Rodeo
Get started

TTC Group (Tech Talent Consulting)

DFIR Manager

United Kingdom
Posted about 15 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

DFIR Manager

Duration: Full-time
Location: Remote
Mode of Interview: 3-4 rounds of video interviews
Travel Required: Ability to travel up to 20%

Overview

Client is hiring a DFIR Manager who will be leading a high-performing Security Incident Response function, overseeing cross-functional investigations, incident resolution, and remediation efforts across global operations. This position is responsible for developing and implementing incident response strategies, driving key performance metrics, mentoring team members, and ensuring legal and technical integrity throughout forensic investigations. As a strategic partner to leadership, the role provides detailed reporting, resource management, and operational oversight while also acting as a technical authority during incidents. The ideal candidate fosters innovation, ensures constant readiness through training and tooling, and plays a critical role in post-breach remediation, client communication, and maintaining organizational resilience in a 24x7 environment.

The successful candidate will work closely with the Director of Global Incident Response Operations. The ideal candidate will have an energetic, can-do attitude and be comfortable working in a metrics-driven environment, delivering results and supporting team members.

Qualifications:

  • Minimum 3 years of Management/Leadership experience & client-facing experience in technical situations.
  • Minimum 6 years of experience in Incident Response.
  • Bachelor’s degree or equivalent work experience.
  • 5+ years of information security experience, as well as leading teams with a deep passion for cybersecurity and incident response.
  • Experience in the Cyber Insurance and Legal markets.
  • Experience in conducting Tabletop Exercises in Incident Response.
  • Experience in the deployment and management of EDR Technology.
  • Experience with Security Technologies and the NIST Framework.
  • Experience in forensic investigations both on-premises and in the cloud.
  • Experience in mentoring, developing, and delivering in-house training.
  • Must be available to provide coverage to meet business requirements in 3 regions.
  • Strong knowledge of DFIR Tools.
  • Strong knowledge of Virtualization Technologies, Operating Systems, Firewalls, VPN’s, SIEM, Enterprise Gateway Technologies, Networking Devices, Security Technologies, etc.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Key Responsibilities

  • Leading security incidents in a cross-functional and collaborative environment, targeting incident resolution & mentoring team members to continue to scale in a high-growth environment.
  • Developing IR initiatives that improve our capabilities to respond and swiftly remediate security events.
  • Creating a culture of accountability, quality, agility, and high performance that will foster the attraction, development, and retention of security analysts.
  • Responsible for being a focal incident response point for all within the organization. This includes being able to provide initial analysis and identification of IOC’s, escalation to the appropriate business units, and post-incident activities.
  • Oversee Incident Response Plans: Design, implement, and manage the client's incident response policies and procedures to ensure preparedness.
  • Coordinate Incident Response Teams: Lead cross-functional teams during security incidents, ensuring an organized and timely response.
  • Triage and Prioritize Incidents: Assess incidents for severity and potential impact, assigning appropriate resources and setting response priorities.
  • Serve as technical point of contact during an incident, providing updates to internal and external stakeholders.
  • Serve as an incident manager, reporting key findings, barriers, escalations, and concerns to the Director of Global Incident Response Operations, while liaising with Legal, the Director of Sales, and the IRC team.
  • Maintain and prepare departmental reports for Key Performance Indicators (KPIs) to be presented to the Global Head of Incident Response Operations and EVP Sales & Revenue as needed.
  • Responsible for supporting a wide number of technologies and being able to proficiently perform advanced troubleshooting on the fly (packet captures, debugs, traffic analysis).
  • Responsible for developing and documenting Incident Response methods and guidelines for the organization.
  • Support the department's DFIR tooling selection process and any proof-of-concept projects.
  • Chain of Custody: Ensure that evidence is collected, handled, and preserved in a legally defensible manner, maintaining the chain of custody for potential litigation.
  • Perform live-endpoint investigation.
  • Implement and deploy an Incident Response-focused ticketing system to improve incident tracking, remediation, and metrics for incidents worked.
  • Post-incident Analysis: Conduct root cause analysis after incidents to identify vulnerabilities and develop strategies to prevent recurrence.
  • Responsible for working with 3rd parties to assist with incident response, business email compromise, security breach, improving overall security, investigations, recommendations, and remediation.
  • Assist Sales and SOC in the successful conversion from incident response, PBR, RMS, eDiscovery to SOC, including process and procedure build-out.
  • Budget and Resource Management: Oversee the allocation of resources, including personnel, tools, and budgets, to effectively manage incident response and forensics operations.
  • Monitor and Manage Regional profit & loss metrics and requirements.
  • Create, maintain, and enhance an onboarding program that is concise and repeatable, effectively covering all aspects of the CERT role.
  • Client Education: Raise awareness across external organisations about digital forensics, incident response protocols, and security best practices.
  • Maintain and manage AWS instances to ensure timely deletion and removal of data to minimize company and customer fees/overages.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Attributes

  • Successful track record of helping to implement security initiatives and frameworks flexibly and innovatively.
  • A collaborative approach to decision-making and the ability to influence with minimal guidance.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

United Kingdom

Sign up to applySee more jobs like this