Incident Response Principal Consultant

This principal-level consulting role centres on leading high-priority incident response engagements for organisations facing sophisticated cyber threats. Day to day, the practitioner conducts intrusion investigations, performs host and network-based forensic analysis across Windows, macOS, and Linux, and supports cloud IR

Senior Incident Response Consultant, DFIR

The Role Consultants lead end-to-end incident response engagements for external clients, conducting digital forensics investigations, malware analysis, and threat actor attribution. The position requires 24/7 on-call availability, remote and on-site deployment, executive briefings, and maintaining a 75% billable utilisation target

Senior DFIR Consultant – Remote (Anywhere in the U.S.)

The Role This fully remote position involves leading and executing complex digital forensics and incident response investigations, including host forensics, network traffic analysis, log review, malware triage, and business email compromise analysis. The consultant communicates findings to both technical and

Senior Incident Response Consultant | USA, Remote | $120,000 – $155,000

The Role This position leads complex digital forensic investigations from initial triage through containment and recovery, covering host, network, cloud, and application environments. Consultants direct client teams during live incidents, scope engagements, develop detection logic from attacker behaviour, and deliver

IR & Forensics – Senior Consultant

The Role This position sits within a cyber incident response practice, where consultants lead investigations into malware, ransomware, data breaches, and insider threats across enterprise, cloud, and hybrid environments. Day-to-day work spans triage, containment, forensic analysis, threat hunting, log review,

Principal DFIR Consultant

The Role This senior consulting position leads digital forensics and incident response engagements, with a focus on business email compromise and ransomware cases. Day to day, the work spans forensic investigation, log and artifact analysis, containment support, client communication, team

Lead Cyber Incident Response Consultant

The Role This position leads complex cyber security incident investigations end to end, performing advanced digital forensics across Windows, Linux, macOS, and multi-cloud environments. Day to day involves analysing logs, network traffic, memory, and disk artefacts, maintaining chain-of-custody, and delivering

Cyber Response & Recovery Manager (Reactive DFIR) – German Speaking

The Role This hands-on position sits within a cyber advisory practice, focusing on reactive digital forensics and incident response. Day to day, the role involves managing medium to large incident response cases, supporting clients in building internal IR capabilities, contributing

Principal Consultant, DFIR

The Role This position involves leading end-to-end incident response engagements, from initial identification and containment through to forensic investigation, log analysis, and report writing. The practitioner also conducts threat actor communications and ransomware negotiations when required, operating independently under pressure

Associate Director, Incident Response and Forensics

The Role This senior leadership position oversees a global team of digital forensics, incident response, and eDiscovery analysts. Day to day, the role involves directing forensic investigations, guiding incident handling across the full response lifecycle, driving tool adoption, and collaborating

Senior Incident Response Security Consultant, Mandiant, Google Cloud (Hebrew)

The Role This remote position, based in Israel, involves leading end-to-end incident response engagements for clients, encompassing forensic investigation, threat hunting, malware triage, containment, and remediation. Consultants communicate findings to technical teams and executive stakeholders, manage crisis situations, and occasionally

Lead Cyber Security Specialist (Digital Forensics)

The Role This position leads end-to-end incident response operations, covering triage, investigation, containment, and recovery across endpoint, network, cloud, and mobile environments. The specialist conducts digital forensic acquisition, performs log analysis across multiple data sources, develops response playbooks, contributes to

Lead IT Specialist (Cybersecurity Incident Response)

The Role This position leads end-to-end cybersecurity incident response activities, covering triage, investigation, containment, eradication, and recovery. Day-to-day work includes analysing logs across endpoints, networks, cloud, and applications, performing digital forensics across multiple device types, communicating with stakeholders, and contributing

Senior Director, Digital Forensics & Incident Response

The Role This senior leadership position owns and commands the enterprise response to cyber incidents across cloud, on-premises and OT/ICS environments globally. Day to day, the role drives incident scoping, containment, eradication and recovery, oversees forensic evidence integrity, delivers executive

DFIR Consultant

The Role This fully remote position involves supporting clients through the full lifecycle of cyber incidents, from initial triage and evidence preservation through forensic analysis and final reporting. Day-to-day work centres on investigating Business Email Compromise and ransomware cases, delivering

Incident Response Senior Consultant (Remote)

The Role This position involves leading incident response engagements for major organisations, investigating breaches, analysing attacker behaviour, and delivering technical findings. Consultants work remotely across a varied caseload, responding to complex, high-profile incidents and helping clients understand and contain advanced

Principal Incident Response Security Consultant, Mandiant

The Role This senior consulting position involves leading end-to-end incident response engagements for clients facing complex, high-profile security incidents. Day-to-day responsibilities include conducting forensic investigations, performing threat hunting, triaging malware, supporting containment and remediation efforts, and communicating findings to both

Incident Response Principal Consultant (Remote)

The Role This position involves leading complex incident response engagements for major global organisations, investigating breaches, analysing threat actor activity, and delivering expert guidance throughout the full incident lifecycle. Consultants work across a varied caseload, handling high-profile investigations that demand

Incident Responder

Scope and contain live security incidents, reconstruct intrusions using host and network forensics, preserve evidence, and produce clear written timelines for clients and regulators in a fast-paced IR consultancy environment.

IT Incident Response and Forensics Specialist III

Lead complex security investigations and digital forensics across endpoints, networks, and cloud environments. Responsibilities include threat hunting, evidence preservation, root cause analysis, playbook development, and post-incident reporting to strengthen security posture.

Incident Response Principal Consultant (Remote)

The Role This remote position involves leading complex incident response investigations for major global organisations, responding to advanced cyber threats and breaches. Day to day, consultants conduct forensic analysis, manage high-stakes engagements, and advise clients on containment and remediation strategies

Principal Incident Response Analyst

The Role This senior position sits within a Threat Detection and Response team, covering hands-on security incident analysis, digital forensic investigations, and proactive threat hunting. The analyst leads containment and remediation efforts, coordinates with cross-functional teams during active incidents, and

Cyber Crime Incident Responder

The Role This position involves investigating and containing sophisticated cyberattacks, including APT campaigns, ransomware, and complex intrusions across national and international engagements. Practitioners conduct forensic analyses to secure digital evidence, analyse attacker infrastructures, and collaborate directly with agencies such as

IR & Forensics – Senior Consultant

Senior consultant role leading cyber incident response and forensic investigations across enterprise, cloud, and hybrid environments. Responsibilities include triage, malware analysis, threat hunting, and advising client stakeholders during active incidents.

Principal Incident Response Security Consultant, Mandiant

Senior Mandiant consultant managing complex incident response engagements, performing digital forensics, threat hunting, and malware analysis across cloud and on-premise environments, while communicating findings to executive and legal stakeholders.

Incident Response Senior Consultant

The Role This senior consulting position centres on leading complex incident response engagements from investigation through remediation. Day-to-day work spans host and network forensics across Windows, macOS, and Linux, malware analysis, threat hunting, and cloud incident response, with direct communication

Cyber Security Specialist

This role sits within a dedicated Cyber Security and Reaction Service team, where the successful candidate manages the full lifecycle of incident response for national and international clients. Day to day, this involves reconstructing complex attacks, implementing containment measures, conducting

Incident Response Senior Consultant (Remote, CAN)

Lead incident response engagements and intrusion investigations for global organisations, conducting host and network forensics across Windows, Mac and Linux, performing malware analysis, and delivering findings to senior stakeholders.

Senior Incident Response & DFIR Consultant

The Role This position leads end-to-end incident response engagements for enterprise clients, conducting digital forensics investigations, threat hunting, and log analysis across Windows, Active Directory, Microsoft 365, and cloud environments. The consultant also liaises with executive and technical stakeholders, produces

Consulting Associate/Recovery Services (Forensic Services practice)

The Role This position sits within a forensic services practice focused on fraud, misconduct, and cybercrime investigations. Day to day, practitioners collect and analyse digital evidence across Windows, Linux, virtualised, and cloud environments, lead incident containment and eradication, and support

Senior Specialist, Incident Response

The Role This position sits within a global CSIRT function, leading investigations across the full incident response lifecycle — from initial analysis and containment through to eradication, recovery, and post-incident review. The specialist collaborates daily with security operations, cloud, infrastructure,

Cyber Security Analyst – Level 3

The Role This senior SOC position involves leading the response to complex, critical security incidents at escalation level three, conducting in-depth digital forensic investigations across endpoints, servers and cloud environments, performing proactive threat hunting, and mentoring level-one and level-two analysts

Cyber Security Incident Response Analyst

The Role The analyst conducts forensic investigations into cyber security incidents reported to the CSIRT, triaging and examining digital media across heterogeneous environments. Daily work involves identifying threats, determining containment and remediation actions, analysing network traffic, reviewing log data, and

Senior Incident Response Consultant, DFIR

The Role This position leads digital forensics and incident response engagements for external clients facing active cybersecurity threats. Day-to-day work includes malware analysis, forensic examination of compromised systems, threat actor attribution, and delivering executive briefings, with 24/7 on-call availability and

Senior Security Consultant, Incident Response, Mandiant

The Role This position involves leading end-to-end incident response engagements, supporting clients through investigation, containment, remediation, and crisis management. Day to day, consultants analyse threats across network, cloud, disk, and memory environments, communicate findings to diverse audiences, and help organisations

Digital Forensics and Incident Response Specialist

The Role This position leads end-to-end security incident response, from initial detection and triage through containment, eradication, and recovery. Day to day, it involves conducting digital forensic investigations, maintaining case documentation, developing response playbooks, and supporting proactive threat hunting across

Senior Specialist, Incident Response

The Role This position sits within a global CSIRT and information security function, focusing on investigating cybersecurity incidents across their full lifecycle — from initial analysis and containment through to eradication and recovery. Day to day involves digital forensic examination,

IR & Forensics – Manager

The Role This position leads end-to-end cyber incident response engagements, covering triage, containment, forensic analysis, and recovery across enterprise, cloud, and hybrid environments. Day to day involves directing investigations into malware, ransomware, and data breaches, advising client stakeholders during active

Cyber Incident Investigation Specialist

The Role This position involves working alongside senior incident responders on live client engagements across Asia, supporting the containment, investigation, and recovery phases of real cyber attacks. The work is hands-on and delivery-focused, with direct mentorship guiding professional development in

CERT Lead

The Role This position leads a Computer Emergency Response Team through all phases of the incident response lifecycle, serving as the senior technical escalation point for high-profile cybersecurity incidents across city agencies. Day-to-day responsibilities span malware analysis, digital forensics, threat

Associate Director, Incident Response and Forensics

The Role This position leads a global team of digital forensics, incident response, and eDiscovery analysts, overseeing the full incident response lifecycle from preparation through recovery. Day-to-day responsibilities include forensic analysis of operating systems, network traffic examination, IOC derivation, malware

Principal Consultant, DFIR

The Role This position involves leading end-to-end incident response engagements, from initial identification and containment through to recovery and reporting. Practitioners conduct digital forensic investigations across servers and endpoints, perform log analysis, and when required, manage threat actor communications and

Cyber Incident Responder

The Role This position involves responding to and investigating a range of cyber incidents on behalf of clients across multiple sectors, including legal, insurance and law enforcement. The successful candidate manages investigations end to end, applying technical expertise in incident

Cyber Security Analyst – Level 3

The Role This senior SOC position involves leading the operational response to the most complex and critical security incidents, conducting in-depth digital forensic investigations, performing proactive threat hunting, and developing detection rules using the MITRE ATT&CK framework. The analyst also

Senior Cyber Response Analyst / Active TS/SCI

The Role This position leads incident response operations for high-severity cyber events affecting DoDIN-Europe, conducting malware analysis, memory forensics, and digital investigations to determine root cause and adversary tactics. The analyst manages SIEM alert triage, refines detection logic, and produces

IR & Forensics – Consultant

The Role This consultant position involves leading and supporting cybersecurity incident response engagements across enterprise, cloud, and hybrid environments. Day-to-day responsibilities include triage, containment, forensic analysis, threat hunting, log analysis, and documenting incident timelines, while communicating technical findings clearly to

Senior Digital Forensics and Incident Response Consultant

The Role This position sits within a dedicated incident response team, supporting clients through the full lifecycle of security incidents — from preparation and initial containment through to root cause analysis. Day-to-day work involves analysing attacks on corporate networks and

Cyber Incident Responder

The Role This position involves conducting forensic investigations and incident response engagements across complex, large-scale cyber attacks. Day-to-day work includes log analysis, host and network forensics, malware analysis, proactive threat hunting, and producing detailed investigation reports for clients globally. Skills

Principal Incident Response Consultant, Google Public Sector

Lead incident response and forensic consulting engagements for US public sector clients, managing breach containment, threat hunting, and remediation while mentoring staff and developing new business opportunities leveraging Google and Mandiant capabilities.

Senior Cybersecurity Incident Responder

Senior DFIR role within a managed SOC environment, leading major incident response engagements, conducting digital forensic investigations, delivering proactive advisory services including tabletop exercises, compromise assessments and threat hunting for commercial and government clients.

IR & Forensics – Consultant

The Role This consultant position focuses on supporting enterprise cyber incident response engagements across cloud, hybrid, and on-premises environments. Day-to-day responsibilities include triage and containment, forensic analysis of endpoints and networks, threat hunting, log analysis, and documenting findings to support

Consulting Associate/Recovery Services (Forensic Services practice)

Hands-on forensic analyst and incident responder supporting ransomware, BEC, and fraud investigations. Responsibilities include digital forensic collection, endpoint containment, enterprise identity remediation, and producing defensible written findings for clients and counsel.

Cyber Security Specialist

The Role This position involves managing IT security and compliance incidents for clients across national and international boundaries, handling the full lifecycle of DFIR cases from complex attack analysis through to containment. Day-to-day responsibilities include developing detection and response concepts,

Consulting Director, DFIR, Reactive Services (Unit 42)

Senior consulting director leading technical breach response teams and delivering expert DFIR guidance to clients across industries. Requires 10+ years hands-on experience with forensic tools, threat landscape knowledge, and strong client relationship management.

Senior Cybersecurity Incident Responder

Join a CSIRT team delivering digital forensics and incident response engagements, including evidence collection, log analysis, threat hunting, compromise assessments, tabletop exercises, and stakeholder reporting across Australia and New Zealand.

IR & Forensics – Manager

Lead cyber incident response engagements involving ransomware, data breaches, and insider threats. Direct forensic analysis, threat hunting, and recovery across enterprise, cloud, and hybrid environments. Advise client stakeholders and manage IR teams in a consulting capacity.

Digital Forensic and Incident Response Investigator

The Role This position sits within a global cyber operations team, serving as a second-line escalation point for complex security incidents on a 9/5 basis with weekend on-call coverage. Day to day, the investigator leads end-to-end incident response — from

Information Technology Manager II

The Role This position leads complex cyber incident investigations across enterprise, cloud, and on-premises environments, covering the full incident response lifecycle from triage to post-incident reporting. Day-to-day work includes digital forensics, malware analysis, proactive threat hunting, and developing SIEM detections

DFIR Consultant

Join a specialist DFIR team responding to BEC and ransomware incidents. Responsibilities include evidence acquisition, forensic analysis, malware triage, timeline development, client communication, and written reporting across endpoint, server, and cloud environments.

DFIR Consultant

The Role This position involves conducting digital forensics and incident response investigations across Windows and Linux environments. Day to day, the consultant collects disk and memory images, analyses forensic artefacts for indicators of compromise, reviews host and appliance logs, builds

Incident Response Lead (DFIR), UAE

The Role This Dubai-based position centres on leading cybersecurity incident response activities across enterprise environments, covering triage, containment, eradication, and recovery. Day-to-day work includes conducting digital forensic investigations, performing root cause analysis, coordinating with SOC and IT teams, developing response

Security Specialist – Incident Commander (DFIR)

The Role This position leads the response to high-severity cybersecurity incidents across a large global organisation, coordinating across security operations, IT, legal, and production teams. Day-to-day work spans active incident management, digital forensic investigations, threat hunting, post-incident reporting, and running

Incident Response Analyst, Digital Forensics & Incident Response

The Role This position involves hands-on technical work across all stages of active incident response engagements, including triage, evidence acquisition, forensic analysis, containment, eradication, and post-incident reporting. The analyst operates under senior direction, collaborating with incident commanders and SOC teams

Cybersecurity Incident Response Commander

The Role This position serves as the primary technical and operational authority for a Digital Forensics and Incident Response function, commanding engagements across ransomware, business email compromise, data exfiltration, and complex multi-vector incidents. The role owns IR processes and playbooks,

Senior DFIR Investigator

The Role This position involves leading complex digital forensic and incident response investigations across host, network and cloud environments. Day to day, the role includes analysing threat actor behaviour, producing forensic reports and timelines, guiding clients through incidents, and delivering

Director, Digital Forensics & Incident Response (Global)

The Role This senior leadership position oversees a globally distributed forensics and incident response function, setting strategic direction and ensuring consistent, high-quality delivery across cyber preparedness, active incident management, forensic investigations, and post-incident recovery, while also driving commercial growth by

Cyber Response & Recovery Manager – German Speaker

The Role This is a hands-on reactive digital forensics and incident response (DFIR) position, where the successful candidate manages medium to large cases as a case manager. Between incidents, the role involves supporting client IR capability building, runbook development, tabletop

Senior Digital Forensics and Incident Response Analyst

The Role This position sits within a Security Operations Centre, focusing on leading investigations into complex cyber security incidents. Day to day, the analyst collects and examines forensic evidence, responds to threats such as malware, phishing and endpoint compromise, and

Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves hands-on incident response work, including collecting forensic artifacts, analysing disk and memory images, reviewing host and appliance logs, and building event timelines. The consultant engages with insurance partners, legal counsel, and client technical teams to

Senior DFIR Analyst

The Role This position sits within a global cybersecurity function and focuses on investigating and responding to security incidents across a large enterprise environment. Day to day involves collecting and preserving digital evidence, analysing logs and artefacts from multiple security

T&T I Cyber: D&R I Manager | Incident Response & Handling

The Role This position centres on leading client-facing incident response engagements from initial scoping through containment and remediation. Day-to-day work includes digital forensics analysis, network log and PCAP review, malware triage, security analytics, and producing reports for both technical and

T&T | Cyber : D&R | Director | Incident Response & Handling

The Role This director-level position leads end-to-end incident response engagements, guiding clients from initial scoping through containment and remediation. Responsibilities include DFIR analysis, network log and PCAP review, malware triage, security analytics, and producing clear reports for both technical and

Staff Cybersecurity Specialist – Incident Response

The Role This senior individual contributor position focuses on leading end-to-end incident response engagements, from initial investigation through to recovery, working directly with affected organisations. Alongside hands-on response work, the specialist mentors junior analysts and contributes to improving security operations

Principal DFIR Consultant – Remote (Anywhere in the U.S.)

The Role This senior individual contributor position leads the most complex and high-visibility incident response engagements, including ransomware, APT, and insider threat cases. Day to day involves conducting advanced host forensics, network analysis, cloud forensics, and malware triage, while also

Director, DFIR (Remote)

The Role This fully remote position involves leading digital forensics and incident response engagements across a range of cyber threats, including ransomware and data theft. The director oversees multiple concurrent incidents, coordinates cross-functional teams, and liaises with external stakeholders such

Principal DFIR Consultant

The job posting is cut off at “Client Management And” but I have enough information to write the description. Let me craft the HTML with the three required sections. Key points from the posting: – Principal DFIR Consultant, remote USA

Principal Consultant, Digital Forensic and Incident Response (DFIR) (Remote)

The Role This fully remote position involves leading digital forensics and incident response engagements across a range of industries, conducting sophisticated forensic analysis, managing investigations of varying complexity, and serving as a senior technical expert for clients navigating active cyber

Engineer, Cybersecurity DFIR

The Role This position sits within a cybersecurity DFIR team defending critical financial infrastructure against global threats. Day to day, the engineer handles security analytics, incident detection and investigation, endpoint forensics, threat hunting, intrusion detection, and the design of preventative

Principal Consultant, DFIR, Reactive Services (Unit 42) – Remote Weekend Shift

The Role This senior individual contributor position involves leading expert-level incident response and digital forensics engagements across diverse industries. Day to day, consultants conduct forensic investigations, analyse attacker activity, assess scope and impact, and guide clients through containment, remediation, and

Cyber Network Defense Analyst III

The Role This position supports a federal cyber defence programme, conducting Tier 2 and Tier 3 digital forensics and incident response investigations both remotely and on-site. Day-to-day work involves responding to cyber incidents, performing proactive threat hunting, and analysing host-based,

Cyber Network Defense Analyst II

The Role This position supports front-line cyber defence and incident response operations within a federal programme protecting national communications infrastructure. Day to day, analysts conduct Tier 2 and Tier 3 digital forensics and incident response investigations, perform proactive threat hunting,

Contract Bench, Incident Responder (DFIR)

The Role This contract position involves conducting digital forensic investigations and incident response engagements on a flexible, as-needed basis. Responders analyse live response data, investigate threat actor activity across Windows environments and cloud platforms, and help eradicate adversaries across clients’

Senior Consultant, DFIR (Wed-Sun)

The Role This position involves leading digital forensics and incident response engagements across modern enterprise environments, investigating threat actor activity on endpoints, cloud platforms including AWS, Azure, and GCP, SaaS applications, and identity providers, while supporting clients through active incidents

Senior Consultant, DFIR

The Role This position involves leading incident response and digital forensics engagements across complex, modern enterprise environments, including Windows endpoints, cloud platforms such as AWS, Azure, and GCP, and SaaS applications. Consultants investigate active threats, support clients through high-pressure incidents,

Senior Incident Response Consultant

The Role This position leads forensic investigations across host, network, and application environments while guiding clients through containment, remediation, and recovery. Day to day involves triaging active security incidents, identifying attacker tactics, developing investigative tooling, producing reports, and working directly

Lead Cyber Mission Threat Analyst – Clearance Required

The Role This senior position leads cyber threat hunting, incident investigation, forensic analysis, and enterprise monitoring in support of U.S. Navy cybersecurity operations. The analyst identifies indicators of compromise, examines adversary tactics, conducts complex investigations, and delivers actionable recommendations to

DFIR

The Role This position sits at the front line of cyber defence, handling the full incident response lifecycle for clients worldwide. Day to day, practitioners perform digital forensic investigations across Windows, Linux, and cloud environments, conduct proactive threat hunting, analyse

Principal Engagement Lead (Remote)

The Role This fully remote position centres on leading multiple concurrent cybersecurity incident response engagements, serving as the primary point of contact for clients, insurance carriers, and legal counsel. Day-to-day responsibilities include scoping engagements, coordinating cross-functional response teams, and driving

Incident Response and Forensics Lead

The Role This senior position leads a digital forensics and incident response team within a federal environment, overseeing day-to-day operations, managing service delivery, briefing clients and senior leadership, analyzing intrusion artifacts such as malware, and monitoring emerging threats from external

Lead Cyber Mission Threat Analyst – Clearance Required

The Role This senior position leads cyber threat hunting, incident investigation, enterprise monitoring, and forensic analysis in support of U.S. Navy cybersecurity operations. Working alongside government professionals, the analyst identifies indicators of compromise, examines adversary tactics, conducts complex investigations, and

Senior Incident Response Security Consultant, Mandiant, Google Cloud

The Role This senior-level position involves leading end-to-end incident response engagements for clients facing complex, high-profile security incidents. Day to day, consultants perform forensic analysis across network, disk, memory, and cloud environments, conduct threat hunting, triage malware, and support containment,

Incident Response Lead – Germany *

The Role This position leads cyber incident response engagements across Germany and the wider region, guiding clients through forensic investigations, breach analysis, and remediation planning. Day to day involves examining Windows, Linux, and macOS systems, reviewing logs, coordinating vendor support,

Incident Response Security Consultant, Mandiant (English)

The Role This position involves leading end-to-end incident response engagements, helping organisations detect, contain, and recover from security incidents. Day to day work spans forensic investigation, malware triage, threat analysis, and communicating findings to both technical teams and senior stakeholders,

DFIR Expert (Lead)

The Role This position leads complex digital forensics investigations and incident response engagements, serving as the senior escalation point for confirmed breaches. Day-to-day responsibilities span forensic analysis across file systems, memory, and networks, alongside containment and recovery activities, tool development,

Senior Cyber Incident Response Investigator

The Role This role centres on managing and resolving serious cyber incidents for organisations globally. Day to day, investigators analyse security intrusions end-to-end, perform host and network forensics, conduct malware analysis, hunt advanced threats, and develop remediation plans, with client-facing

Security Specialist – Incident Commander (DFIR)

The Role This position leads the end-to-end response to high-severity cybersecurity incidents across global infrastructure, game production pipelines, and player-facing services. Day-to-day responsibilities include coordinating cross-functional teams, conducting digital forensic investigations, performing proactive threat hunting, running simulation exercises, and producing

Minimum qualifications

The Role This position involves protecting network boundaries, hardening systems against attacks, and monitoring infrastructure for intrusions. The engineer owns and drives resolution of complex security incidents, collaborates with software engineers to identify and remediate vulnerabilities, and handles sensitive policy

Lead Service Manager – Incident Response Analyst

The Role This senior position sits within a managed security services SOC and CSIRT function, leading incident response engagements across a multi-tenant client base. Day to day, the analyst delivers containment, investigation, and remediation for retainer clients, working independently under

Incident Response Expert

The Role This position involves leading and supporting end-to-end forensic investigations across complex cybersecurity incidents, including ransomware and nation-state activity. Day-to-day work includes log analysis, host and network forensics, memory analysis, malware triage, threat hunting, and collaborating with client security

Digital Forensics and Incident Response Analyst

The Role This position sits within a specialist cyber risk and investigations team, where the analyst serves as a first responder to client-reported cyber incidents. Day-to-day work covers threat investigation, containment, and eradication, alongside supporting internal security operations and contributing

Senior Investigator – DFIR

The Role This senior position focuses on delivering end-to-end incident response engagements, encompassing evidence acquisition, processing, and analysis, through to presenting findings to clients. The role also involves contributing to broader practice operations, including business development, client liaison, and managing

Senior Cybersecurity Incident Responder

The Role This senior position sits within a dedicated incident response team, leading digital forensics and incident response engagements across Australia and New Zealand. Day-to-day work spans reactive incident investigations alongside proactive advisory services such as tabletop exercises, compromise assessments,

ETR Lead

The Role This position leads a specialist team within a global cyber defence function, overseeing external threat response strategy and daily operations. Responsibilities span digital forensic investigations, stakeholder collaboration across legal, HR and security teams, managing an analyst reporting mailbox,

Incident Response Lead, DFIR

The Role This founding position leads complex cloud and enterprise incident response investigations, setting best practices and standards for an AI-native DFIR function. The role involves close collaboration with AI engineers who automate routine forensic tasks, allowing the lead to

Lead Consultant – Incident Response

The Role This position leads active incident response engagements and supports IR retainer clients, conducting host-based and network forensic investigations across Windows, Mac, and Linux environments. Responsibilities include threat hunting, EDR-driven assessments, full packet analysis, report writing, and advising customers

Incident Response Security Consultant, Mandiant (English)

The Role This position involves leading end-to-end incident response engagements, helping organisations detect, contain, and recover from security incidents. Day-to-day work spans network forensics, malware triage, cloud and memory analysis, and communicating findings clearly to both technical teams and executive

Principal Consultant, Incident Response (Weekend Schedule)

The Role This position involves leading client-facing incident response engagements on a Friday-to-Monday schedule, working ten hours per day. Responsibilities include scoping work, managing forensic investigations end to end, advising clients on immediate containment measures, and providing long-term remediation guidance

Senior Information Security Incident Response Analyst

The Role This senior position leads complex security incident investigations, performing forensic analysis across host, disk, memory, network, cloud, and mobile environments. The analyst guides clients through containment and recovery, reconstructs event timelines, communicates findings to technical and executive audiences,

Senior Information Security Incident Response Analyst

The Role The analyst leads advanced security incident investigations spanning endpoints, networks, cloud platforms, and mobile environments. Day to day involves performing host, disk, memory, and log forensic analysis, reconstructing attack timelines, determining incident scope, and guiding stakeholders through containment,

Senior Incident Response Security Consultant, Mandiant, Google Cloud

The Role This senior consulting position centres on leading end-to-end incident response engagements for clients facing complex, high-profile cyber incidents. Day-to-day responsibilities include forensic analysis across disk, memory, network, and cloud environments, threat hunting, malware triage, containment, remediation, and crisis

Cyber Response & Recovery Assistant Manager (Reactive DFIR)

The Role This hands-on position sits within a specialist cyber response team, focusing on reactive digital forensics and incident response. Day to day, the role involves acting as a junior case manager on smaller engagements or supporting senior colleagues on

Incident response researcher/ DFIR

The Role This position involves conducting forensic investigations and incident response engagements across complex, large-scale cyberattacks. Day to day, the analyst performs log analysis, host and network forensics, threat hunting in client environments, and security simulations, while producing detailed professional

Engineer, Cybersecurity DFIR

The Role This position focuses on defending critical financial infrastructure through hands-on incident response, endpoint forensics, and proactive threat hunting. Day to day involves detecting and investigating security incidents, analysing forensic artefacts to build timelines, tuning intrusion detection controls, and

Senior Cyber Incident Response Investigator

The Role This position involves leading end-to-end cyber incident investigations for organisations globally, performing host, network, and log forensics, conducting malware analysis, and proactively hunting for advanced threats. The work includes developing remediation plans, running tabletop exercises, and collaborating directly

Cyber Security Analyst – Level 3

The Role This senior SOC position centres on leading the response to the most complex and critical security incidents at escalation level three. Day-to-day responsibilities include deep forensic investigation of compromised systems, proactive threat hunting, developing MITRE ATT&CK-based detection rules,

Incident Response Practice Lead (Hands-on)

The Role This position leads complex cyber incidents from initial triage through containment, eradication, recovery, and post-incident review. Day-to-day responsibilities include digital forensics, threat hunting, compromise assessments, and building IR methodologies, playbooks, and service offerings while working directly with clients

CSIRT Analyst

The Role This position sits within a CSIRT team, handling escalated security incidents and conducting digital forensics and incident response investigations. Day-to-day responsibilities span threat hunting, compromise assessments, threat intelligence collection, detection engineering in SIEM and XDR platforms, purple teaming

Principal Consultant, Incident Response (Weekend Schedule)

The Role This position centres on leading end-to-end incident response engagements for a range of clients, covering initial scoping, forensic investigation, containment, and long-term remediation guidance. It operates on a Friday-to-Monday schedule, ten hours per day, with Tuesday through Thursday

Principal Consultant, Incident Response (Unit 42)

The Role This position leads end-to-end incident response engagements for clients, managing scope, guiding forensic investigations, and overseeing containment and remediation. Day to day involves hands-on host-based analysis across Windows, Linux, and macOS environments, as well as reviewing firewall, web,

Global Director of Autonomous Incident Response and Forensic Analysis

The Role This senior leadership position oversees a 24/7 global incident response and digital forensics function, driving strategy, execution, and continuous improvement. Day to day, the role involves coordinating rapid containment and recovery efforts, managing forensic investigations, producing executive-level reporting,

Tier II-III Incident Response Analyst-Senior

The Role This senior position leads advanced cybersecurity incident investigations, coordinating responses to high-impact security events. Day-to-day responsibilities include conducting in-depth forensic analysis, reviewing suspicious code, performing malware analysis, hunting for threats, and gathering cyber threat intelligence across client environments.

Incident Response Consultant, Mandiant

The Role This position involves leading end-to-end cyber incident response engagements, supporting clients through complex security breaches from initial investigation through to containment and remediation. Day-to-day work includes forensic analysis, threat hunting, malware triage, and advising both technical teams and

Lead Incident Responder – DFIR Specialist

The Role This position involves leading incident response engagements for enterprise clients experiencing active cyber breaches, managing a team of investigators, collecting and analysing digital evidence, scoping technical work, preparing reports and deliverables, and providing on-site support across Australia and

Cyber Incident Response

The Role Three positions are available within a UK Tier 1 cyber response practice: one focused on digital forensics and incident response across disk, memory, network and log sources; one advising clients on security operations, threat intelligence and AI-enabled defence;

Cyber Security Analyst

The Role This position leads complex cyber security incident investigations across diverse technology environments, performing advanced digital forensics on Windows, Linux, macOS and multi-cloud platforms. Day-to-day responsibilities include analysing logs, network traffic and memory artefacts, establishing attacker timelines, preserving evidence

Incident Analyst (full time or student program)

The Role This position sits within an incident response team, with day-to-day work spanning incident analysis, malware analysis, and digital forensics projects. Depending on experience and interests, the role may also extend into security consulting, training, and assessment engagements across

Experte Computer Incident Response Team (CSIRT)

The Role This position sits within a central IT security function and focuses on identifying, analysing, containing and resolving security incidents. Working closely with technical leadership, the specialist supports the organisation’s day-to-day incident response capability, driving both operational and methodological

Incident Response Lead – Germany *

The Role This position leads cyber incident response engagements for customers across Germany and the wider region, conducting forensic investigations across Windows, Linux, and macOS environments, analysing diverse log sources, coordinating with vendors and team members, producing case reports, and

Cyber Response and Recovery – Assistant Manager (Reactive)

The Role This hands-on position sits within a reactive digital forensics and incident response (DFIR) team, handling live cyber incidents as a junior case manager on smaller engagements or as a team contributor on larger ones. Outside of active incidents,

Senior Incident Responder

The Role This position leads cyber incident response engagements from initial scoping through to resolution, managing cases end-to-end across the Asia region. Day-to-day work involves hands-on investigation, coordinating response activities, and delivering outcomes for clients experiencing active breaches or digital

Senior Cybersecurity Incident Responder

The Role This position sits within a mature cybersecurity defence operations centre, delivering digital forensics and incident response engagements across Australia and New Zealand. Day-to-day work spans reactive incident investigations, tabletop exercises, compromise assessments, threat hunting, breach readiness assessments, and

Crisis & Incident Response – Consultant

The Role This consultant position focuses on leading and supporting cybersecurity incident response engagements across enterprise, cloud, and hybrid environments. Day-to-day work includes forensic analysis, threat hunting, log review, triage, and containment, as well as documenting findings and communicating technical

Cyber Response & Recovery – Senior Manager

The Role This senior position sits within a cyber response and risk consulting practice, leading teams through active security incidents while conducting digital forensics across disk, memory, network, and log sources. Beyond incident work, the role involves helping clients mature

Incident Response Lead

The Role This position leads a global incident response function, building and operating a follow-the-sun team across EMEA, Asia, and the APAC region. Day to day, it combines hands-on technical investigation of major incidents — spanning containment, eradication, and recovery

Senior Incident Response Security Consultant, Mandiant, Google Cloud (Hebrew)

The Role This senior consulting position involves leading end-to-end incident response engagements for clients, covering investigation, containment, remediation, and crisis management. Day-to-day work includes forensic analysis across network, cloud, disk, and memory environments, as well as threat hunting, malware triage,

Digital Forensics and Incident Response, Senior Manager

The Role This senior leadership position oversees multiple incident response teams, directing complex digital forensic investigations and cybersecurity incident response engagements. The role involves advising during high-severity incidents, communicating findings to executives and legal stakeholders, managing team performance, and supporting

Junior Incident Responder

The Role Working alongside senior practitioners on live client engagements, this position involves supporting the containment, investigation, and recovery phases of cyber incidents. Day-to-day responsibilities span hands-on digital forensics, incident response activities, and contributing to a tech-enabled team that operates

Dutch Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves hands-on incident response work, including collecting forensic artifacts, analysing disk and memory images, reviewing host and appliance logs, and building event timelines. The consultant collaborates with insurers, legal teams, and client technical staff to assess

Senior Cybersecurity Incident Responder

The Role This position sits within a dedicated incident response team, delivering digital forensics and incident response engagements for commercial and government clients across Australia and New Zealand. Day-to-day work spans reactive breach investigations, compromise assessments, threat hunting, tabletop exercises,

Digital Forensics & Cyber Incident Responder – Hybrid – London

The Role This position sits within a specialist team that handles real-world cyber security incidents, including ransomware attacks and significant breaches. Day to day, practitioners investigate live incidents, examine forensic evidence, map attacker behaviour, and guide affected organisations through their

Senior Digital Forensic Investigator

The Role This senior-level position leads complex digital forensics and incident response engagements, handling high-stakes cases ranging from financially motivated breaches to state-affiliated espionage. The investigator coordinates with security operations and customer success teams to mobilise rapidly, identify threat sources,

Principal Cyber Security Specialist (Operations)

The Role This senior position sits within a national cyber security operations directorate, contributing to incident response at a national level, malware and forensic analysis, and cyber threat intelligence collection. The postholder also plays an active part in strategic leadership,

Junior DFIR Analyst

The Role The analyst supports incident response operations around the clock, conducting live endpoint investigations, gathering forensic artifacts, performing traffic analysis, and producing technical reports for clients. The role also involves contributing to the development of IR processes, maintaining incident

German Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves responding to cyber incidents on behalf of clients, conducting Windows and Unix/Linux forensic investigations, collecting disk and memory images from physical and virtual systems, analysing artefacts for indicators of compromise, reviewing host and appliance logs,

Information Security Incident Response Analyst

The Role The analyst investigates security incidents end to end, conducting host, memory, network, and cloud forensic analysis to reconstruct attacker activity and identify root cause. Day-to-day work includes client communication, containment support, report writing, and participation in an on-call

SOC Analyst – Digital Forensics & Incident Response

The Role This position sits within a 24×7 SOC environment and focuses on advanced investigation of escalated security incidents. Day-to-day work spans digital forensics, malware triage, threat correlation across multiple security platforms, incident timeline reconstruction, containment support, and maintaining thorough,

Incident Response Security Consultant, Mandiant

The Role This position involves leading end-to-end incident response engagements, guiding organisations through investigation, containment, remediation, and crisis management. Consultants assess and respond to active threats, advise on cyber risk reduction, and support clients before, during, and after security incidents,

INCIDENT RESPONSE LEAD, DFIR (UK)

The Role This position leads complex digital forensic investigations day to day, spanning business email compromise, ransomware, network intrusions, and insider threats, with an initial emphasis on cloud email environments across Google and Microsoft platforms. The analyst builds defensible timelines,

Senior Cybersecurity Incident Responder

The Role This position sits within a managed security operations centre, focusing on digital forensics and incident response engagements for commercial and government clients. Day to day work spans reactive incident investigations, tabletop exercises, compromise assessments, breach readiness evaluations, threat

Senior Director of Digital Forensics & Incident Response

The Role This senior leadership position oversees a 24x7x365 global security operations centre, directing enterprise-wide incident response and digital forensic investigations. The role involves shaping multi-year strategy, managing global teams across DFIR and related functions, and advising executive leadership during

Senior Director, Digital Forensics and Incident Response

The Role This senior leadership position involves commanding complex cyber investigations end-to-end, from initial response through containment and recovery. Day to day, the role spans ransomware, business email compromise, cloud and identity compromise, and insider threat investigations, alongside executive briefings,

Digital Forensics and Incident Response (DFIR) Consultant

The Role This position involves responding to active cyber incidents, conducting forensic acquisition and analysis of physical and virtual systems, reviewing host and appliance logs, correlating events into timelines, and applying mitigation strategies to contain and remediate threats such as

Cyber Digital Forensics & Incident Response Manager

The Role This hybrid management position leads a team of digital forensics and incident response analysts operating within a 24×7 on-call model. Day to day, the role involves overseeing service delivery during significant cyber events such as ransomware and malware

Cyber Incident Response & Digital Forensics Assistant Manager

The Role This hands-on position sits within a dedicated cyber response team, delivering incident response and digital forensics services to clients facing active security incidents. The work spans investigation, containment and recovery activities, with regular on-call responsibilities as part of

Lead DFIR Specialist (Assistant Director), Technology Firm

The Role This hands-on leadership position oversees enterprise-scale cyber incident response, guiding a specialist team through investigation, containment, remediation, and post-incident review. The role also involves refining response playbooks, driving continuous improvement, and coordinating with security operations, infrastructure, and application

Junior Incident Responder, Singapore

The Role This position involves working alongside experienced responders on live cyber incidents, supporting clients through containment, investigation, and recovery. Day-to-day work spans active engagements across the Asia region, contributing to end-to-end digital emergency response within a fast-paced, technology-enabled team

Cyber Incident Response Manager

The Role This hands-on position centres on managing reactive digital forensics and incident response (DFIR) cases of medium to large scale. When not leading live incidents, the role involves helping clients strengthen their own response capabilities through runbooks, tabletop exercises,

Incident Response Lead

The Role This senior position within a global security operations centre involves leading technical responses to complex cybersecurity incidents around the clock. Day to day responsibilities include coordinating containment and recovery activities, conducting advanced investigations across endpoints, networks, and cloud

Senior Cybersecurity Incident Responder

The Role This position sits within a cybersecurity incident response team, leading digital forensics and incident response engagements across Australia and New Zealand. Day-to-day work spans reactive incident investigations alongside proactive advisory activities such as tabletop exercises, compromise assessments, threat

Chef de file de la réponse aux incidents

The Role This senior position sits within a global security operations centre, providing round-the-clock coverage across the organisation. Day to day, it involves leading technical responses to complex cybersecurity incidents, coordinating investigations, and driving containment, eradication, and recovery activities in

Cyber Response & Recovery – Senior Manager

The Role This senior position sits within a specialist cyber response team, leading incident response cases and conducting digital forensics across disk, memory, network, and log data. Between incidents, the role involves helping clients strengthen their own response capabilities through

Cyber Incident Response Manager

The Role This position involves leading technical analysis during cyber security incidents and data breaches, managing client engagements from initial response through to recovery. Day-to-day work includes producing investigation reports, developing detection content for SecOps environments, and coordinating across threat

Senior Investigator Digital Forensics, Incident Response (DFIR)

The Role This senior-level position involves leading complex digital forensic investigations and incident response engagements across cloud, OT, and enterprise environments. Day-to-day responsibilities include memory forensics, malware triage, threat hunting, log analysis, timeline development, and mentoring junior investigators across concurrent

Cyber Security Consultant

The Role This mid-level position sits within a global incident management team, focusing on detecting, analysing, and responding to client cybersecurity incidents. Day-to-day work spans forensic investigations, threat containment, root cause analysis, and producing technical reports, with regular travel to

Cyber Digital Forensics & Incident Response Manager

The Role This hybrid position leads a team of digital forensics and incident response analysts operating within a 24×7 on-call model, overseeing service delivery during significant cyber events such as ransomware attacks and security breaches. Day-to-day responsibilities include managing client

Tier 3 Digital Forensics and Incident Response Analyst

The Role This senior-level position leads investigations into high-priority cybersecurity incidents, coordinating cross-functional teams and serving as the primary escalation point for junior analysts. Day-to-day responsibilities include alert triage, root cause analysis, detection rule tuning, threat research, post-incident review, and

Cyber Incident Responder/ Forensic Analyst

The Role This position centres on investigating cyber incidents through the analysis of logs, endpoint artifacts, and network data. Day to day, the analyst collects and preserves digital evidence, documents findings and timelines, and supports containment and remediation efforts, coordinating

DFIR

The Role This position sits within an incident response team, handling the full lifecycle of cyber incidents on behalf of clients worldwide. Day to day work spans detection, containment, eradication and recovery, digital forensics investigations across Windows and Linux platforms,

Senior Incident Responder, Singapore

The Role This position leads cyber incident response engagements from initial scoping through to resolution and defensive recommendations. Day to day, the work involves investigating active breaches, coordinating response efforts, and delivering clear findings — operating as a hands-on technical

Security Incident Responder (m/w/d)

The Role Practitioners lead technical responses to active cyber incidents, primarily ransomware and business email compromise cases, on behalf of mid-sized organisations. Day-to-day work spans log analysis, attack vector investigation, containment planning, system recovery, and producing forensic reports that support

Cyber Incident Responder

The Role The position involves supporting clients who are actively experiencing cyberattacks, working as part of a dedicated team to investigate and contain incidents. Day to day, this means conducting analyses using endpoint detection, network sensors, and manual techniques when

Senior Cyber Incident Responder

The Role This position involves supporting clients through active cyber attacks, leading and guiding a team during major cyber incidents. Day to day, the work spans hands-on cyber incident response and digital forensics, requiring direct client engagement and the ability

Senior Analyst / Assistant Manager – Incident Response

The Role This position involves supporting cyber incident response engagements across triage, evidence collection, and forensic analysis of endpoints, servers, and cloud environments. Analysts examine security telemetry and logs to reconstruct timelines, assess incident scope, and assist technical teams with

DFIR Lead Cyber Operations Analyst

The Role This VP-level position sits at the heart of a major bank’s cyber defence function, leading digital forensics and incident response investigations. Day to day, analysts examine malware, malicious samples and network traffic, collaborate with internal teams, external partners

Staff Cybersecurity Specialist – Incident Response (f/m/x)

The Role This senior individual contributor position leads incident response engagements end-to-end, from initial investigation through to recovery, working directly alongside customers during critical security events. The role also involves mentoring junior responders, driving operational improvements, and contributing to security

DFIR Expert (Lead)

The Role This position leads digital forensics investigations and incident response engagements, acting as the highest escalation point during confirmed breaches. Day-to-day work spans forensic analysis across file systems, memory, and networks, alongside threat containment, tool development, reporting, and collaboration

Lead Cybersecurity Incident Response Specialist

The Role This position sits within a cyber defence operations team and covers the full incident response lifecycle. Day to day, the specialist triages security events, leads in-depth investigations, and advises stakeholders on containment, eradication, and recovery strategies to protect

Principal Consultant – DFIR

The Role This position leads technical engagements across digital forensics and incident response, managing emergency situations from initial triage through remediation. Day to day, the consultant coordinates team workflows, conducts intelligence-driven investigations, produces high-quality client deliverables, and contributes to cyber

Executive Principal Consultant

The Role This position leads and coordinates digital forensics and incident response engagements, managing teams through complex security events. Day to day responsibilities include responding to emergency incidents, conducting intelligence-driven investigations, supporting clients through threat assessments, and contributing to cross-service

Consultant – DFIR

The Role This consultant position involves delivering digital forensics and incident response engagements for clients, working as part of a collaborative team. Day-to-day responsibilities include conducting investigations, supporting containment strategies, advising on attacker behaviour and risk, producing client reports, and

Incident Response Consultant, Cyber Security

The Role This position involves leading and supporting incident response engagements for client organisations, conducting forensic analysis, threat hunting, and malware triage. Consultants help clients navigate complex, high-profile security incidents through investigation, containment, remediation, and crisis management, reducing business risk

Senior Cyber Incident Response Analyst

The Role This position sits within a busy incident response practice, where analysts investigate active cyber incidents, conduct host and network intrusion analysis, perform malware reverse engineering, and carry out digital forensics work. Proactive services such as compromise assessments and

Cyber Incident Response Analist

The Role This position focuses on responding to active cyber incidents, conducting forensic analysis of digital artefacts, and detecting threats before they escalate. Day to day work involves investigating attacks carried out by sophisticated advanced persistent threat groups and supporting

Lead Consultant – Incident Response (CPX)

The Role This position leads complex incident response engagements across both operational technology and IT environments, spanning sectors such as energy, utilities, and oil and gas. Day-to-day work includes threat hunting, forensic investigations, industrial protocol analysis, evidence acquisition, and delivering

Principal Consultant, Incident Response

The Role This position leads client-facing incident response engagements from initial scoping through to resolution, conducting host-based forensic analysis across Windows, Linux, and macOS environments, examining log sources including firewalls and databases, and guiding organisations through containment and long-term remediation

Staff Cybersecurity Specialist – Incident Response (f/m/x)

The Role This senior individual contributor position centres on leading end-to-end incident response engagements, from initial investigation through to recovery, working directly with customers during active cyber incidents. The position also involves mentoring less experienced responders and contributing to broader

Principal Consultant, DFIR, Reactive Services (Unit 42)

The Role This position involves leading and managing incident response engagements on a reactive basis, conducting host-based forensic analysis across Windows, Linux, and macOS environments, examining diverse log sources to uncover malicious activity, investigating data breaches, and providing clients with

Senior Cyber Incident Response Analyst (Cape Town or Johannesburg)

The Role This position involves responding to active cyber incidents, conducting host and network intrusion analysis, performing digital forensics, and hunting for threats within client environments. The analyst also delivers proactive services such as compromise assessments, malware reverse engineering, and

DFIR Specialist

The Role This position sits within a cybersecurity team focused on defending a defence organisation against real-world threats. Day to day, the specialist investigates security incidents, performs memory and host-based forensic analysis, conducts threat hunting across internal and external sources,

Lead Engineer – Digital Forensics & Incident Response (Cyber Security Office)

The Role This position leads the investigation and management of cybersecurity incidents across cloud, on-premise, and hybrid environments. Day-to-day responsibilities include log analysis, threat containment, stakeholder coordination, report writing, post-incident reviews, and maintaining incident response playbooks, with rotational on-call duties

Principal Consultant, DFIR, Reactive Services (Unit 42)

The Role This position involves leading and managing incident response engagements on a reactive basis, conducting host-based forensic analysis across Windows, Linux, and macOS environments, examining diverse log sources to uncover malicious activity, investigating data breaches, and advising clients on

Senior Associate/Cybersecurity & Incident Response (Forensic Services practice)

The Role This position involves conducting security and privacy investigations, including breach detection, threat analysis, incident response, and malware analysis. Day to day, practitioners perform digital forensic analysis, support criminal matters in collaboration with law enforcement, and prepare clear communications

Cyber Response, Senior Associate / Assistant Manager

The Role This position sits within a cyber incident response team, focusing on investigating breaches such as ransomware and business email compromise. Day-to-day work spans digital forensics, log analysis, root-cause investigation, and supporting clients through containment and recovery, with outputs

Associate Principal Incident Responder

The Role This position leads and coordinates incident response engagements across the APAC region, investigating high-impact security incidents within operational technology environments. Day to day involves determining root cause, assessing operational impact, driving containment and recovery, and advising customers through

Staff Incident Response Analyst

The Role This hands-on position serves as the senior technical escalation point for L2 SOC analysts and an external MDR partner, handling complex intrusions, cloud forensics, and high-stakes containment decisions. Day-to-day work involves threat hunting in the SIEM, extracting host

Manager, Cyber Defence

The Role This position sits within a specialist cyber defence practice, where the focus is on helping clients protect critical data, systems, and assets. Day to day, the manager leads incident response engagements, supports technical delivery teams, and helps organisations

Information Security Incident Response Analyst

The Role This position sits within a global DFIR team, conducting technical investigations across host, disk, memory, network, and cloud environments. Day to day, the analyst reconstructs attacker timelines, supports clients through containment and recovery, contributes to readiness assessments, and

Cyber Incident Response & Digital Forensics (DFIR), Vice President

The Role This senior cybersecurity position involves supporting a 24×7 cyber operations centre, investigating and triaging security incidents, conducting digital forensic analysis, and communicating findings clearly to both technical and non-technical stakeholders to help strengthen an organisation’s overall security posture.