Rodeo
Get started

CYFOR Group

Cyber Incident Response Consultant

Manchester
£40k – £50k/yr
Posted about 13 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Location: Manchester, hybrid
Employment type: Full-time
Salary: £40,000–£50,000 per year

About CYFOR Secure

CYFOR Secure is part of CYFOR Group, a nationwide provider of cyber security, digital forensics and eDiscovery services.

We support organisations across a range of sectors, including legal, insurance, corporate and law enforcement, helping them respond to complex cyber incidents and digital investigations.

Due to continued growth, we are looking for an experienced Cyber Incident Responder to join our team.

The Role

The ideal candidate will have at least 2 years’ experience responding to and investigating a range of cyber incidents and demonstrate in-depth knowledge of common cyber incident types and threat actor methodologies.

You’ll have a deep technical knowledge of incident response, digital forensics, M365, cloud environments and investigations processes, along with excellent client facing skills and a can-do attitude. You’ll also be able to demonstrate flexibility, commitment and integrity.

In return, you’ll receive a salary commensurate with experience; plus training, overtime and excellent career prospects. You’ll enjoy a varied and highly fulfilling role, working with great colleagues in a fantastic atmosphere.

This is a unique opportunity to join a highly successful business that truly focuses on its main asset, its team members.

Main responsibilities:

  • Perform emergency incident response for customers; including containment (credential resets, network quarantine and EDR rollouts) to prevent further compromise and gathering of relevant forensic evidence.
  • Investigate forensic evidence from compromised devices and networks to determine the root cause of incidents and understand the actions taken by threat actors.
  • Acquire and investigate server logs, firewall logs, intrusion detection system alerts, traffic logs and host system logs to determine what data has been impacted during a cyber incident using open-source tools and industry standard forensics software.
  • Conduct forensic acquisitions from relevant servers and workstations
  • Analyse malware to understand and communicate its impact on systems and data
  • Deliver high-quality technical investigation and forensic reports to clients
  • Deliver regular, high-quality updates to clients throughout an investigation
  • You will also be required to travel at short notice for Cyber Incident response.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Skills and Experience

  • At least two years’ hands-on cyber incident response experience within a consultancy, managed security service provider or other client-facing environment.
  • Experience collecting forensic evidence from compromised systems.
  • Experience investigating cyber incidents to understand malicious activity.
  • Proven understanding of the Cyber Kill Chain, MITRE ATT&CK and other information security defence and intelligence frameworks.
  • Comprehensive knowledge of incident handling, threat hunting and threat intelligence.
  • Ability to correlate events from various sources to create incident timelines.
  • Experience in cloud-based infrastructure including Microsoft Azure and Office 365, Amazon AWS, and Google Cloud.
  • Excellent client-facing skills, with the ability to communicate at all levels, adapting the style of communication to meet the needs of the audience.
  • An excellent attitude and the willingness to learn and study for certifications.
  • Ability to effectively plan and coordinate projects.
  • Excellent written and verbal communication skills.
  • An investigative mindset with a high level of attention to detail.
  • Demonstrate a flexible approach to work and a high level of self-motivation.
  • Ability to exercise discretion and confidentiality.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable Skills

  • Previous exposure to enterprise scale infrastructure and technology stacks.
  • Appropriate incident response certifications (E.g., CREST Intrusion Analyst or Incident Manager).
  • Experience deploying and monitoring endpoint protection (e.g. SentinelOne) across a variety of systems during incident response.

Security Clearance

Please note that this role will require NPPV3 clearance in addition to National security clearance to SC level. Applicants MUST have been continuously resident in the United Kingdom for the last 5 years. If you do not hold an active SC clearance, please familiarise yourself with the vetting process before applying.

What We Offer

You will join a growing team working on varied and technically challenging investigations, with opportunities for training, professional development, overtime and career progression.

CYFOR is committed to creating an environment where talented people can develop their skills, take ownership of their work and make a meaningful contribution to clients.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Incident Response
Digital Forensics
M365
Cloud Investigations
Malware Analysis
Threat Hunting
Threat Intelligence
Cyber Kill Chain
MITRE ATT&CK
Microsoft Azure
Amazon AWS
Google Cloud
Client Communication
Project Coordination
Forensic Acquisition
EDR Rollouts

Location

Manchester, England, United Kingdom

Sign up to applySee more jobs like this