At a Glance
- Tasks: Conduct forensic investigations on computers, mobile devices, and cloud platforms to uncover digital evidence.
- Company: Join CYFOR, a leading firm in cyber security with a focus on team collaboration.
- Benefits: Enjoy competitive salary, generous holiday bonuses, and a supportive work environment.
- Other info: Flexible working options and opportunities for professional growth in a thriving company.
- Why this job: Make a real impact in cyber security while developing your skills in a dynamic role.
- Qualifications: 3+ years in digital forensics, strong analytical skills, and experience with forensic tools.
The predicted salary is between 50000 - 60000 ÂŁ per year.
Location: Remote (Hybrid)
The Role
Due to our continued growth, we are looking for an experienced Corporate Forensic Analyst to join the CYFOR Secure Incident Response team. The successful candidate will primarily focus on corporate forensic investigations involving dead‑box analysis across computers, mobile devices, cloud platforms and email environments. The role is centred around the forensic investigation and evidential analysis side of cyber security incidents, supporting clients through structured and defensible digital forensic examinations.
You will also work closely with the wider Incident Response team, supporting investigations into business email compromise (BEC), ransomware and other cyber incidents where forensic analysis is required. While the role is not primarily an incident‑response position, there will be opportunities to assist live investigations and support broader response activities where appropriate.
The ideal candidate will have experience conducting forensic examinations across Windows systems, mobile devices and cloud‑based environments, with excellent attention to detail, strong reporting skills and a professional client‑facing approach. You will also demonstrate integrity, flexibility and the ability to manage sensitive investigations with discretion.
In return, you’ll receive a salary commensurate with experience; plus training, overtime and excellent career prospects. You’ll enjoy a varied and highly fulfilling role, working with great colleagues in a fantastic atmosphere. This is a unique opportunity to join a highly successful business that truly focuses on its main asset, its team members.
Main Responsibilities
- Conduct forensic examinations of desktop computers, laptops, servers and mobile devices using forensically sound methodologies.
- Acquire, preserve and analyse digital evidence from Windows systems, mobile devices, cloud platforms and email environments while maintaining evidential integrity.
- Perform dead‑box forensic investigations involving deleted data recovery, user activity analysis, timeline reconstruction and artefact examination.
- Investigate cloud and email platforms including Microsoft 365, Exchange Online and associated audit logs to identify suspicious or malicious activity.
- Support investigations into ransomware, business email compromise (BEC), insider threats, data theft and unauthorised access incidents.
- Use forensic and case management tooling including Magnet Axiom and Salesforce throughout investigations and evidence handling workflows.
- Produce high‑quality forensic reports suitable for internal stakeholders, legal teams, law enforcement and corporate clients.
- Assist with expert witness statements and provide court attendance when required.
- Support the Incident Response team during active cyber incidents where forensic expertise is required.
- Maintain accurate chain of custody documentation and evidence handling procedures throughout investigations.
- Deliver clear and concise updates to clients and stakeholders throughout engagements.
- Assist with forensic triage and evidence collection during onsite and remote engagements when required.
- Contribute to the continuous improvement of forensic methodologies, processes and internal capabilities.
- Keep up to date with emerging threats, forensic techniques and evolving technologies across endpoint, mobile and cloud ecosystems.
- Support knowledge sharing and mentoring activities across the wider team where appropriate.
Skills and Experience
- Minimum 3 years’ experience in digital forensics or cyber investigations.
- Experience conducting dead‑box forensic investigations across Windows systems and mobile devices.
- Experience collecting, preserving and analysing digital evidence using industry‑standard forensic methodologies.
- Experience using Magnet Axiom, Encase or X-Ways and other digital forensic tooling.
- Knowledge of Microsoft 365, Exchange Online and cloud‑based investigations.
- Ability to analyse forensic artefacts and reconstruct user and system activity timelines.
- Understanding of ransomware and business email compromise investigations.
- Experience producing detailed technical and client‑facing forensic reports.
- Excellent written and verbal communication skills.
- Strong attention to detail and investigative mindset.
- Ability to handle sensitive and confidential investigations professionally.
- Excellent client‑facing skills with the ability to communicate effectively at all levels.
- Ability to work independently and manage multiple investigations simultaneously.
- Demonstrate a flexible approach to work and a high level of self‑motivation.
- Ability to travel occasionally where required for onsite forensic collections or client support.
- Experience with cloud forensic investigations involving Microsoft Azure or AWS.
- Previous experience supporting cyber incident response investigations.
- Experience with email header analysis and phishing investigations.
- Knowledge of forensic acquisition methodologies for Apple and Android devices.
- Experience with forensic scripting or automation using PowerShell or Python.
- Understanding of evidential procedures and legal requirements relating to digital evidence.
- Previous experience providing expert witness statements or attending court proceedings.
- Relevant certifications such as GCFA, GCFE, CCE, CFCE or equivalent digital forensic qualifications.
- Experience working within corporate, legal or law enforcement investigation environments.
Benefits
- Company pension scheme (3% employer contribution).
- Extra day’s holiday for your birthday.
- Annual holiday loyalty bonus (increasing to 30 days after 3 years).
- MediCash Cashplan.
- Life Assurance (Death in Service).
- Annual Media Subscriptions (from a choice of Netflix HD, Amazon Prime, etc).
- An annual anniversary gift, rising in value each year.
- Loyalty bonuses: 3 years – £300, 5 years – £500, 10 years – £1,000.
- Multiple free social events throughout the year, including a CYFOR Family Day.
- Free month‑end lunches.
Security Clearance
Please note that this role may require National Security Vetting to SC level depending on client requirements. Applicants may be required to undergo background screening and vetting checks where necessary.
Corporate Forensic Analyst in London employer: CYFOR group
Contact Detail:
CYFOR group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Corporate Forensic Analyst in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the cyber security field, attend industry events, and join relevant online forums. You never know who might have a lead on your next Corporate Forensic Analyst role!
✨Tip Number 2
Show off your skills! Create a portfolio showcasing your forensic investigations, reports, and any relevant projects. This will give potential employers a taste of what you can bring to the table.
✨Tip Number 3
Prepare for interviews by brushing up on common forensic scenarios and case studies. Be ready to discuss your experience with tools like Magnet Axiom and how you've handled sensitive investigations in the past.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are proactive about their job search!
We think you need these skills to ace Corporate Forensic Analyst in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Corporate Forensic Analyst role. Highlight your experience with digital forensics, especially any work with Windows systems and mobile devices. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about forensic investigations and how your background makes you a great fit for our team. Keep it professional but let your personality show through.
Showcase Your Reporting Skills: Since strong reporting skills are key for this role, include examples of reports you've produced in the past. We love seeing clear, concise communication, so make sure to highlight your ability to convey complex information effectively.
Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our fantastic team!
How to prepare for a job interview at CYFOR group
✨Know Your Forensic Tools
Make sure you’re well-versed in the forensic tools mentioned in the job description, like Magnet Axiom and Encase. Be ready to discuss your experience with these tools and how you've used them in past investigations.
✨Showcase Your Attention to Detail
As a Corporate Forensic Analyst, attention to detail is crucial. Prepare examples from your previous work where your meticulous nature helped uncover important evidence or led to successful investigations.
✨Prepare for Technical Questions
Expect technical questions related to dead-box analysis, cloud investigations, and evidential procedures. Brush up on your knowledge of Microsoft 365 and Exchange Online, and be ready to explain your approach to analysing digital evidence.
✨Demonstrate Client-Facing Skills
Since this role involves communicating with clients and stakeholders, practice articulating complex forensic findings in a clear and concise manner. Think of scenarios where you’ve had to explain technical details to non-technical audiences.