Remote Incident Response & Digital Forensics Analyst

Remote Incident Response & Digital Forensics Analyst

Full-Time 50000 - 70000 £ / year (est.) No working from home possible
NTT America, Inc.

At a Glance

  • Tasks: Investigate security incidents and analyse digital forensic evidence to support clients.
  • Company: Join NTT DATA, a leader in tech innovation and diversity.
  • Benefits: Remote work, competitive salary, and opportunities for professional growth.
  • Other info: Be part of a global team with excellent career advancement opportunities.
  • Why this job: Make a real impact in cybersecurity while developing advanced skills.
  • Qualifications: Experience in incident response and digital forensics is essential.

The predicted salary is between 50000 - 70000 £ per year.

Make an impact with NTT DATA. Join a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

Job Description Summary

The Information Security Incident Response Analyst supports clients during security incidents by performing technical investigations, analyzing digital forensic evidence, and assisting with containment and remediation activities. This role focuses on identifying indicators of compromise, reconstructing attacker activity, and communicating clear, actionable findings. The analyst works as part of a global DFIR team, handling a variety of incident types across diverse environments. They contribute to process improvements, maintain strong client communication, and continue building advanced DFIR skills through hands‑on investigations and internal project work.

Key Responsibilities

  • Investigates security incidents by performing host, disk, memory, network, and cloud forensic analysis under established processes and guidance.
  • Analyzes artifacts across Windows, Linux, and macOS systems, helping reconstruct timelines and determine root cause.
  • Supports clients through containment and recovery efforts by providing technical recommendations and clear communication.
  • Participates in the team’s on‑call rotation for urgent incident response needs.
  • Completes internal and client tasks such as tabletop exercises, IR readiness assessments, basic forensic reviews, and environment hardening support.
  • Identifies observable gaps and risks within client environments and recommends improvements to strengthen security posture.
  • Produces accurate documentation—including investigation notes, status updates, and final reports.
  • Collaborates with global DFIR and other teams and stays current on threats, attacker techniques, and emerging forensic tools.

Knowledge and Attributes

  • Solid understanding of digital forensics fundamentals, including host‑based analysis across major operating systems.
  • Working knowledge of network forensics, cloud log analysis (e.g., Azure, AWS, GCP), and common forensic tools.
  • Ability to clearly communicate technical findings to both technical and non‑technical audiences.
  • Strong analytical and problem‑solving skills, especially during time‑sensitive investigations.
  • Motivated to continuously learn deeper DFIR techniques and methodologies.

Required Experience

  • Proven experience in incident response and digital forensics, with capability in host‑based, image, and log analysis.
  • Experience using SIEM, EDR, IDS/IPS, and other security tools to triage, investigate, and respond to incidents.
  • Ability to perform network analysis using tools such as Wireshark, tcpdump, and other tools.
  • Experience in cybersecurity operations, consulting, DFIR services, or related technical security roles.

Academic Qualifications, Certifications

  • Bachelor’s degree or equivalent experience in Information Technology, Computer Science, Cybersecurity, or a related discipline (preferred).
  • Relevant cybersecurity certifications such as:
    • SANS GIAC Security Essentials (GSEC) or equivalent preferred.
    • SANS GIAC Certified Intrusion Analyst (GCIA) or equivalent preferred.
    • SANS GIAC Certified Incident Handler (GCIH) or equivalent preferred.
    • Additional DFIR‑related certifications are considered a plus.

Additional UK‑Specific Role Requirements

  • Active UK Security Clearance is required to deliver services within sensitive or regulated client environments.

Operational Technology (OT) Incident Response & Digital Forensics

  • Background and hands‑on experience in OT environments.
  • Experience investigating ICS/SCADA systems and industrial sectors such as manufacturing, energy, utilities, or critical infrastructure.
  • Ability to collect and analyze OT forensic artifacts, interpret OT protocols and system behavior, and assess the impact of cyber incidents on physical processes.
  • Certifications SANS OT/ICS certifications such as GICSP or GRID, IEC 62443 or equivalent required.

Workplace type: Remote Working

NTT DATA is a $30+ billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world’s leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is part of NTT Group, which invests over $3 billion each year in R&D.

Equal Opportunity Employer

NTT DATA is proud to be an Equal Opportunity Employer with a global culture that embraces diversity. We are committed to providing an environment free of unfair discrimination and harassment. We do not discriminate based on age, race, colour, gender, sexual orientation, religion, nationality, disability, pregnancy, marital status, veteran status, or any other protected category. Join our growing global team and accelerate your career with us. Apply today.

Third parties fraudulently posing as NTT DATA recruiters

NTT DATA recruiters will never ask job seekers or candidates for payment or banking information during the recruitment process, for any reason. Please remain vigilant of third parties who may attempt to impersonate NTT DATA recruiters—whether in writing or by phone—in order to deceptively obtain personal data or money from you. All email communications from an NTT DATA recruiter will come from an @nttdata.com email address. If you suspect any fraudulent activity, please contact us (global.careers@nttdata.com).

Remote Incident Response & Digital Forensics Analyst employer: NTT America, Inc.

At NTT DATA, we pride ourselves on being a global leader in technology services, offering a dynamic and inclusive work environment where innovation thrives. As a Remote Incident Response & Digital Forensics Analyst, you will have the opportunity to work with cutting-edge technologies while contributing to meaningful projects that impact clients and society. Our commitment to employee growth is reflected in our extensive training programs and collaborative culture, ensuring you can develop your skills and advance your career in a supportive setting.

NTT America, Inc.

Contact Details:

NTT America, Inc. Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Remote Incident Response & Digital Forensics Analyst

Tip Number 1

Network like a pro! Reach out to folks in the industry, join relevant online forums, and attend virtual meetups. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your skills! Create a portfolio showcasing your incident response and digital forensics projects. This could be anything from case studies to personal projects that demonstrate your expertise. It’s a great way to stand out!

Tip Number 3

Prepare for interviews by brushing up on common technical questions and scenarios related to digital forensics. Practice explaining your thought process clearly, as communication is key in this field. We want to see how you tackle problems!

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at NTT DATA.

We think you need these skills to ace Remote Incident Response & Digital Forensics Analyst

Digital Forensics
Incident Response
Host-Based Analysis
Network Forensics
Cloud Log Analysis
SIEM
EDR

Some tips for your application 🫡

Tailor Your CV:Make sure your CV reflects the skills and experiences that match the job description. Highlight your incident response and digital forensics experience, and don’t forget to mention any relevant certifications!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about this role and how your background makes you a perfect fit. Keep it concise but impactful.

Showcase Your Technical Skills:In your application, be specific about the tools and technologies you’ve worked with. Mention your experience with SIEM, EDR, and any forensic tools you’re familiar with to catch our attention.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way to ensure your application gets into the right hands and shows us you’re serious about joining our team!

How to prepare for a job interview at NTT America, Inc.

Know Your Forensics Inside Out

Make sure you brush up on your digital forensics fundamentals. Be prepared to discuss host-based analysis across Windows, Linux, and macOS systems. Familiarise yourself with common forensic tools and be ready to explain how you've used them in past incidents.

Communicate Clearly

Since this role involves communicating technical findings to both technical and non-technical audiences, practice explaining complex concepts in simple terms. Think of examples where you've had to break down intricate information for clients or team members.

Show Your Problem-Solving Skills

Prepare to demonstrate your analytical and problem-solving skills, especially in time-sensitive situations. Have a few examples ready where you successfully navigated a challenging incident response scenario, highlighting your thought process and the outcome.

Stay Current on Threats

Keep yourself updated on the latest threats, attacker techniques, and emerging forensic tools. Mention any recent trends or incidents you've followed, and be ready to discuss how they might impact the role you're applying for.