INCIDENT RESPONSE LEAD, DFIR (UK)
Asymmetric Security
London, England
The Role
This position leads complex digital forensic investigations day to day, spanning business email compromise, ransomware, network intrusions, and insider threats, with an initial emphasis on cloud email environments across Google and Microsoft platforms. The analyst builds defensible timelines, uncovers novel attack paths, and collaborates with an engineering team to develop AI-assisted investigative tooling.
Skills & Experience
Candidates require substantial hands-on incident response experience, particularly across cloud and email platforms. Familiarity with log analysis, forensic methodology, and building evidential timelines is essential. Experience working within or alongside engineering teams to shape tooling, and the ability to document and codify investigative best practices, are also expected.
Who It Suits
This role suits a technically accomplished DFIR practitioner who is comfortable leading investigations independently and wants genuine influence over how the discipline evolves. It appeals to someone eager to work at the intersection of traditional forensics and emerging AI capabilities, in a founding-team environment carrying meaningful responsibility.
Typical advertised salary for Incident Response roles in United Kingdom: £53,000–£85,000 (median £68,000 — from 24 recent listings analysed by Forensic Focus).
Learn More/Apply





