Cyber Incident Responder in Manchester

Cyber Incident Responder in Manchester

Manchester Full-Time On-site
Cyfor Secure

CYBER INCIDENT RESPONDER

Salary: Depending on experience

Location: Remote

The Role

Due to our continued growth, we are looking for an experienced Cyber Incident Responder to add to the CYFOR Secure team.

The ideal candidate will have at least 3 years' experience investigating cyber incidents, with hands-on experience of the incident types we see most: ransomware, business email compromise and Microsoft 365 account compromise, and web application compromise. You\'ll be comfortable working in client environments you don\'t control, often alongside the client\'s MSP or hosting provider, and able to explain findings clearly to clients, insurers and legal advisers. You\'ll also be able to demonstrate flexibility, commitment and integrity.

This role is primarily focused on incident response investigations. You will also support remote and onsite business recovery, compromise assessments and other proactive work when required.

In return, you\'ll receive a salary commensurate with experience; plus training, overtime and excellent career prospects. You\'ll enjoy a varied and highly fulfilling role, working with great colleagues in a fantastic atmosphere.

This is a unique opportunity to join a highly successful business that truly focuses on its main asset, its team members.

Security Clearance

Please note that this role will require NPPV3 clearance in addition to National security clearance to SC level. Applicants MUST have been continuously resident in the United Kingdom for the last 5 years. If you do not hold an active SC clearance, please familiarise yourself with the vetting process before applying.

Main Responsibilities

  • Deliver emergency incident response engagements from first contact through containment, eradication and recovery, including credential resets, host isolation, EDR deployment and persistence removal.
  • Lead and own incidents end to end without day-to-day senior support, setting investigative and containment direction, making decisions under pressure and escalating only where commercial or legal judgement is needed.
  • Investigate Microsoft 365 and Entra ID compromise, including business email compromise, malicious mailbox rules, token and OAuth abuse, using unified audit logs, sign-in logs, Purview and eDiscovery.
  • Investigate ransomware and hands-on-keyboard intrusions across Windows and Linux estates to establish initial access, lateral movement, privilege escalation, persistence and the systems and data affected, including abuse of remote management (RMM) tooling.
  • Investigate web application and e-commerce compromise, including web shells and payment page script injection, working with hosting providers to obtain the logs and images needed.
  • Collect and preserve evidence using remote triage collection, targeted acquisition and full imaging where justified, maintaining continuity and evidential integrity in line with ISO/IEC 17025 and the FSR Code of Practice.
  • Analyse artefacts with tools such as Magnet AXIOM and command-line tooling, and correlate firewall, VPN, EDR, authentication and cloud audit logs into a defensible timeline.
  • Deploy and use EDR (SentinelOne) during engagements for visibility, containment and threat hunting, and confirm agent coverage across affected hosts.
  • Plan and carry out containment strategies suited to the client\'s environment and business priorities, weighing the impact of isolation, credential resets and service shutdowns against the risk of further compromise.
  • Work alongside the client\'s MSP or hosting provider during containment and remediation: agree actions, maintain a shared remediation tracker, and check that recommended actions have been completed before the client is told the environment is safe.
  • Own the remediation action tracker for each engagement, assigning actions to the client, MSP and third parties, chasing progress and reporting status until every action is closed and verified.
  • Provide regular, concise updates to clients, insurers, loss adjusters and breach counsel covering findings, risk, containment status, client actions and next steps.
  • Write investigation reports, timelines, executive summaries and indicators of compromise in CYFOR\'s report templates, clearly separating what the evidence shows from what is inferred, and supporting the client\'s data protection notification decisions.
  • Support recovery and rebuild work with our business recovery partners, including restoration from backup, Active Directory hardening, segmentation recommendations and validation of a clean environment.
  • Help scope new engagements by identifying the evidence and access required and giving realistic time estimates for each phase.
  • Support the delivery of compromise assessments and threat hunting engagements as these services grow.
  • Travel at short notice for onsite response, evidence collection and recovery support.
  • Feed lessons from engagements back into playbooks, collection lists and report templates, and share knowledge across the team.

Skills and Experience

  • Minimum 3 years\' hands-on experience in cyber incident response and digital forensics.
  • Proven investigation experience in Microsoft 365 and Entra ID, including audit log, sign-in log and mailbox analysis.
  • Experience investigating ransomware or other hands-on-keyboard intrusions in Windows Active Directory environments.
  • Demonstrable experience leading incidents as the primary responder, with the confidence to take ownership, make containment decisions and direct client and MSP teams without supervision.
  • Experience planning and executing containment strategies, and driving remediation to completion through an action tracker.
  • Experience collecting forensic evidence from live and compromised systems, including remote triage collection.
  • Working knowledge of Linux, both as an analysis platform and as a compromised host to investigate.
  • Ability to correlate events from multiple log sources into an accurate incident timeline.
  • Good understanding of MITRE ATT&CK and common threat actor techniques.
  • Experience using EDR platforms during incident response.
  • Clear, accurate report writing that stands up to scrutiny from insurers and legal advisers.
  • Confidence communicating with clients under pressure, and with insurers, MSPs and legal advisers.
  • Ability to manage several live engagements at once and keep actions and case records up to date.
  • An investigative mindset with a high level of attention to detail.
  • Willingness to work out of hours during live incidents.
  • Ability to exercise discretion and confidentiality.

Desirable Skills

  • Incident response certifications such as CREST Registered Intrusion Analyst, GCFA or GCIH.
  • Experience working with cyber insurers, breach counsel or loss adjusters on incident response engagements.
  • Experience with Microsoft Purview, eDiscovery and Defender.
  • Experience with Magnet AXIOM, KAPE and timeline analysis tooling.
  • Experience investigating web servers (IIS, Apache, nginx), including web shells and card skimming scripts.
  • Knowledge of RMM platforms (e.g. N-able, Kaseya) and how threat actors abuse them.
  • Experience with virtualisation (VMware, Hyper-V) and backup systems (e.g. Veeam), including restoration.
  • Experience with cloud and hosted environments (Azure, AWS and smaller hosting providers).
  • Experience with firewalls, VPNs and network logs.
  • Basic malware triage to extract indicators of compromise.
  • Scripting in PowerShell or Python to automate collection and analysis.

Benefits

  • Flexible working
  • Company pension scheme (3% employer contribution)
  • 24 Days annual holiday plus Bank holidays
  • Extra day\'s holiday for your birthday
  • Annual holiday loyalty bonus (increasing to 30 days after 3 years)
  • MediCash Cashplan

Job Type: Full-time

Pay: Β£50,000.00-Β£60,000.00 per year

Benefits:

  • Additional leave
  • Casual dress
  • Company events
  • Company pension
  • Cycle to work scheme
  • Discounted or free food
  • Free flu jabs
  • Free parking
  • Life insurance
  • On-site parking
  • Work from home

Application question(s):

  • Describe an incident you led end to end without senior support. What was it, what containment did you put in place, and what was the outcome? (150 words max)
  • Walk us through how you would investigate a suspected business email compromise in Microsoft 365. Which logs would you pull first, and what would you look for?
  • A client\'s MSP tells you remediation is complete after a ransomware incident. How would you verify that before telling the client they are safe?
  • How have you tracked and driven remediation actions across a client, their MSP and third parties? Which tools or formats did you use?
  • Which forensic and triage tools have you used in live engagements?
  • Permanently Resident in United Kingdom for last 5 years?

Experience:

  • Cyber Incident Response: 2 years (required)

Work authorisation:

  • United Kingdom (required)

Work Location: Hybrid remote in Manchester M24 1SW

#J-18808-Ljbffr

Cyfor Secure

Contact Details:

Cyfor Secure Recruitment Team