Cyber Digital Forensics & Incident Response Manager – Inverness

Cyber Digital Forensics & Incident Response Manager – Inverness

Inverness Full-Time 60000 - 80000 £ / year (est.) Home office (partial)
R

At a Glance

  • Tasks: Lead cyber incident response and manage a team of DFIR analysts.
  • Company: Capgemini, a leader in cybersecurity with a focus on innovation.
  • Benefits: Hybrid working, flexible hours, and extensive training opportunities.
  • Other info: Join a supportive community committed to inclusivity and professional growth.
  • Why this job: Make a real impact in cybersecurity while developing your leadership skills.
  • Qualifications: Experience in managing DFIR teams and strong technical expertise in cyber incident response.

The predicted salary is between 60000 - 80000 £ per year.

This is a Hybrid Role Onsite 2-3 Days Per Week. Work location either Manchester or Inverness.

An excellent opportunity has arisen within our Team for a Digital Forensics & Incident Response (DFIR) Manager. DFIR (Digital Forensics and Incident Response) is a specialist cyber security capability responsible for delivering rapid, high-impact incident response and investigation during significant cyber events, such as Malware or Ransomware attacks or Cyber security breaches.

The Digital Forensics and Incident Response Manager is a leadership position within Capgemini’s Cyber Defence Centre’s (CDC’s) team. This role will oversee the DFIR Service, taking responsibility for all aspects of service delivery. The successful candidate will be one of the foremost technical experts for all aspects of cyber incident response, ensuring that the team are suitably trained and that cyber incidents are handled in accordance with the requirements of our clients.

You will manage a team of DFIR analysts and be responsible for the management of the services provided to our clients, ensuring they cover the key contractual deliverables/requirements and that clients are satisfied with the quality and performance of the services.

You will need to demonstrate experience of developing, managing and mentoring a Team and ensuring that appropriate resources are in place to deliver a first-class service, delivering against SLAs and KPIs. You will also need excellent Stakeholder management skills including the ability to translate complex technical threats and vulnerabilities into executive-friendly insights that articulate potential business risks and recommended actions.

Who You’ll Work With

You’ll lead a close-knit team of DFIR analysts within a 24×7 on-call model, Cyber Threat Intelligence (CTI) analysts and collaborate with DFIR, CDC, and client teams. You’ll be surrounded by professionals who are passionate about cybersecurity and committed.

Your role

  • Lead and coordinate end-to-end cyber incident response activities, ensuring effective containment, eradication, and recovery during high-severity incidents.
  • Oversee and perform digital forensic investigations, including evidence collection, preservation, and analysis across endpoint and cloud-based environments.
  • Own the delivery of incident reporting and executive briefings, translating technical findings into business risk and actionable recommendations.
  • Establish and maintain DFIR processes, playbooks, and runbooks, ensuring alignment with recognised standards such as NCSC CIR.
  • Lead, mentor, and manage a team of DFIR analysts, ensuring operational readiness, on-call coverage, and delivery against SLAs and KPIs.

You can bring your whole self to work. At Capgemini, building an inclusive future is part of everyday life and will be part of your working reality. We have built a representative and welcoming environment for everyone.

Your skills and experience

  • Experienced in managing a distributed team of DFIR specialists and related technical teams.
  • Strong experience leading cyber incident response, managing high-severity incidents and coordinating technical and stakeholder response.
  • Hands-on expertise in digital forensics, including evidence collection and analysis across endpoint and cloud environments (e.g. AWS, Azure).
  • Ability to deliver clear incident reports and executive briefings, translating technical findings into business impact and actions.
  • Experience developing and improving DFIR processes and playbooks, aligned to recognised frameworks such as NCSC CIR.
  • Relevant industry certifications such as CREST (CPIA/CRIA) or SANS (GCIA, GCIH, GCFA).

Capgemini is proud to be a Disability Confident Employer (Level 2) under the UK Government’s Disability Confident scheme. As part of our commitment to inclusive recruitment, we will offer an interview to all candidates who declare they have a disability and meet the minimum essential criteria for the role.

Your security clearance and pre-employment checks

If you are successfully offered this position, you will go through a series of pre-employment checks, including identity, nationality (single or dual) or immigration status, employment history going back 3 continuous years, and unspent criminal record check (known as Disclosure and Barring Service). Some roles will also require an additional level of security clearance: Security Check (SC) Clearance.

Make it real – what does it mean for you?

Flexibility to work your way

You will be encouraged to have a positive work-life balance. Our hybrid-first way of working means we embed hybrid working in all that we do and make flexible working arrangements the day-to-day reality for our people. All UK employees are eligible to request flexible working arrangements.

Your wellbeing

You’d be joining an accredited Great Place to work for Wellbeing in 2024. Employee wellbeing is vitally important to us as an organisation. We see a healthy and happy workforce as a critical component for us to achieve our organisational ambitions.

Shape your path

You will be empowered to explore, innovate, and progress. You will benefit from Capgemini’s ‘learning for life’ mindset, meaning you will have countless training and development opportunities from think tanks to hackathons, and access to 250,000 courses with numerous external certifications from AWS, Microsoft, Harvard ManageMentor, Cybersecurity qualifications and much more.

Shared energy

You’ll be bringing your unique skills and perspectives to the team, inspiring and taking inspiration from your teammates as you unlock value in everything you do. You’ll be joining a professional community of experts, who have got your back and will support you every step of the way.

Cyber Digital Forensics & Incident Response Manager – Inverness employer: Recruit4Mum

Capgemini is an exceptional employer, offering a dynamic work culture that prioritises flexibility and employee wellbeing. With a strong commitment to professional development, employees have access to extensive training opportunities and a supportive environment that fosters innovation and collaboration. Located in Inverness, this role not only allows you to lead a passionate team in the critical field of cybersecurity but also provides a chance to make a meaningful impact while enjoying a healthy work-life balance.

R

Contact Details:

Recruit4Mum Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Cyber Digital Forensics & Incident Response Manager – Inverness

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Recruit4Mum, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through Recruit4Mum

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Recruit4Mum. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Cyber Digital Forensics & Incident Response Manager – Inverness

Digital Forensics
Incident Response
Team Management
Stakeholder Management
Evidence Collection
Cloud Environments (e.g. AWS, Azure)
Incident Reporting

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Recruit4Mum insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Recruit4Mum that you’re committed to staying ahead in the game.

How to prepare for a job interview at Recruit4Mum

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at Recruit4Mum to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Recruit4Mum.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.