Cyber Security Incident Manager
SEP2
England
The Role
The successful candidate leads structured incident response engagements, directs analysts during active incidents, and performs hands-on technical work including image handling, malware analysis and deep log review. They also produce post-incident reports, manage customer onboarding into the DFIR service, and participate in an on-call rota alongside SOC operations.
Skills & Experience
Candidates must hold a relevant DFIR certification such as SANS/GIAC and demonstrate proficiency with tools including Velociraptor, FTK Imager, KAPE, Autopsy, Wireshark and sandboxing platforms. SIEM experience across Google SecOps, Splunk or Microsoft Sentinel is required, alongside a strong background in cloud, Linux, Windows and networking environments.
Who It Suits
This role suits a technically confident DFIR practitioner who is equally comfortable managing customer relationships under pressure as performing forensic analysis. Someone methodical, self-motivated and experienced in a customer-facing security environment will thrive, particularly those looking to take a coordination lead within a growing managed DFIR practice.
Typical advertised salary for Incident Response roles in United Kingdom: £53,000–£90,000 (median £70,000 — from 30 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in United Kingdom →
Certifications mentioned: SANS — find training for these on the DFIR Training Finder.





