Senior Incident Response Consultant, Mandiant (Weekend team)
United Kingdom
The Role
Operating on a Friday-to-Monday, 10-hour shift pattern, the consultant leads complex incident response engagements for clients, examining cloud, endpoint, and network evidence sources, identifying attacker TTPs and IOCs, building investigative tooling, and delivering clear technical and executive-level reports under tight deadlines.
Skills & Experience
Candidates need at least five years of end-to-end IR experience alongside network, cloud, disk, and memory forensics skills. Linux/Unix proficiency is required. Preferred certifications include GCFA, GCFE, GNFA, GCIA, GREM, or GCIH, with cloud platform certifications also valued. CTF experience is a plus.
Who It Suits
This role suits a seasoned incident responder comfortable leading high-pressure, client-facing engagements and communicating findings to both technical teams and executive leadership. Those who thrive in structured shift environments and enjoy mentoring junior colleagues will find the format particularly well suited to them.
Typical advertised salary for Incident Response roles in United Kingdom: £53,000–£90,000 (median £70,000 — from 30 recent listings analysed by Forensic Focus).
Compare Incident Response salaries in United Kingdom →
Certifications mentioned: GCFA · GCFE · GREM · GNFA · GCIH — find training for these on the DFIR Training Finder.





