← All jobs · More in this country

Cyber Security Incident Manager

SEP2

England

Remote · Mid · Full-time

The Role

The successful candidate leads structured incident response engagements, directs analysts during active incidents, and performs hands-on technical work including image handling, malware analysis and deep log review. They also produce post-incident reports, manage customer onboarding into the DFIR service, and participate in an on-call rota alongside SOC operations.

Skills & Experience

Candidates must hold a relevant DFIR certification such as SANS/GIAC and demonstrate proficiency with tools including Velociraptor, FTK Imager, KAPE, Autopsy, Wireshark and sandboxing platforms. SIEM experience across Google SecOps, Splunk or Microsoft Sentinel is required, alongside a strong background in cloud, Linux, Windows and networking environments.

Who It Suits

This role suits a technically confident DFIR practitioner who is equally comfortable managing customer relationships under pressure as performing forensic analysis. Someone methodical, self-motivated and experienced in a customer-facing security environment will thrive, particularly those looking to take a coordination lead within a growing managed DFIR practice.

Typical advertised salary for Incident Response roles in United Kingdom: £53,000–£90,000 (median £70,000 — from 30 recent listings analysed by Forensic Focus).

Learn More/Apply

Applications are handled entirely by the employer or the original listing site. Forensic Focus aggregates and summarises public listings; details can change after publication — always confirm on the employer's page.

Listed: 2026-08-29