Senior Digital Forensics and Incident Response Consultant in London

Senior Digital Forensics and Incident Response Consultant in London

London Full-Time No working from home possible
NTT DATA

We\'re a business with a global reach that empowers local teams, and we undertake hugely exciting work that is genuinely changing the world. Our advanced portfolio of consulting, applications, business process, cloud, and infrastructure services will allow you to achieve great things by working with brilliant colleagues, and clients, on exciting projects.

Our inclusive work environment prioritises mutual respect, accountability, and continuous learning for all our people. This approach fosters collaboration, well-being, growth, and agility, leading to a more diverse, innovative, and competitive organisation. We are also proud to share that we have a range of Inclusion Networks such as: the Women\'s Business Network, Cultural and Ethnicity Network, LGBTQ+ & Allies Network, Neurodiversity Network and the Parent Network.

For more information on Diversity, Equity and Inclusion please click here: Creating Inclusion Together at NTT DATA UK | NTT DATA

KEY RESPONSIBILITIES

Advanced Digital Forensic Investigations

  • Lead complex digital forensic investigations across Windows, Linux, macOS, mobile, and cloud platforms
  • Conduct advanced disk, memory, network, and malware forensic analysis with minimal supervision
  • Perform forensically sound evidence acquisition from diverse systems and environments
  • Analyze complex attack chains, lateral movement, and advanced persistent threat activities
  • Reconstruct incident timelines and attacker methodologies from forensic artifacts
  • Provide expert forensic analysis for legal proceedings, regulatory investigations, and internal reviews

Incident Response Leadership

  • Lead major incident response engagements for sophisticated cyber attacks and data breaches
  • Coordinate multi-team incident response activities across technical, legal, and business stakeholders
  • Perform advanced threat hunting, containment, eradication, and recovery activities
  • Develop and execute incident response strategies for complex security events
  • Interface with executive leadership, legal counsel, and regulatory bodies during major incidents
  • Conduct post-incident reviews and develop remediation roadmaps

Malware Analysis and Reverse Engineering

  • Conduct static and dynamic malware analysis on sophisticated threats and custom malware
  • Perform reverse engineering of malicious code to understand capabilities and attribution
  • Analyze exploitation techniques, persistence mechanisms, and command and control infrastructure
  • Develop indicators of compromise (IOCs) and detection signatures from malware analysis
  • Document malware behavior, capabilities, and remediation procedures
  • Contribute to threat intelligence with malware analysis findings and IOCs

Cloud and Container Forensics

  • Lead forensic investigations in cloud environments including AWS, Azure, and GCP
  • Conduct container and Kubernetes forensic analysis for cloud-native incidents
  • Analyze cloud logs, API calls, and identity activity for security investigations
  • Perform forensic acquisition and analysis of cloud workloads and serverless environments
  • Investigate cloud-specific attack vectors including misconfigurations and identity compromise
  • Develop cloud forensic methodologies and investigation playbooks

Threat Intelligence and Attribution Analysis

  • Analyze threat actor tactics, techniques, and procedures (TTPs) using MITRE ATT&CK framework
  • Conduct threat attribution analysis based on forensic artifacts and intelligence sources
  • Correlate internal incident data with external threat intelligence feeds
  • Identify advanced persistent threat campaigns and targeted attack patterns
  • Develop tactical and strategic threat intelligence from investigation findings
  • Share threat intelligence with industry partners and information sharing communities

Expert Witness and Legal Support

  • Provide expert witness testimony in legal proceedings and regulatory investigations
  • Prepare forensic reports meeting legal and regulatory evidentiary standards
  • Work with legal teams on e-discovery, litigation support, and regulatory response
  • Maintain chain of custody and forensic integrity throughout investigations
  • Present technical findings to non-technical audiences including courts and regulators
  • Support law enforcement and regulatory agencies with cyber investigations

KEY PERFORMANCE INDICATORS

  • Successful resolution of complex digital forensic investigations with actionable findings
  • Client satisfaction scores for DFIR engagements and incident response leadership (target: 4.5/5.0+)
  • Quality and accuracy of forensic analysis and investigation reports
  • Effective incident containment and recovery with minimal business impact
  • Contribution to DFIR methodologies, tools, and threat intelligence
  • Professional recognition through certifications, speaking engagements, or research publications

Advanced Digital Forensics Expertise

  • Mastery of forensic analysis across multiple operating systems (Windows, Linux, macOS, mobile)
  • Expert knowledge of disk forensics, file system analysis, and data recovery techniques
  • Advanced memory forensics and volatile data analysis capabilities
  • Deep understanding of network forensics and packet analysis for investigations
  • Comprehensive knowledge of cloud forensics and container investigation techniques

Forensic Tools and Platforms

  • Forensic suites: EnCase, FTK, X-Ways Forensics, Autopsy, SIFT Workstation
  • Memory forensics: Volatility, Rekall, WinDbg, memory imaging tools
  • Network forensics: Wireshark, NetworkMiner, Zeek, tcpdump, packet analysis
  • Malware analysis: IDA Pro, Ghidra, OllyDbg, x64dbg, Cuckoo Sandbox, REMnux
  • Mobile forensics: Cellebrite, Magnet AXIOM, iOS and Android forensic tools

Incident Response and Threat Hunting

  • EDR platforms: CrowdStrike Falcon, Carbon Black, Microsoft Defender, SentinelOne
  • SIEM and logging: Splunk, ELK Stack, Azure Sentinel, log analysis and correlation
  • Threat hunting: YARA rules, Sigma rules, threat hunting frameworks and methodologies
  • IR tools: Velociraptor, KAPE, GRR Rapid Response, PowerShell forensics
  • Cloud forensics: AWS CloudTrail, Azure Monitor, GCP Cloud Logging, cloud IR tools

Technical Knowledge Areas

  • Operating systems: Deep Windows internals, Linux forensics, macOS artifacts, registry analysis
  • File systems: NTFS, ext4, APFS, FAT, artifact analysis and timeline reconstruction
  • Networking: TCP/IP, network protocols, proxy logs, firewall analysis
  • Malware techniques: Packing, obfuscation, anti-analysis, persistence mechanisms
  • Cloud platforms: AWS, Azure, GCP architecture and forensic artifact locations

Incident Management and Communication

  • Senior-level communication with executives, legal teams, and regulatory bodies
  • Crisis management and calm leadership during high-pressure security incidents
  • Ability to translate complex technical findings into business impact assessments
  • Coordination of cross-functional teams during major incident response
  • Presentation skills for delivering findings to diverse stakeholder audiences

Professional Skills

  • Independent problem-solving for complex and novel forensic challenges
  • Analytical thinking and attention to detail in evidence analysis
  • Calm and methodical approach during high-stress incident response situations
  • Strong written communication for forensic reports and legal documentation
  • Mentoring and knowledge
NTT DATA

Contact Details:

NTT DATA Recruitment Team