Digital Forensic Investigator

The Role This position sits within a Scientific Support Unit and centres on the forensic examination, recovery and analysis of digital evidence from a variety of devices. Day to day, the investigator conducts intelligence-led examinations, produces evidential reports, and advises

Lead Cyber Incident Response Consultant

The Role This position leads complex cyber security incident investigations end to end, performing advanced digital forensics across Windows, Linux, macOS, and multi-cloud environments. Day to day involves analysing logs, network traffic, memory, and disk artefacts, maintaining chain-of-custody, and delivering

Cyber Response & Recovery Manager (Reactive DFIR) – German Speaking

The Role This hands-on position sits within a cyber advisory practice, focusing on reactive digital forensics and incident response. Day to day, the role involves managing medium to large incident response cases, supporting clients in building internal IR capabilities, contributing

Incident Responder

Scope and contain live security incidents, reconstruct intrusions using host and network forensics, preserve evidence, and produce clear written timelines for clients and regulators in a fast-paced IR consultancy environment.

Frontline Digital Forensic Technician (FTC/Secondment)

The Role This position involves conducting frontline triage of digital exhibits to determine the appropriate investigative pathway for each case. The work requires early examination of devices and materials, some of which may be distressing in nature, while maintaining accurate

Cyber Security Incident Response Analyst

The Role The analyst conducts forensic investigations into cyber security incidents reported to the CSIRT, triaging and examining digital media across heterogeneous environments. Daily work involves identifying threats, determining containment and remediation actions, analysing network traffic, reviewing log data, and

Cyber Incident Responder

The Role This position involves responding to and investigating a range of cyber incidents on behalf of clients across multiple sectors, including legal, insurance and law enforcement. The successful candidate manages investigations end to end, applying technical expertise in incident

Senior DFIR Investigator

The Role This position involves leading complex digital forensic and incident response investigations across host, network and cloud environments. Day to day, the role includes analysing threat actor behaviour, producing forensic reports and timelines, guiding clients through incidents, and delivering

Director, Digital Forensics & Incident Response (Global)

The Role This senior leadership position oversees a globally distributed forensics and incident response function, setting strategic direction and ensuring consistent, high-quality delivery across cyber preparedness, active incident management, forensic investigations, and post-incident recovery, while also driving commercial growth by

Senior Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves leading complex incident response engagements and conducting forensic investigations across Windows, Unix, and Linux environments. Day-to-day work includes collecting forensic artifacts, analysing logs and memory images, identifying indicators of compromise, building event timelines, and supporting

Cyber Response & Recovery Manager – German Speaker

The Role This is a hands-on reactive digital forensics and incident response (DFIR) position, where the successful candidate manages medium to large cases as a case manager. Between incidents, the role involves supporting client IR capability building, runbook development, tabletop

Senior Digital Forensics and Incident Response Analyst

The Role This position sits within a Security Operations Centre, focusing on leading investigations into complex cyber security incidents. Day to day, the analyst collects and examines forensic evidence, responds to threats such as malware, phishing and endpoint compromise, and

Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves hands-on incident response work, including collecting forensic artifacts, analysing disk and memory images, reviewing host and appliance logs, and building event timelines. The consultant engages with insurance partners, legal counsel, and client technical teams to

Digital Forensics Practitioner

The Role This position sits within a specialist forensic unit that supports fraud investigations nationally. Day-to-day work encompasses assisting with warrant executions, preserving digital evidence, and conducting forensic analysis. The role operates under flexible working patterns, including weekend and out-of-hours

Digital Forensics Laboratory Team Leader

The Role This position combines hands-on digital forensic examination work with day-to-day leadership of a laboratory team. The role involves assigning casework, monitoring analyst output for quality, managing workloads to meet deadlines, liaising with the case team, and maintaining ISO

Senior Incident Response Security Consultant, Mandiant, Google Cloud

The Role This senior-level position involves leading end-to-end incident response engagements for clients facing complex, high-profile security incidents. Day to day, consultants perform forensic analysis across network, disk, memory, and cloud environments, conduct threat hunting, triage malware, and support containment,

Digital Forensic Unit Investigator

The Role This position involves extracting and analysing data from electronic devices using forensically sound methods, processing recovered evidence in line with national guidelines, advising investigating officers on digital matters, and supporting victim identification efforts across a wide range of

Digital Forensics and Incident Response Analyst

The Role This position sits within a specialist cyber risk and investigations team, where the analyst serves as a first responder to client-reported cyber incidents. Day-to-day work covers threat investigation, containment, and eradication, alongside supporting internal security operations and contributing

Digital Media Examiner – Counter Terrorism Policing

The Role This position involves the forensic acquisition, examination, and analysis of digital devices to support counter terrorism investigations at regional, national, and international levels. Examiners produce evidence packages, witness statements, and appear in court, while also contributing to quality

Digital Media Examiner – Technician – NDES S3 – Police Staff – CTP London

The Role This position involves conducting forensic examinations of digital devices, including mobile phones, computers, and storage media, within a counter terrorism context. Day-to-day work includes data extraction, peer reviewing examinations, supporting non-technical colleagues, and occasionally attending court as a

Incident Response Lead, DFIR

The Role This founding position leads complex cloud and enterprise incident response investigations, setting best practices and standards for an AI-native DFIR function. The role involves close collaboration with AI engineers who automate routine forensic tasks, allowing the lead to

Digital Forensics Laboratory Team Leader

The Role This position leads a team of digital forensics analysts within a laboratory environment, overseeing daily caseload assignment, quality sampling, and project delivery. The team leader conducts forensic examinations, liaises with case management teams, maintains ISO compliance, and acts

Principal Consultant, Incident Response (Weekend Schedule)

The Role This position involves leading client-facing incident response engagements on a Friday-to-Monday schedule, working ten hours per day. Responsibilities include scoping work, managing forensic investigations end to end, advising clients on immediate containment measures, and providing long-term remediation guidance

Digital Multimedia Evidence Unit Manager

The Role This position leads a specialist unit responsible for the forensic handling of digital multimedia evidence, including CCTV, audio and video material. Day-to-day responsibilities span managing team workloads, overseeing evidential processes, advising operational colleagues and partner agencies, attending court

Senior Incident Response Security Consultant, Mandiant, Google Cloud

The Role This senior consulting position centres on leading end-to-end incident response engagements for clients facing complex, high-profile cyber incidents. Day-to-day responsibilities include forensic analysis across disk, memory, network, and cloud environments, threat hunting, malware triage, containment, remediation, and crisis

Cyber Response & Recovery Assistant Manager (Reactive DFIR)

The Role This hands-on position sits within a specialist cyber response team, focusing on reactive digital forensics and incident response. Day to day, the role involves acting as a junior case manager on smaller engagements or supporting senior colleagues on

Senior DFIR Analyst

The Role Working within a Security Operations Centre, this position centres on leading investigations into complex cyber security incidents, from phishing and malware through to endpoint compromise. The analyst collects and examines forensic evidence, coordinates incident containment and remediation, and

Principal Consultant, Incident Response (Weekend Schedule)

The Role This position centres on leading end-to-end incident response engagements for a range of clients, covering initial scoping, forensic investigation, containment, and long-term remediation guidance. It operates on a Friday-to-Monday schedule, ten hours per day, with Tuesday through Thursday

Senior DFIR Investigator

The Role This position sits within a global security services team, leading end-to-end forensic investigations across host, network and cloud environments. Day to day, the role involves analysing threat actor activity, producing detailed forensic reports and timelines, guiding clients through

Principal Consultant, Incident Response (Unit 42)

The Role This position leads end-to-end incident response engagements for clients, managing scope, guiding forensic investigations, and overseeing containment and remediation. Day to day involves hands-on host-based analysis across Windows, Linux, and macOS environments, as well as reviewing firewall, web,

Data Forensic Investigator

The Role This position involves identifying, preserving, extracting, interpreting and presenting digital evidence from a range of devices in support of criminal investigations. Work is carried out at the request of investigating officers, with a strong focus on maintaining forensic

Digital Forensics Practitioner

The Role This position involves supporting fraud investigation teams by acquiring and examining digital evidence from computers, storage devices, mobile phones, and CCTV systems. Practitioners work within specialist forensic laboratories, presenting clear and accurate findings to assist complex, large-scale criminal

Cyber Incident Response

The Role Three positions are available within a UK Tier 1 cyber response practice: one focused on digital forensics and incident response across disk, memory, network and log sources; one advising clients on security operations, threat intelligence and AI-enabled defence;

Cyber Security Analyst

The Role This position leads complex cyber security incident investigations across diverse technology environments, performing advanced digital forensics on Windows, Linux, macOS and multi-cloud platforms. Day-to-day responsibilities include analysing logs, network traffic and memory artefacts, establishing attacker timelines, preserving evidence

Digital Forensics Specialist

The Role This position sits within a Cyber Incident Response Team, supporting active cyber incidents through hands-on forensic analysis across Windows, Linux and macOS endpoints, cloud platforms and identity services. Day-to-day work includes determining root cause, analysing attacker behaviour, producing

Data Forensic Technician

The Role Working within a regional forensics collaboration, the technician extracts and analyses data from computers and digital media devices to support criminal investigations. Day-to-day duties include forensic imaging, triage examination, producing evidential statements, liaising with police officers, and occasionally

Cyber Response and Recovery – Assistant Manager (Reactive)

The Role This hands-on position sits within a reactive digital forensics and incident response (DFIR) team, handling live cyber incidents as a junior case manager on smaller engagements or as a team contributor on larger ones. Outside of active incidents,

Digital Forensic Unit Technician

The Role The position involves extracting and analysing data from electronic devices to support criminal investigations, using forensically sound techniques in line with national guidelines. Day-to-day responsibilities include processing digital exhibits, maintaining laboratory equipment, providing technical advice, and upholding compliance

Digital Forensics Investigator – Birmingham City Centre

The Role This position involves conducting forensic examinations and acquisitions of digital evidence from a broad range of devices, including mobile phones, computers, SIM cards, and memory cards. Investigators recover, analyse, and report on evidence in line with case strategies,

Forensics Consultant

The Role This position involves guiding clients through all stages of digital forensic investigations, from data collection and processing through to analysis. The consultant manages forensic projects end-to-end across PCs, servers, mobile devices and cloud environments, while advising both clients

Cyber Response & Recovery – Senior Manager

The Role This senior position sits within a cyber response and risk consulting practice, leading teams through active security incidents while conducting digital forensics across disk, memory, network, and log sources. Beyond incident work, the role involves helping clients mature

Data Forensic Investigator – ICAT

The Role This position sits within a digital forensics unit, where investigators examine computers and mobile devices to recover evidence across a range of criminal cases. Day-to-day work includes managing technical investigations, attending search warrants, interviewing suspects, supporting major incident

Digital Forensics & Cyber Incident Responder – Hybrid – London

The Role This position sits within a specialist team that handles real-world cyber security incidents, including ransomware attacks and significant breaches. Day to day, practitioners investigate live incidents, examine forensic evidence, map attacker behaviour, and guide affected organisations through their

Assistant Digital Investigator

The Role This position involves conducting forensic examinations of mobile devices, computers, SIM cards, and memory cards, recovering extant, deleted, and encrypted data using established methodologies. Work is carried out in line with ISO/IEC 17025 and the Forensic Science Regulator’s

Digital Forensics Examiner – NDES S3 – Police Staff – CTP London

The Role This position involves conducting forensic examinations of digital devices in support of counter-terrorism investigations. Day-to-day work includes imaging devices, recovering deleted or encrypted data, analysing device activity, and producing clear technical reports and witness statements for use as

DFIR Investigator

The Role This position sits within a global security services team and involves leading end-to-end digital forensics and incident response investigations across host, network and cloud environments. Day to day, investigators analyse threat actor behaviour, produce forensic reports and timelines,

Senior Digital Forensic Analyst

The Role This office-based position within an established forensic laboratory involves conducting mobile and computer examinations for law enforcement, government, and legal clients. Analysts manage their own caseload, produce court-admissible reports, conduct defence work, peer review junior colleagues’ output, and

Information Security Incident Response Analyst

The Role The analyst investigates security incidents end to end, conducting host, memory, network, and cloud forensic analysis to reconstruct attacker activity and identify root cause. Day-to-day work includes client communication, containment support, report writing, and participation in an on-call

Digital Forensics Practitioner

The Role This position involves conducting advanced digital investigations, extracting and interpreting evidence from devices such as mobile phones and hard drives. The practitioner produces detailed examination reports and court statements, while also advising frontline officers on the correct seizure

Digital Forensics Investigator – Team Leader

The Role This position involves leading a team of digital investigators while managing a personal caseload of forensic device examinations. Day-to-day responsibilities include developing examination strategies, handling digital exhibits, producing expert reports and witness statements, attending client sites for equipment

Incident Response Security Consultant, Mandiant

The Role This position involves leading end-to-end incident response engagements, guiding organisations through investigation, containment, remediation, and crisis management. Consultants assess and respond to active threats, advise on cyber risk reduction, and support clients before, during, and after security incidents,

INCIDENT RESPONSE LEAD, DFIR (UK)

The Role This position leads complex digital forensic investigations day to day, spanning business email compromise, ransomware, network intrusions, and insider threats, with an initial emphasis on cloud email environments across Google and Microsoft platforms. The analyst builds defensible timelines,

Corporate Forensic Analyst

The Role This position centres on conducting structured digital forensic examinations across Windows computers, mobile devices, cloud platforms and email environments. Day-to-day work involves acquiring and analysing evidence from dead-box investigations, supporting business email compromise and ransomware cases, and contributing

Cyber Digital Forensics & Incident Response Manager

The Role This hybrid management position leads a team of digital forensics and incident response analysts operating within a 24×7 on-call model. Day to day, the role involves overseeing service delivery during significant cyber events such as ransomware and malware

Cyber Incident Response & Digital Forensics Assistant Manager

The Role This hands-on position sits within a dedicated cyber response team, delivering incident response and digital forensics services to clients facing active security incidents. The work spans investigation, containment and recovery activities, with regular on-call responsibilities as part of

Digital Forensics Senior Associate

The Role This position involves conducting in-depth digital forensic investigations, collecting and preserving evidence, performing root cause analysis on potential security breaches, and producing detailed investigation reports. The analyst collaborates with Legal, Technology, and HR teams to support incident response,

Digital Forensics Apprentice

The Role This apprenticeship sits within a digital forensics team, where you support the recovery and preservation of evidence from digital devices across a range of investigations. Day to day, you assist qualified examiners with data extraction, device processing, and

Senior Digital Investigator – Mobile

The Role This position involves conducting forensic examinations of digital devices, with a strong focus on mobile forensics. Day to day, the investigator manages their own casework, develops tailored examination strategies, produces court-ready reports and formal statements, and provides written

Senior DFIR / Incident Response / Digital Forensics

The Role This VP-level position sits at the heart of a major bank’s cyber defence function, conducting hands-on digital forensics and incident response across host, network, cloud, and live environments. The analyst investigates malware, malicious samples, and network activity, liaising

Cyber Incident Response Manager

The Role This hands-on position centres on managing reactive digital forensics and incident response (DFIR) cases of medium to large scale. When not leading live incidents, the role involves helping clients strengthen their own response capabilities through runbooks, tabletop exercises,

Cyber Response & Recovery – Senior Manager

The Role This senior position sits within a specialist cyber response team, leading incident response cases and conducting digital forensics across disk, memory, network, and log data. Between incidents, the role involves helping clients strengthen their own response capabilities through

Cyber Incident Response Manager

The Role This position involves leading technical analysis during cyber security incidents and data breaches, managing client engagements from initial response through to recovery. Day-to-day work includes producing investigation reports, developing detection content for SecOps environments, and coordinating across threat

Cyber Security Consultant

The Role This mid-level position sits within a global incident management team, focusing on detecting, analysing, and responding to client cybersecurity incidents. Day-to-day work spans forensic investigations, threat containment, root cause analysis, and producing technical reports, with regular travel to

Cyber Digital Forensics & Incident Response Manager

The Role This hybrid position leads a team of digital forensics and incident response analysts operating within a 24×7 on-call model, overseeing service delivery during significant cyber events such as ransomware attacks and security breaches. Day-to-day responsibilities include managing client

Senior Digital Forensic Operations Officer

The Role This position combines operational leadership of scene-based practitioners with hands-on delivery of digital forensic services supporting serious and organised crime investigations. The postholder provides tactical and strategic advice to investigative teams across the UK, ensuring digital evidence on

Forensic Computer Analyst

The Role This position sits within a specialist policing unit and involves the forensically sound acquisition and examination of digital devices, including computers and mobile phones, in support of criminal investigations. The analyst prepares expert witness statements, attends crime scenes,

Digital Forensics & Insider Risk Analyst

The Role This position leads end-to-end digital forensic investigations within an insider risk management function, covering evidence collection, preservation, and analysis across diverse data sources. The analyst manages eDiscovery workflows, produces investigative findings and timelines, and ensures all work meets

Digital Forensic Analyst

The Role Analysts secure, retrieve, and examine data from digital devices such as mobile phones and computers to support police investigations. Day-to-day work includes processing evidence, recording detailed notes, presenting findings to investigators and courts, conducting peer reviews, and mentoring

International Digital Forensics and Incident Response (DFIR) Expert

The Role This position involves leading and supporting end-to-end cyber incident response engagements for international clients, spanning triage, forensic investigation, recovery, and lessons learned. Day-to-day work includes examining endpoints, cloud platforms and enterprise systems, producing technical reports, and collaborating with

Senior Digital Forensic Analyst

The Role This is a senior evidential forensics position based full-time in a UK laboratory. Day to day, the analyst conducts mobile and computer examinations, produces court-admissible reports for criminal and civil proceedings, peer reviews junior colleagues’ casework, manages an

DFIR Lead Cyber Operations Analyst

The Role This VP-level position sits at the heart of a major bank’s cyber defence function, leading digital forensics and incident response investigations. Day to day, analysts examine malware, malicious samples and network traffic, collaborate with internal teams, external partners

Criminal Defence Digital Forensic Investigator

The Role The investigator examines and analyses digital evidence from computers, mobile devices, cloud platforms, and other digital media in support of criminal defence proceedings. Working alongside case managers, solicitors, and barristers, the role involves acquiring, interpreting, and presenting forensic

Senior Director | Digital Forensics & Investigations

The Role This London-based position leads complex digital forensics and investigations engagements, advising corporations, law firms and governments on regulatory matters, litigation support and data disputes. Day to day, the work involves directing evidence-driven technical projects, acting as a trusted

Information Security Incident Response Analyst

The Role This position sits within a global DFIR team, conducting technical investigations across host, disk, memory, network, and cloud environments. Day to day, the analyst reconstructs attacker timelines, supports clients through containment and recovery, contributes to readiness assessments, and