Incident Response Lead (DFIR)

Incident Response Lead (DFIR)

Full-Time No working from home possible
L

Incident Response Lead (DFIR) - Hybrid - Can be based anywhere in the UK - Up to Β£110k The opportunity: Do you want to lead the response to incidents that matter nationally? A Cyber Consultancy is looking for an Incident Response Lead to join its Cyber Response Services team, reporting directly to the head of cyber response. This is a hands-on operational leadership role with a clear route into service line leadership. The team cover industries such as government, critical infrastructure and large enterprise, from ransomware through to advanced network intrusions. You will lead case managers and practitioners, stay technical in the forensics, and have a real say in how the practice grows. Your benefits: Up to Β£110k salary Funded certifications and a structured training programme Exposure to nationally significant incidents across government and CNI Defined progression into senior leadership of a fast-growing capability Hybrid working from London or Manchester hubs Pension contribution and private healthcare [confirm] Your responsibilities as an Incident Response Lead will be to: Manage and coordinate a portfolio of cyber security incidents for clients, working closely with the head of cyber response Lead a team of case managers and practitioners through the full incident lifecycle: scoping, triage, containment, evidence preservation, eradication and recovery Carry out and quality-assure digital forensics on disk, volatile memory, network traffic and log data Own the commercial side of engagements, including scoping, costing, financial management and risk Help clients stand up or mature their own IR capability through playbooks, maturity assessments and tabletop exercises Drive the development of in-house cyber response tooling, lab environments and operating procedures Mentor junior team members and shape the team's learning and development Contribute to bids and proposals, and maintain a current view of the threat landscape for clients Take part in an on-call rotation and be ready to travel at short notice, sometimes for two to three weeks at a time As an Incident Response Lead you will ideally have: Significant experience managing complex cyber security incidents end to end, including leading a rapid deployment incident response team Strong digital forensics competency, with advanced experience of tools such as X-Ways, EnCase, FTK, AXIOM/IEF or Cellebrite, and of preserving cloud data and encrypted evidence Technical depth in at least one of network and log analysis, Linux or Mac forensics, memory forensics, malware reverse engineering or mobile forensics A working programming skillset (Python preferred) and solid knowledge of enterprise Windows, Active Directory and Linux environments Excellent written and verbal communication, with the ability to guide senior non-technical stakeholders through a live incident Certifications such as CCIM, GCIH, CRIA, CCNIA, CCHIA, GCFA or GNFA are highly desirable, as are CISSP, CISM or CISA Current SC or DV clearance, or eligibility and willingness to obtain it If you are interested in this role, please contact me at c.burn@ltharper.com

Incident Response Lead (DFIR) employer: LT Harper Recruitment Group

Join a dynamic and innovative risk and resilience consultancy that prioritises employee growth and development, offering a collaborative remote work environment. As a Crisis and Event Response Lead, you will have the opportunity to shape critical organisational responses while benefiting from a culture that values expertise and encourages open communication. With competitive daily rates and a focus on meaningful impact, this role is perfect for those looking to make a significant difference in crisis management.

L

Contact Details:

LT Harper Recruitment Group Recruitment Team