1 to 25 of 26 Forensic Analysis Jobs in the UK

Digital Forensics Unit Project Lead

Hiring Organisation
Reed
Location
Twickenham, Middlesex, England, United Kingdom
Employment Type
Full-Time
Salary
£40,000 per annum, Inc benefits
Digital Forensic Investigator (Part-Time) 1-Year Fixed Term Contract £40,000 30 Hours Per Week (4 Days) Office-Based | Twickenham We're seeking a skilled digital forensics professional to join a specialist investigations team, conducting forensic examinations of digital devices, producing evidential reports, and supporting investigations from … enforcement, government, regulatory, or commercial digital forensics experience who enjoys technically challenging investigations and working to criminal evidential standards. The Role As a Digital Forensic Investigator, you'll be responsible for the forensic capture, preservation, analysis and reporting of digital evidence across a range of investigations. Working ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment, recovery support, forensic analysis, threat hunting and post-incident reviews. The role offers opportunities at both Consultant and Senior Consultant level, depending on your experience. … practical recommendations throughout the incident lifecycle. Key responsibilities include: Supporting cyber incident response engagements from initial triage through investigation, remediation and recovery Conducting digital forensic analysis across endpoints, networks, cloud environments and enterprise platforms Performing root cause analysis and identifying attacker activity, techniques and persistence mechanisms Supporting ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment, recovery support, forensic analysis, threat hunting and post-incident reviews. The role offers opportunities at both Consultant and Senior Consultant level, depending on your experience. … practical recommendations throughout the incident lifecycle. Key responsibilities include: Supporting cyber incident response engagements from initial triage through investigation, remediation and recovery Conducting digital forensic analysis across endpoints, networks, cloud environments and enterprise platforms Performing root cause analysis and identifying attacker activity, techniques and persistence mechanisms Supporting ...

Forensics Consultant

Hiring Organisation
Iceberg
Location
United Kingdom
play a key role in supporting complex client matters from initial evidence collection through to data delivery, acting as a technical expert across forensic workflows and eDiscovery operations. The position offers a varied workload spanning forensic collections, mobile device analysis, data processing, quality assurance, workflow optimisation … technical consulting. Key Responsibilities Perform legally defensible forensic collections across a variety of data sources. Manage digital evidence throughout its lifecycle, ensuring strict chain of custody and forensic best practices. Conduct forensic analysis of computers and mobile devices. Support complex eDiscovery workflows including data processing, loading ...

Senior Director | Digital Forensics & Investigations

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
expert witness – drafting and peer‐reviewing formal statements, preparing expert reports and providing oral evidence in court or arbitration. Leading complex digital forensic investigations across a broad range of devices, data systems and cloud environments. Directing mobile device forensic analysis, including advanced extraction, decryption, and interpretation … messaging data. Conducting forensic imaging, recovery, and analysis in line with industry best practice. Developing methodologies for cloud and hybrid ecosystems, including Microsoft 365, Google Workspace, AWS, Azure, and other SaaS or collaboration platforms. Integrating automation, analytics, and AI‐assisted techniques to enhance accuracy, speed, and defensibility. Mentoring ...

Senior Director | Digital Forensics & Investigations

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
expert witness — drafting and peer reviewing formal statements, preparing expert reports and providing oral evidence in court or arbitration.* Leading complex digital forensic investigations across a broad range of devices, data systems and cloud environments.* Directing mobile device forensic analysis, including advanced extraction, decryption, and interpretation … messaging data.* Conducting forensic imaging, recovery and analysis in line with industry best practice.* Developing methodologies for cloud and hybrid ecosystems, including Microsoft 365, Google Workspace, AWS, Azure, and other SaaS or collaboration platforms.* Integrating automation, analytics, and AI-assisted techniques to enhance accuracy, speed and defensibility.* Mentoring ...

Cyber Response & Recovery Manager - German Speaker

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
intrusion) – managing resources and defining objectives at each stage of the incident response process; scoping and triage, containment, evidence preservation and extraction, eradication, recovery, forensic analysis and investigation. Fluent German speaker and ability to draft reports in German. A broad understanding of the cyber security threat landscape. Strong … programmer will be able to transfer skillsets across languages. Technical proficiency in at least one of these areas: network security/traffic/log analysis; Linux and/or Mac/Unix operating system forensics; Linux/Unix disk forensics (ext2/3/4, HFS+, and/ ...

Cyber Response & Recovery Manager (Reactive DFIR) - German Speaking

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
intrusion) – managing resources and defining objectives at each stage of the incident response process; scoping and triage, containment, evidence preservation and extraction, eradication, recovery, forensic analysis and investigation. Fluent German speaker and ability to draft reports in German. A broad understanding of the cyber security threat landscape. Strong … programmer will be able to transfer skillsets across languages. Technical proficiency in at least one of these areas: network security/traffic/log analysis; Linux and/or Mac/Unix operating system forensics; Linux/Unix disk forensics (ext2/3/4, HFS+, and/ ...

Embedded Cyber Detection and Response Deputy Team Lead

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
identity environments. Conduct advanced threat hunting activities to identify emerging threats, undetected adversary activity, and gaps in detection coverage. Support incident response activities including forensic analysis, root cause determination, remediation planning, and post-incident reviews. Collaborate with Security Engineering to improve detection logic, automate workflows, and optimize security … such as Splunk, Microsoft Sentinel, CrowdStrike, SentinelOne, Palo Alto, Microsoft Defender, or equivalent technologies. Strong understanding of incident response methodologies, digital forensics principles, malware analysis, and threat hunting techniques. Working knowledge of the MITRE ATT&CK Framework, NIST Cybersecurity Framework, and incident response best practices. Experience supporting operational improvement ...

SOC Shift Lead

Hiring Organisation
Claranet Limited
Location
Leeds, West Yorkshire, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
Incident Triage - Understand the principles behind effective triage, including the rationale for using standardised playbooks and the criteria for escalating incidents without undertaking complex forensic analysis Threat Intelligence Integration - Be knowledgeable about the role and structure of threat intelligence – how feeds are sourced, what constitutes actionable information … malware indicators are defined Scripting and Automation - Understand the concepts behind using scripting for automating regular data extraction and log analysis, and the benefits such tools being to maintaining consistency in alert handling Benefits At Claranet, we go the extra mile with our people—because we believe in building ...

Lead Cyber Security Monitoring

Hiring Organisation
DVSA
Location
Birmingham, West Midlands, England, United Kingdom
Employment Type
Full-Time
Salary
£44,241 per annum
business operations. This ensures that the best possible levels of service quality and availability are maintained, whilst containing any security breach to allow for forensic analysis to establish cause. It establishes action plans in collaboration with other managers in the team and wider DVSA. It effectively manages, investigates … management, using threat intelligence to identify emerging risks, suspicious activity, and weaknesses in DVSA's security posture. Manage post-incident review, including root cause analysis, to feedback information and so improve monitoring and evidencing need for policy change as necessary. Managing and improving SOC processes and protective monitoring capabilities ...

Lead Cyber Security Monitoring

Hiring Organisation
DVSA
Location
Uxbridge, Middlesex, England, United Kingdom
Employment Type
Full-Time
Salary
£44,241 per annum
business operations. This ensures that the best possible levels of service quality and availability are maintained, whilst containing any security breach to allow for forensic analysis to establish cause. It establishes action plans in collaboration with other managers in the team and wider DVSA. It effectively manages, investigates … management, using threat intelligence to identify emerging risks, suspicious activity, and weaknesses in DVSA's security posture. Manage post-incident review, including root cause analysis, to feedback information and so improve monitoring and evidencing need for policy change as necessary. Managing and improving SOC processes and protective monitoring capabilities ...

Lead Cyber Security Monitoring

Hiring Organisation
DVSA
Location
Swansea, West Glamorgan, Wales, United Kingdom
Employment Type
Full-Time
Salary
£44,241 per annum
business operations. This ensures that the best possible levels of service quality and availability are maintained, whilst containing any security breach to allow for forensic analysis to establish cause. It establishes action plans in collaboration with other managers in the team and wider DVSA. It effectively manages, investigates … management, using threat intelligence to identify emerging risks, suspicious activity, and weaknesses in DVSA's security posture. Manage post-incident review, including root cause analysis, to feedback information and so improve monitoring and evidencing need for policy change as necessary. Managing and improving SOC processes and protective monitoring capabilities ...

Cyber Response & Recovery Manager (Remediation)

Hiring Organisation
KPMG UK
Location
City of London, London, United Kingdom
most operationally critical phase of a cyber incident: restoring business services safely and securely. The role will work closely with incident response leads, forensic teams, legal advisers, crisis management teams, technology teams and client executives to convert incident findings into practical remediation, rebuild and recovery actions. As a cyber … during active cyber incidents and post-incident remediation programmes. Responsibilities will include: Lead cyber recovery workstreams during major incidents, working closely with incident response, forensic, client IT, legal, insurer and senior stakeholder teams, translating incident findings into clear remediation and recovery actions. Deliver hands-on remediation across enterprise environments ...

Security Platform Engineer, UK Security Operations

Hiring Organisation
Jobleads-UK
Location
City of Westminster, England, United Kingdom
logging strategies. Investigate and analyse security incidents, including identifying root causes, determining the scope of impact, and taking appropriate containment and remediation actions. Perform forensic analysis to identify and investigate suspicious activity. Automate security tasks and workflows to improve efficiency and effectiveness. Google is proud ...

Cyber Response & Recovery Assistant Manager (Reactive DFIR)

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
intrusion) – managing resources and defining objectives at each stage of the incident response process; scoping and triage, containment, evidence preservation and extraction, eradication, recovery, forensic analysis and investigation. A broad understanding of the cyber security threat landscape. Strong technical background in computers and networks, and programming skills. Proven ...

Security Operations Lead - MUST HAVE SC CLEARANCE - Inverness or Preston - 6 months+

Hiring Organisation
Octopus Computer Associates
Location
Preston, Lancashire, United Kingdom
Employment Type
Contract
Contract Rate
GBP Annual
improvement across the incident management life cycle. This is a governance, assurance, and supplier management role and does not perform SOC monitoring, incident investigation, forensic analysis, or operational response activities. Key Responsibilities: Security Incident Governance Own and govern the security incident management framework across suppliers Define and maintain … Support audits, assurance reviews, and regulatory inspections Post-Incident Review & Continuous Improvement Coordinate governance of Post Incident Reviews (PIRs) Ensure suppliers provide: Root cause analysis Corrective actions Improvement activities Identify opportunities to improve incident governance, reporting, and operational effectiveness Your skills and experience Essential Significant experience in Security Incident ...

Senior DFIR / Incident Response / Digital Forensics

Hiring Organisation
Jobleads-UK
Location
Knutsford, England, United Kingdom
support rotation with occasional extended hours and weekend work as required. Qualifications Digital forensics and incident response expertise, including host, network, cloud and live forensic analysis, supported by rigorous documentation practices. Excellent written and verbal communication skills, with the ability to clearly articulate complex technical findings to senior ...

Senior DFIR / Incident Response / Digital Forensics

Hiring Organisation
Jobleads-UK
Location
Knutsford, England, United Kingdom
work. To be successful in this role, you will need the following: Digital forensics and incident response expertise, including host, network, cloud and live forensic analysis, supported by rigorous documentation practices. Excellent written and verbal communication skills, with the ability to clearly articulate complex technical findings to senior ...

SC Security Platform Engineer - 12 Month Contract

Hiring Organisation
Jobleads-UK
Location
Farnborough, England, United Kingdom
logging strategies. Investigate and analyse security incidents, including identifying root causes, determining the scope of impact, and taking appropriate containment and remediation actions. Perform forensic analysis to identify and investigate suspicious activity. Automate security tasks and workflows to improve efficiency and effectiveness. Preferred Qualifications (PQs) Certifications in Security ...

Chief Information Security Officer

Hiring Organisation
Jobleads-UK
Location
Wolverhampton, England, United Kingdom
alerts originating from Safran CERT/SOC and the SED ISS operational unit. Handle alerts on administrator and user workstations, including first‐level forensic analysis, user interviews, and coordination with Local Support teams. Escalate issues requiring clarification or broader company involvement to central ISS teams. Candidate Profile Master ...

Security Engineer (Institutional Trading)

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
quant teams. Exposure to blockchain on‐chain concepts (wallets, addresses, transactions) but no requirement to audit contracts. Familiarity with SOC operations, and post‐incident forensic analysis. Familiarity with SOC2, ISO 27001, or financial audit requirements Any relevant industry certification Blockchain is committed to diversity and inclusion in the workplace ...

Senior Cloud Security Engineer

Hiring Organisation
Jobleads-UK
Location
Belfast City District, Northern Ireland, United Kingdom
configurations to identify security risks; triage findings and drive remediation with resource owners. Identify threats through vulnerability assessments, penetration testing support, and log analysis; ensure security controls meet compliance requirements including SOC 2 and ISO 27001. Automate cloud security controls, data collection, and workflows using Python, Bash, cloud APIs … management, and detection platforms. Integrate security controls into CI/CD pipelines and engineering delivery workflows, advancing DevSecOps practices across the organization. Lead containment, forensic analysis, and remediation for cloud security incidents in partnership with CSIRT and engineering teams. Lead cloud security projects and major components of complex ...

Information Security Engineering Specialist

Hiring Organisation
BP Energy
Location
Sunbury-On-Thames, London, United Kingdom
Employment Type
Work From Home
incident investigation and response efforts for security breaches, ensuring timely resolution and minimal impact. Manage the full lifecycle of security incidents, from detection and analysis to containment, eradication, recovery, and post-incident review. Develop, implement, and maintain comprehensive information assurance frameworks and policies to protect sensitive data and systems. … Qualifications Proven experience in Information Security with a solid focus on engineering and operational aspects. Demonstrated expertise in incident investigation and response, including forensic analysis and remediation. In-depth knowledge and practical experience in Incident Management methodologies and tools. Solid understanding of Information Assurance principles, frameworks, and regulatory ...

Senior Cloud Incident Response Specialist

Hiring Organisation
Jobleads-UK
Location
United Kingdom
seeking a Senior Incident Response Security Consultant (Mid) to lead advanced incident response engagements across cloud and on-prem environments. You will perform forensic analysis, threat hunting, and malware triage, guiding clients through investigations and containment with clear executive communication. Role requires a Bachelor's degree ...