentor junior investigators. 

KEY RESPONSIBILITIES 

  • Forensic Investigations & Incident Response 
  • Lead complex forensic investigations across Windows, Linux, macOS, mobile, and cloud platforms 
  • Conduct advanced disk, memory, network, and malware forensic analysis 
  • Lead major IR engagements for sophisticated cyber-attacks and data breaches 
  • Coordinate multi-team IR activities across technical, legal, and business stakeholders 
  • Perform threat hunting, containment, eradication, and recovery activities 
  • Reconstruct attack chains, lateral movement, and APT activities Malware Analysis & Cloud Forensics 
  • Conduct static/dynamic malware analysis and reverse engineering 
  • Lead forensic investigations in AWS, Azure, and GCP environments 
  • Analyze cloud logs, API calls, and container/Kubernetes incidents 
  • Develop IOCs and detection signatures 
  • Expert Witness & Legal Support 
  • Provide expert witness testimony in legal proceedings 
  • Prepare forensic reports meeting legal and evidentiary standards 
  • Work with legal teams on e-discovery and regulatory response 
  • Maintain chain of custody and forensic integrity 
  • Threat Intelligence 
  • Analyze threat actor TTPs using MITRE ATT&CK framework 
  • Conduct threat attribution analysis and identify APT campaigns 
What experience you';ll bring:

Experience: 6+ years in digital forensics/incident response | 3+ years leading complex investigations and major IR engagements | APT or nation-state incident experience 

Technical Expertise 

  • Forensics: EnCase, FTK, X-Ways, Autopsy, Volatility, Wireshark 
  • Malware: IDA Pro, Ghidra, Cuckoo Sandbox, REMnux 
  • Mobile: Cellebrite, Magnet AXIOM 
  • EDR: CrowdStrike, Carbon Black, Microsoft Defender, SentinelOne 
  • SIEM: Splunk, ELK Stack, Azure Sentinel 
  • IR Tools: Velociraptor, KAPE, GRR Rapid Response 
  • Cloud: AWS CloudTrail, Azure Monitor, GCP Cloud Logging 
  • Deep Knowledge: Windows internals, file systems (NTFS, ext4, APFS), malware techniques, cloud forensics 

Mandatory Certification: GCFA or GCFE 
Preferred: GREM, CHFI, GCIH, ECIH, or EnCE 

KEY COMPETENCIES 

Senior-level communication with executives, legal teams, and regulators | Crisis management during high-pressure incidents | Independent problem-solving | Mentoring junior analysts 

Who we are:

We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.

Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women's Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network.

For more information on Diversity, Equity and Inclusion please click here: Creating Inclusion Together at NTT DATA UK | NTT DATA

what we';ll offer you:

We offer a range of tailored benefits that support your physical, emotional, and financial wellbeing. Our Learning and Development team ensure that there are continuous growth and development opportunities for our people. We also offer the opportunity to have flexible work options.

You can find more information about NTT DATA UK & Ireland here: 

We are an equal opportunities employer. We believe in the fair treatment of all our employees and commit to promoting equity and diversity in our employment practices. We are also a proud Disability Confident Committed Employer - we are committed to creating a diverse and inclusive workforce. We actively collaborate with individuals who have disabilities and long-term health conditions which have an effect on their ability to do normal daily activities, ensuring that barriers are eliminated when it comes to employment opportunities. In line with our commitment, we guarantee an interview to applicants who declare to us, during the application process, that they have a disability and meet the minimum requirements for the role. If you require any reasonable adjustments during the recruitment process, please let us know. Join us in building a truly diverse and empowered team.

Back to search Email to a friend



  • London, Greater London, United Kingdom NTT DATA Full time £80,000 - £120,000 per year

    We're a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.Our...


  • Greater London, United Kingdom Control Risks Full time

    Associate Director, Digital Forensics and Incident Response London, England, United Kingdom We now have an exciting opportunity for an Associate Director to join our Digital Forensics and Incident Response (DFIR) team in London. As the senior member of the EMEA DFIR team with deep digital forensic experience, you will be integral to the wider EMEA practice,...


  • London, London, City of, ECA EP, United Kingdom Cypfer Full time £60,000 - £100,000 per year

    CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware...


  • City Of London, United Kingdom Ransomware Recovery Full time

    CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware...


  • London, Greater London, United Kingdom Control Risks Full time £90,000 - £120,000 per year

    We now have an exciting opportunity for an Associate Director to join our Digital Forensics and Incident Response (DFIR) team in London. As the senior member of the EMEA DFIR team with deep digital forensic experience, you will be integral to the wider EMEA practice, and in turn part of a global practice offering and influencing the direction of our forensic...


  • City Of London, United Kingdom Control Risks Full time

    OverviewWe now have an exciting opportunity for an Associate Director to join our Digital Forensics and Incident Response (DFIR) team in London. As the senior member of the EMEA DFIR team with deep digital forensic experience, you will be integral to the wider EMEA practice, and in turn part of a global practice offering and influencing the direction of our...

  • Senior DFIR Lead

    2 weeks ago


    Greater London, United Kingdom Control Risks Full time

    A global consulting firm is seeking an Associate Director for their Digital Forensics and Incident Response team in London. This role involves leading cyber incident investigations, managing high-stress engagements, and developing business strategies. Preferred candidates will have extensive experience in digital forensics and incident response, combined...


  • City Of London, United Kingdom Ransomware Recovery Full time

    CYPFER is a leading first-responder cybersecurity organization enabling clients to swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware...


  • London, United Kingdom Palo Alto Networks Full time £150 - £200

    A leading cybersecurity company is seeking a Principal Consultant to oversee incident response engagements.To be considered for an interview, please make sure your application is full in line with the job specs as found below.The role involves direct client interactions, managing forensic investigations, and mentoring team members.Candidates should have...


  • Greater London, United Kingdom BAE Systems (New) Full time

    A leading defense and security company in the UK is looking for an Incident Response Specialist to join their team. The role involves conducting forensic analysis of digital incidents, responding to cyber threats, and writing concise reports. Ideal candidates will have experience with forensic tools and a good understanding of the threat landscape. This...