Haystack
← Back to Jobs
Remote
Technology
LH

Incident Response Lead (DFIR)

LT Harper Recruitment GroupUnited Kingdom🇬🇧United KingdomPosted 14 Sept 2026

Why This Role Stands Out

Lead impactful incident responses on nationally significant cases while developing your technical and leadership skills with a competitive salary up to £110k and a clear path to senior leadership. This remote role is perfect for a driven individual eager to grow within a reputable cyber consultancy and contribute to critical infrastructure and government security. Apply now to take your career in incident response to the next level.

Quick Overview

Salary
£110k/yr
Seniority
Mid Senior
Work mode
Remote
Location
United Kingdom
Active DirectoryPython

Job Description

Incident Response Lead (DFIR) - Hybrid - Can be based anywhere in the UK - Up to £110k


The opportunity:

Do you want to lead the response to incidents that matter nationally?


A Cyber Consultancy is looking for an Incident Response Lead to join its Cyber Response Services team, reporting directly to the head of cyber response. This is a hands-on operational leadership role with a clear route into service line leadership. The team cover industries such as government, critical infrastructure and large enterprise, from ransomware through to advanced network intrusions. You will lead case managers and practitioners, stay technical in the forensics, and have a real say in how the practice grows.


Your benefits:

Up to £110k salary

Funded certifications and a structured training programme

Exposure to nationally significant incidents across government and CNI

Defined progression into senior leadership of a fast-growing capability

Hybrid working from London or Manchester hubs

Pension contribution and private healthcare (confirm)


Your responsibilities as an Incident Response Lead will be to:


  • Manage and coordinate a portfolio of cyber security incidents for clients, working closely with the head of cyber response
  • Lead a team of case managers and practitioners through the full incident lifecycle: scoping, triage, containment, evidence preservation, eradication and recovery
  • Carry out and quality-assure digital forensics on disk, volatile memory, network traffic and log data
  • Own the commercial side of engagements, including scoping, costing, financial management and risk
  • Help clients stand up or mature their own IR capability through playbooks, maturity assessments and tabletop exercises
  • Drive the development of in-house cyber response tooling, lab environments and operating procedures
  • Mentor junior team members and shape the team's learning and development
  • Contribute to bids and proposals, and maintain a current view of the threat landscape for clients
  • Take part in an on-call rotation and be ready to travel at short notice, sometimes for two to three weeks at a time


As an Incident Response Lead you will ideally have:


  • Significant experience managing complex cyber security incidents end to end, including leading a rapid deployment incident response team
  • Strong digital forensics competency, with advanced experience of tools such as X-Ways, EnCase, FTK, AXIOM/IEF or Cellebrite, and of preserving cloud data and encrypted evidence
  • Technical depth in at least one of network and log analysis, Linux or Mac forensics, memory forensics, malware reverse engineering or mobile forensics
  • A working programming skillset (Python preferred) and solid knowledge of enterprise Windows, Active Directory and Linux environments
  • Excellent written and verbal communication, with the ability to guide senior non-technical stakeholders through a live incident
  • Certifications such as CCIM, GCIH, CRIA, CCNIA, CCHIA, GCFA or GNFA are highly desirable, as are CISSP, CISM or CISA
  • Current SC or DV clearance, or eligibility and willingness to obtain it


If you are interested in this role, please contact me at

Similar jobs