← Tillbaka till jobb

Cyber Incident Response Analyst

  • Distans
  • Sverige
  • Engelska
  • Publicerad 08.10.26

Cyber Incident Response Analyst (DFIR) | 12 Month B2B Contract | Remote Europe We are hiring a hands-on Cyber Incident Response Analyst for a specialist digital and cyber security services provider that is strengthening its Digital Forensics and Incident Response (DFIR) capability. When a customer is breached, this is the person who gets the call, takes control of the investigation and sees it through to closure. This is an initial 12 month B2B contract, open to candidates based in Europe. ABOUT THE ROLE You will lead investigations end to end: scoping the incident, acquiring and preserving evidence, carrying out host, memory, mobile and log forensics, establishing the timeline and root cause, and driving containment, eradication and recovery. Alongside the technical work, you will be the customer's trusted point of contact while an incident is live, keeping legal, IT, compliance and leadership stakeholders informed and aligned, often under real time pressure. Please note: this is a hands-on investigator role. It is not a GRC, audit, policy, security architecture or pure SOC management position. You need to be working in DFIR or incident response today and leading forensic investigations yourself. WHAT YOU WILL BE DOING

  • Leading incident response engagements from first notification through containment, recovery and lessons learned- Performing forensic analysis across endpoints, servers, memory, mobile devices, cloud and log sources- Acquiring and handling evidence in a forensically sound way, maintaining chain of custody throughout- Using tools such as EnCase, Magnet AXIOM, Cellebrite, Volatility and KAPE to reconstruct attacker activity- Identifying root cause, attacker TTPs, persistence and the full scope of compromise- Threat hunting across customer environments using EDR telemetry and other data sources- Acting as the primary customer contact during live incidents, coordinating with legal, IT and compliance teams- Writing clear investigation reports, executive summaries and remediation recommendations- Feeding lessons learned back into detections, playbooks and IR procedures

WHAT WE ARE LOOKING FOR

  • Currently in a DFIR or incident response role, leading investigations and forensic analysis end to end- Hands-on forensic tooling experience, e.g. EnCase, Magnet AXIOM, Cellebrite, Volatility or KAPE- A SOC background covering 24/7 monitoring, triage and escalation- Exposure to threat hunting and EDR-based detection- Comfortable being client-facing during live incidents- Strong written reporting and verbal communication- Based in Europe and able to work on a B2B contract basis

NICE TO HAVE

  • GIAC certification such as GCIH, GCFR or GCFA, or similar (GCFE, GNFA, GREM, EnCE, CHFI)- EDR platforms such as CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne or Carbon Black- SIEM experience, e.g. Microsoft Sentinel, Splunk, QRadar or Elastic- Cloud incident response across Azure, Microsoft 365 or AWS- Ransomware and business email compromise investigations- Malware triage and Python or PowerShell scripting- Consultancy or MSSP background

IS THIS ROLE FOR YOU? This role will suit someone who has personally run real investigations and can stand in front of a customer mid-incident and calmly explain what is happening and what comes next. If your experience is SOC triage and escalation without leading forensic investigations, or incident coordination and GRC rather than hands-on analysis, this one is unlikely to be the right fit. HOW TO APPLY Apply directly through this advert with an up to date CV, your availability, current location and any certifications held. Be ready to talk through one or two recent investigations you personally led. The client is not named in this advert. Shortlisted candidates will be fully briefed before any CV is submitted, and we never send a CV anywhere without your consent.