DFIR Analyst - Greater London - Ankura

    Ankura
    Ankura Greater London

    1 week ago

    Description

    • Develop an understanding of a client's security posture to guide them in identifying, analysing and addressing cyber related threats and risks.
    • Perform and support evaluation of Cyber Security programs based upon a recognised framework or regulation e.g. NIST Cyber Security Framework, NIS Directive , PCI Data Security Standard, ISO Standards, etc.
    • Perform technical testing of clients' environments including best practice audits, network assessments, penetration testing and vulnerability assessments.
    • Carry out cyber security assessments across a range of technology architectures including cloud and hybrid models.
    • Develop and deliver recommendations, reports, and presentations outlining findings from projects and summarising results of work performed.
    • Maintain detailed working records reflecting assumptions, methodologies, and information sources employed during the performance of all analytical tasks.
    • Manage time and tasks to meet internal and external deadlines.
    • Maintain professional image within the company and project the same to those outside of the company.
    • Support the day-to-day activities of engagements including interaction with other team members, subject matter experts, and client contacts.
    • Provide input into client communications, both written and oral, throughout the lifecycle of the project.
    • Holder of industry qualifications are preferred, but not required: CISSP, SANS, CISA, PMP, CISM, CREST, OSCP/OSCE, GWAPT, GXPN, GPEN and/or similar Forensics / Cyber Security certification(s)You will have qualified in Cyber Security or related disciplines including Computer Science, Engineering, Technology or Computer Forensics or have 3+ years of industry experience and gained experience working on client facing engagements in a management consulting firm.
    • Passion for Cyber Security or Incident Response and a desire for continuous improvement in expertise
    • Strong ability and desire to use technology to solve complex problems
    • Understanding of how to communicate effectively and concisely with key stakeholders
    • Ability to approach projects both from a strategic and tactical perspective
    • Ability to work both independently and as part of a team in a high-paced, multi-task environment with attention to detail.
    • Strong conceptual, as well as quantitative and qualitative analytical skills
    • Team player comfortable working in a dynamic and fast-paced collaborative environment
    • Exceptional organisational skills, to include detailed note taking abilities
    • Strong attention to detail, possessing problem solving, troubleshooting and analytical reasoning skills
    • Frequently communicates with clients and co-workers and share information effectively
    • Flexibility and responsiveness working on multiple projects in sometimes high-pressure situations simultaneously
    • Ability to travel in and outside the UK for work, which could involve a few weeks at a time. Engagement duration can range from a week to months. The ability to travel at short notice is important
    • Able to support out of hours work (approx. one in four weeks)
    • Ability to engage with team and client personnel in demanding, deadline-driven situations
    • Excellent communication (both written and verbal), mathematical, and organisational skills
    • Flexibility with respect to assigned tasks and engagements due to challenging deadlines, changing deliverables, and evolving task priorities
    • Detailed understanding of operating systems and network architecture including high level administrative experience working with Windows and/or non
    • Windows systems (such as Linux, Unix, Mac)
    • Familiarity with security technology stacks, applications and solutions including but not limited to firewalls, SIEM platforms, end point detection & response, Cloud security platforms, logging and monitoring systems, DLP, anti malware controls, security compliance tools, intrusion detection and response systems.
    • Knowledge about applied cyber security principles including policies and good practices, cryptography, access controls, application and network security
    • Understanding of security principles, policies and industry best practices
    • Strong work ethic, eagerness to learn, and motivation to succeed
    • Functional understanding of Network Architecture, Design, and Security Best Practices
    • Fundamental understanding of Computer Forensics principles and practices
    • Familiarity with NIST or ISO frameworks and/or risk assessment methodology
    • Knowledge of Cyber Security compliance and frameworks, such as NIST, ISO 27001 etc.
    • Familiarity assessing and benchmarking security controls in common cloud platforms including Office 365, Google Suite, Azure, AWS or Google Cloud
    • Ability to correlate events from multiple sources to create a timeline analysis across end points of an incident; proficient in log analysis of multiple types; ability to analyse network packet captures and understand memory capture and analysis.
    • Scripting/programming experience (specifically Python, C#, VBA, or Powershell)
    • Awareness of AI tools, techniques and approaches for use in cyber security and DFIR projects.
    Ankura is an Affirmative Action and Equal Opportunity Employer.

    All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against based on disability.

    Equal Employment Opportunity Posters, if you have a disability and believe you need a reasonable accommodation to search for a job opening, submit an online application, or participate in an interview/assessment, please email or call toll-free This email and phone number are created exclusively to assist disabled job seekers whose disability prevents them from being able to apply online.

    Only messages left for this purpose will be returned.

    Messages left for other purposes, such as following up on an application or technical issues unrelated to a disability, will not receive a response.

    Ankura Consulting Group, LLC is an independent global expert services and advisory firm that delivers services and end-to-end solutions to help clients at critical inflection points related to conflict, crisis, performance, risk, strategy, and transformation.

    The Ankura team consists of more than 2000 professionals serving 3,000+ clients across 55 countries who are leaders in their respective fields and areas of expertise.

    Collaborative Lateral Thinking That Deliversᵀᴹ, hard-earned experience, expertise, and multidisciplinary capabilities drive results and Ankura is unrivalled in its ability to assist clients to Protect, Create, and Recover Valueᵀᴹ.

    For more information, please visit, .
    #J-18808-Ljbffr

  • Work in company

    DFIR Analyst

    Only for registered members

    This position supports the Data & Technology practice at Ankura, a team of excellence founded on innovation and growth. · ...

    UK London

    1 week ago

  • Work in company

    DFIR Analyst

    Only for registered members

    Ankura is a team of excellence founded on innovation and growth.This position supports the Data & Technology practice - one of six practices focused on client delivery services across the Firm. · Cyber Security and Privacy Practice is a full-service suite of Cyber Security and pr ...

    London

    1 week ago

  • Work in company

    DFIR Senior Analyst

    Only for registered members

    Ankura's Cyber Security and Privacy Practice is a full-service suite of Cyber Security and Privacy solutions regardless of industry or size Our global team of over 100 professionals includes former federal law enforcement personnel in-house security experts Big 4 consultants fede ...

    UK London

    1 week ago

  • Work in company

    DFIR Senior Analyst

    Only for registered members

    We are seeking a Manager level candidate with Incident Response and project management experience gained in professional services. · ...

    London

    1 week ago

  • Work in company

    Malware Threat Analyst – DFIR

    NCC Group

    Malware Threat Analyst – DFIR · A leading Cyber Security firm is seeking a Malware Analyst to lead efforts in analyzing and mitigating malware threats. · Conduct advanced analysis · Contribute to incident response · Develop detection capabilities · ...

    London

    6 days ago

  • Work in company

    Incident Manager

    Only for registered members

    + Incident Manager · Job summary: Required Qualifications Experience in incident response, digital forensics, security operations or SOC environments. Strong technical understanding of security incidents and forensic investigations across Network environments AWS or other cloud p ...

    London

    1 week ago

  • Work in company

    Incident Manager

    Only for registered members

    Incident manager required for incident response and digital forensics in SOC environments. · ...

    London Area

    1 week ago

  • Work in company

    Cyber Security Engineer

    Only for registered members

    We're looking for a hands-on Cyber Security Engineer who can strengthen our detection, response and monitoring capabilities while helping shape the future of our security tooling processes and controls. This is a great opportunity to influence and mature a security function while ...

    London

    1 week ago

  • Work in company

    Cyber Security Engineer

    Only for registered members

    We're looking for a hands‑on Cyber Security Engineer who can strengthen our detection, response, and monitoring capabilities while helping shape the future of our security tooling processes and controls. · Enhancing and operating core security capabilities including SIEM MDR secu ...

    London Area

    2 days ago

  • Work in company

    Senior SOC Analyst

    Only for registered members

    +We're now looking for a Senior SOC Analyst to take a leading role in complex incident response cases, guiding clients through high‑severity security events and strengthening our overall SOC capability. · + · +Incident response & forensics: · You'll lead major security incidents ...

    United Kingdom

    2 weeks ago

  • Work in company

    Senior SOC Analyst

    Only for registered members

    We're now looking for a Senior SOC Analyst to take a leading role in complex incident response cases, guiding clients through high‑severity security events and strengthening our overall SOC capability. · You'll lead major security incidents from detection through remediation, coo ...

    United Kingdom £55,000 - £90,000 (GBP) per year

    13 hours ago

  • Work in company

    SOC Analyst

    Only for registered members

    We are looking for a SOC Analyst to join our team. The successful candidate will be responsible for investigating complex incidents and improving the quality of our SOC. · ...

    London

    1 week ago

  • Work in company

    Incident Manager

    Only for registered members

    The Incident Response Manager coordinates the organisation's response to security incidents end-to-end, · Lead and coordinate the organisation's response to security incidents from detection through containment, eradication, recovery, and closure · ...

    London SWA JX

    2 weeks ago

  • Work in company

    Lead CyberSecurity SOC Analyst

    Only for registered members

    We are passionate and committed to our people and go beyond the rhetoric of diversity and inclusion. You will be working in an inclusive environment and be encouraged to bring your whole self to work. · ...

    London Full time

    1 week ago

  • Work in company

    Lead CyberSecurity SOC Analyst

    Only for registered members

    We are passionate and committed to our people and go beyond the rhetoric of diversity and inclusion. You will be working in an inclusive environment and be encouraged to bring your whole self to work. · ...

    Farringdon, London, United Kingdom

    1 week ago

  • Work in company

    Senior Incident Responder

    Only for registered members

    hackajob is collaborating with Tesco to connect them with exceptional tech professionals for this role. · Senior Incident Responder (DFIR) · About The Role · Our Digital Forensics and Incident Response (DFIR) team lead the technical investigation and response to security incident ...

    Welwyn Garden City

    2 hours ago

  • Work in company

    Cyber Security Incident Responder

    Only for registered members

    +BRISTOL OR STEVENAGE - Sole British CitizenWe are seeking a proactive CERT Incident Responder to lead our Digital Forensics and Incident Response (DFIR) readiness and drive our Adversarial Exposure Validation (AEV) program.This role is a unique hybrid of defensive response and p ...

    Stevenage

    1 week ago

  • Work in company

    CERT Incident Responder

    Only for registered members

    The CERT Incident Responder is responsible for leading digital forensics and incident response (DFIR) readiness while advancing the organisation's Adversarial Exposure Validation (AEV). The role ensures detection, response, and control validation against real-world threat actor t ...

    Stevenage £50,000 - £60,000 (GBP)

    3 weeks ago

  • Work in company

    CERT Incident Responder

    Only for registered members

    The CERT Incident Responder is responsible for leading digital forensics and incident response (DFIR) readiness. The role ensures detection, response, and control validation against real-world threat actor tactics. · This is a Next step role for an experienced Analyst with a pass ...

    Stevenage £50,000 - £60,000 (GBP)

    2 weeks ago

  • Work in company

    CERT Incident Responder

    Only for registered members

    The CERT Incident Responder is responsible for leading digital forensics and incident response (DFIR) readiness. · Lead digital forensics and incident response (DFIR) activities, ensuring lab readiness, artefact management, and delivery of forensic objectives. · Maintain and enha ...

    Stevenage

    4 days ago

  • Work in company

    CERT Incident Responder

    Only for registered members

    The CERT Incident Responder is responsible for leading digital forensics and incident response (DFIR) readiness. While also advancing the organisation's Adversarial Exposure Validation (AEV)— including Red and Purple Team activities The role ensures detection, response, and contr ...

    Stevenage, England

    2 weeks ago

Jobs
>
London