Skip to content
L&M Cybersecurity

Incident Response

Incident Response Lead

Own major incidents end to end, from the first hour of containment to the board debrief.

Remote (EMEA) Full-time 6+ years

You will be the person a client speaks to on the worst day of their year. That means technical depth across host and cloud forensics, and the composure to run a room of frightened executives.

You will also build our IR capability: playbooks, tooling, retainer onboarding and tabletop exercise design.

What we are looking for

  • Six or more years in incident response or digital forensics
  • Hands-on host, memory and cloud forensic capability
  • Experience leading ransomware and BEC investigations
  • GCFA, GCIH or equivalent
  • Willingness to be on an emergency rotation

What we offer

Fully remote within EMEA, with quarterly team weeks
Certification budget and paid study leave
10% of your time for research and tooling
Private healthcare and generous leave policy