Incident Response
Incident Response Lead
Own major incidents end to end, from the first hour of containment to the board debrief.
Remote (EMEA)
Full-time
6+ years
You will be the person a client speaks to on the worst day of their year. That means technical depth across host and cloud forensics, and the composure to run a room of frightened executives.
You will also build our IR capability: playbooks, tooling, retainer onboarding and tabletop exercise design.
What we are looking for
- Six or more years in incident response or digital forensics
- Hands-on host, memory and cloud forensic capability
- Experience leading ransomware and BEC investigations
- GCFA, GCIH or equivalent
- Willingness to be on an emergency rotation
What we offer
Fully remote within EMEA, with quarterly team weeks
Certification budget and paid study leave
10% of your time for research and tooling
Private healthcare and generous leave policy