All open roles

Digital Forensics Incident Responder

United Kingdom · HybridFull-timeIncident Response
Apply for this role

Lead investigations into active breaches for our customers: contain the attacker, find out exactly what happened, and help organisations recover with confidence.

About the role

Aithsense is a young UK cyber security company founded by people who have spent the last 20 years in security operations. We build an agent-first platform that hunts, investigates and responds on top of the tools our customers already run, and we deliver hands-on services alongside it.

As a Digital Forensics Incident Responder you will be one of the people customers call on their worst day. You will lead investigations into active compromises, from ransomware and business email compromise to insider threats and nation-state intrusions, working across endpoints, networks, identity and cloud. You will also feed what you learn back into our detections and the Aithsense platform, so every case makes the next one faster.

What you'll do

  • Lead incident response engagements end to end: scoping, containment, eradication and recovery, working directly with customers' technical and executive teams
  • Perform forensic acquisition and analysis of disk, memory, network and cloud artefacts across Windows, Linux and macOS
  • Reconstruct attacker activity and timelines, identify root cause, and determine what data and systems were affected
  • Hunt for persistence, lateral movement and data exfiltration using EDR, SIEM and the Aithsense platform
  • Write clear, defensible reports for technical and executive audiences, suitable for regulators, insurers and legal teams
  • Preserve evidence and chain of custody to a standard that holds up to legal and regulatory scrutiny
  • Turn findings into detections, hunting hypotheses and playbooks for the platform
  • Take part in an on-call rotation for urgent incidents

What you'll bring

  • 3+ years' hands-on experience in incident response, digital forensics or threat hunting
  • Strong Windows forensics (event logs, registry, file system artefacts, execution evidence) and working knowledge of Linux and macOS
  • Experience with memory analysis and forensic tooling such as Volatility, KAPE, Velociraptor, X-Ways, EnCase or Autopsy
  • Experience investigating with EDR and SIEM platforms (for example CrowdStrike, Microsoft Defender, SentinelOne, Splunk or Microsoft Sentinel)
  • Understanding of attacker tradecraft and the MITRE ATT&CK framework
  • Confidence communicating calmly and clearly with customers under pressure
  • Excellent written English and report writing
  • Right to work in the United Kingdom

Nice to have

  • Certifications such as GCFA, GCFE, GNFA, GCIH or CREST CRIA/CCSAM
  • Cloud incident response experience in AWS, Azure or Google Cloud, and Microsoft 365 investigations
  • Scripting in Python or PowerShell to automate analysis
  • Malware triage and reverse engineering skills
  • Experience in a consultancy, MSSP or CSIRT environment
  • Eligibility for UK security clearance

What we offer

  • Competitive salary
  • Hybrid working, with flexibility around how and where you do your best work
  • Support for training and certifications
  • Real ownership: your work shapes the platform and the services customers rely on
  • A small, senior team of practitioners who have run security operations for two decades

Apply for Digital Forensics Incident Responder

Tell us about yourself and share a link to your CV. We read every application and reply to everyone.

Prefer to send your CV as a file? Email it to inquiries@aithsense.ai.