Digital Forensics Specialist
- cheltenham, england, United Kingdom
- £60 - £90 Per Hour
Job Description
TechNET IT has partnered exclusively with a global organisation to appoint an experienced Digital Forensics Specialist to join its Cyber Incident Response Team (CIRT).
This is an exciting opportunity for an experienced DFIR professional who thrives in fast-paced enterprise environments and wants to play a key role in responding to real-world cyber incidents.
This is not a traditional digital forensics role focused on law enforcement or post-incident investigations. Instead, you'll be working alongside Incident Responders during active cyber incidents, using forensic techniques to identify attacker activity, support containment, establish root cause and provide the technical insight needed to drive recovery.
We're looking for someone who enjoys solving complex security challenges and can combine deep forensic expertise with a practical, hands-on approach to incident response.
What you'll be doing
- Conduct forensic investigations across Windows, Linux and macOS endpoints, cloud platforms and identity services.
- Support high-severity cyber incidents by providing forensic analysis throughout the incident response lifecycle.
- Perform endpoint, memory, disk and cloud forensics to determine root cause, attacker activity and potential business impact.
- Analyse forensic artefacts including registry hives, event logs, timelines, persistence mechanisms, malware execution and lateral movement.
- Investigate Microsoft 365 and Azure environments, including identity-related attacks and cloud-based compromise.
- Produce clear forensic reports and actionable technical findings for Incident Response leadership.
- Develop and improve forensic playbooks, workflows and evidence-handling procedures.
- Build automation using PowerShell, Python and Bash to streamline forensic collection and triage.
- Work closely with Detection Engineering and Security Operations teams to improve visibility and develop new detections.
What we're looking for
We're keen to speak with professionals who have experience in Digital Forensics and Incident Response within enterprise or corporate environments.
You'll ideally have experience with:
- Digital Forensics & Incident Response (DFIR)
- Enterprise Incident Response
- Windows, Linux and macOS forensics
- Memory and disk forensics
- Microsoft 365 and Azure investigations
- Endpoint Detection & Response platforms
- Timeline reconstruction and forensic analysis
- PowerShell, Python or Bash scripting
- MITRE ATT&CK framework
- Evidence preservation and forensic reporting
Experience with tools such as Velociraptor, KAPE, Volatility, Autopsy, FTK, EnCase, Microsoft Defender XDR, Sentinel or similar forensic technologies would be highly beneficial.
What makes this role different?
This position sits within an established Cyber Incident Response Team, where you'll be involved in live investigations rather than purely post-incident analysis. You'll have the opportunity to influence how digital forensics is delivered across the organisation by helping shape forensic tooling, automation, investigation processes and forensic readiness.
If you're passionate about Digital Forensics, Incident Response and helping organisations respond to sophisticated cyber threats, we'd love to hear from you.
#J-18808-Ljbffr

