Incident Response Manager/DFIR Manager

Your new company
You will join an established international cybersecurity services organisation providing digital forensics, incident response and post-breach support to clients worldwide.
Operating through a global follow-the-sun model, the organisation is expanding its regional leadership capability in response to continued growth. This is a remote UK role, with a preference for candidates based around London, Birmingham or Manchester and occasional client-site travel.

Your new role
As Incident Response Manager, you will lead complex DFIR engagements while managing and developing a regional team of approximately six to seven professionals. This is a highly hands-on role, with around 70% of your time focused on technical delivery. You will lead ransomware and business email compromise investigations, oversee activity across endpoint, cloud and on-premises environments, and act as a senior escalation point during live incidents.

You will communicate findings and recommendations to clients, legal advisers, insurers and internal stakeholders. You will also mentor team members, facilitate client tabletop exercises and provide technical support during selected sales engagements.

What you'll need to succeed
You will be an experienced, client-facing DFIR professional with:

  • Strong experience of ransomware and business email compromise investigations.
  • Experience managing full-lifecycle incident-response engagements.
  • A background in cybersecurity consulting or professional services.
  • Practical experience across endpoint, cloud and on-premises investigations.
  • Previous people-management, team-leadership or substantial mentoring experience.
  • Confidence advising senior clients during high-pressure incidents.
  • Experience working with legal advisers, cyber insurers or other third parties.
  • Experience delivering incident-response tabletop exercises.
  • Strong knowledge of evidence preservation and chain-of-custody requirements.
  • Experience with recognised forensic tools. Magnet AXIOM knowledge would be advantageous, although equivalent experience will be considered.
  • Flexibility to participate in weekend on-call coverage and occasional client travel.

    This role will not suit a traditional IT Incident Manager or someone whose Incident Response experience is limited to SOC alert handling.

What you'll get in return

  • Performance-related bonus, generally between 3% and 5%.
  • Remote working within the UK.
  • Pension contributions after three months.
  • Employer-paid health cover, including optical and dental benefits.
  • A telephone allowance.
  • Paid weekend on-call coverage and additional payment for active incident work.
  • The opportunity to lead a regional DFIR team and work on complex international investigations.

What you need to do now
If you're interested in this role, click 'apply now' to forward an up-to-date copy of your CV, or call us now.
If this job isn't quite right for you, but you are looking for a new position, please contact us for a confidential discussion about your career.

Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk

Job Details

Company
Hays Specialist Recruitment Limited
Location
London, South East England, United Kingdom
Hybrid / Remote Options
Employment Type
Full-Time
Salary
£90,000 - £115,000 per annum
Posted