← All jobs · More in this country

Senior Incident Response & Digital Forensics Analyst

Bloomberg

London, England

Onsite · Senior · Full-time

The Role

Based within a global Cyber Security Operations Centre, this senior position leads end-to-end technical investigations into complex security incidents. Day-to-day work spans acquiring and analysing forensic images, examining memory and network evidence, reverse-engineering suspicious binaries, and reconstructing attacker activity to establish root cause and impact. The analyst also mentors teammates and contributes to tooling, playbooks, and detection development.

Skills & Experience

Candidates must bring substantial hands-on incident response leadership, strong Windows and Linux disk and memory forensics, static and dynamic malware analysis, and deep OS internals knowledge. Proficiency with Splunk or comparable SIEM platforms is essential, as is scripting in Python or similar. Familiarity with Volatility, CrowdStrike Falcon, cloud forensics (AWS/Azure/GCP), EDR tools such as osquery or Carbon Black, and network monitoring tools like Zeek or Suricata is advantageous.

Who It Suits

This role suits an experienced DFIR professional ready to take technical ownership of high-stakes investigations in a complex enterprise environment. Those with a drive to mentor others, build durable forensic processes, and translate incident findings into improved detection coverage will thrive here. Prior CSOC or consultancy backgrounds at senior level are well suited.

Typical advertised salary for Incident Response roles in United Kingdom: £58,000–£90,000 (median £70,000 — from 33 recent listings analysed by Forensic Focus).

Learn More/Apply

Applications are handled entirely by the employer or the original listing site. Forensic Focus aggregates and summarises public listings; details can change after publication — always confirm on the employer's page.

Listed: 2026-09-23