I am recruiting for an experienced Cyber Incident Response Senior Manager to join my client’s growing Cyber Response Services team within its Risk Consulting practice. Cyber security is a significant area of investment and growth for the client, and this is an excellent opportunity for an experienced incident response professional to take on a senior, hands‑on position with a clear path towards broader service line leadership.
The role combines technical incident response and digital forensics with operational leadership, client management and team development. You will lead the response to complex cyber incidents, manage incident response practitioners and case managers, and work closely with senior cyber response leadership.
You will need significant experience handling complex cyber incidents, including ransomware and advanced network intrusions, alongside strong digital forensics capabilities across areas such as disk, memory, network traffic and log analysis.
The Role
As Cyber Incident Response - Senior Manager, you will lead and coordinate responses to complex cyber security incidents on behalf of clients, often during business‑critical situations.
You will be expected to guide organisations through the complete incident response lifecycle, including:
- Initial scoping and triage
- Defining investigation and response objectives
- Evidence identification and preservation
- Containment
- Forensic evidence collection and extraction
- Investigation and forensic analysis
- Eradication
- Recovery
- Post‑incident review and recommendations
You will manage resources and priorities throughout an incident while providing clear, pragmatic advice to senior client stakeholders. When not actively responding to incidents, you will work with clients to develop and improve their internal cyber response capabilities. This may include developing incident response tools, creating and adapting playbooks and runbooks, assessing incident response maturity and facilitating cyber scenario and tabletop exercises. You will also contribute to the continued development of the client's own cyber response capability, including tooling, platforms, operational procedures, laboratory environments, orchestration, team development and delivery efficiency.
Key Responsibilities
- Lead and coordinate complex cyber security incident response engagements.
- Manage responses to incidents including ransomware, data compromise and advanced network intrusions.
- Perform and oversee digital forensic investigations across disk, volatile memory, network traffic, log files and other relevant evidence sources.
- Lead incident response case managers and technical practitioners during rapid-response engagements.
- Maintain a strong understanding of the evolving cyber threat landscape and advise clients on threats relevant to their organisations.
- Support the development of in‑house cyber response and forensic tooling.
- Assess the maturity of clients' incident response capabilities and recommend improvements.
- Help organisations establish or enhance their internal incident response functions.
- Develop incident response plans, procedures, runbooks and playbooks.
- Support and facilitate cyber incident tabletop and scenario exercises.
- Scope and cost cyber response and forensic engagements.
- Take responsibility for project financial management, engagement management and risk management.
- Produce and review high-quality technical and executive‑level deliverables.
- Manage senior client relationships throughout engagements.
- Support bids, proposals and responses to RFPs.
- Mentor and develop junior and mid‑level cyber response practitioners.
- Contribute to the ongoing development of methodologies, tooling and operational processes.
Experience Required
My client is looking for an experienced cyber security professional with a strong background in incident response and digital forensics.
You should have demonstrable experience leading organizations through complex and potentially unstructured cyber incidents, particularly where priorities and investigative objectives need to be established rapidly.
You should be able to demonstrate:
- Significant experience responding to complex cyber security incidents.
- Strong technical competency in digital forensics and incident investigation.
- Experience handling incidents such as ransomware and advanced network intrusions.
- Experience managing or leading rapid‑deployment incident response teams.
- A broad understanding of the cyber threat landscape, attacker techniques and current threat actor activity.
- Strong knowledge of enterprise IT environments, including Windows, Windows Active Directory, Linux and networking technologies.
- Understanding of enterprise Windows security controls.
- Strong knowledge of networking and network security.
- Experience with evidence preservation, forensic acquisition and maintaining evidential integrity.
- Experience preserving cloud‑based evidence and data.
- Experience handling encrypted systems and technologies such as BitLocker, FileVault and/or LUKS.
- Strong stakeholder management and communication skills, including the ability to advise clients during high‑pressure incidents.
- Strong written communication and report‑writing skills.
- Project and engagement management experience.
- The ability to manage multiple concurrent incidents and competing priorities.
- A genuine interest in mentoring and developing junior team members.
Technical Skills
Candidates should have technical proficiency in at least one or more of the following areas:
- Network security, network traffic and log analysis
- Windows forensic investigation
- Linux and/or macOS/Unix operating system forensics
- Advanced memory forensics
- Static and dynamic malware analysis
- Malware reverse engineering
Experience with industry-standard forensic tooling is highly desirable, including:
- X-Ways
- EnCase
- FTK
- Magnet AXIOM / Internet Evidence Finder (IEF)
- TZWorks
- Cellebrite
Relevant professional certifications are also highly desirable.
General Information Security Certifications:
- CISSP – Certified Information Systems Security Professional
- CISM – Certified Information Security Manager
- CISA – Certified Information Systems Auditor
Incident Response Certifications:
- CREST Certified Incident Manager (CCIM)
- GIAC Certified Incident Handler (GCIH)
Digital Forensics / Intrusion Analysis Certifications:
- CREST Certified Registered Intrusion Analyst (CRIA)
- CREST Certified Network Intrusion Analyst (CCNIA)
- CREST Certified Host Intrusion Analyst (CCHIA)
- GIAC Certified Forensic Analyst (GCFA)
- GIAC Network Forensic Analyst (GNFA)
Additional Requirements
Due to the nature of cyber incident response work, candidates must:
- Be willing and able to undertake and obtain UK Security Check (SC) Clearance.
- Be willing to participate in an on‑call rota.
- Be flexible regarding working hours when responding to critical incidents.
- Be prepared to travel at short notice.
- Be comfortable with occasional assignments requiring travel for periods of up to 2–3 weeks.
This is an opportunity to join a growing cyber response capability in a genuinely senior position while remaining closely involved in complex technical investigations. The role offers exposure to major cyber incidents, sophisticated threat activity and senior client stakeholders, alongside the opportunity to shape incident response methodologies, tooling and team capability.
For someone with a strong technical background who is ready to combine hands‑on cyber incident response with team and operational leadership, the position provides a clear opportunity to develop towards senior cyber response and service line leadership.
#J-18808-Ljbffr
Cyber Incident Response - Senior Manager employer: LT Harper Recruitment Group
Join a dynamic and innovative risk and resilience consultancy that prioritises employee growth and development, offering a collaborative remote work environment. As a Crisis and Event Response Lead, you will have the opportunity to shape critical organisational responses while benefiting from a culture that values expertise and encourages open communication. With competitive daily rates and a focus on meaningful impact, this role is perfect for those looking to make a significant difference in crisis management.
Contact Details:
LT Harper Recruitment Group Recruitment Team