Senior DFIR Analyst
Remote
- Full time
Closing date
23/10/2023
About the job
This vacancy has now expired. Please see similar roles below...
"The Senior Digital Forensics and Incident Response Analyst role will sit within our Cyber Defence Department. This is a hands-on technical role which also requires operational management skills.
We are looking for someone with a strong technical background and significant experience across all types of incident response with a strong emphasis on cloud response. Someone with excellent documentation skills who is willing to mentor the rest of the DFIR team and junior members of the defence department. This person will be one of the main escalation points for our SOC and an active member of purple team activities.
The right candidate will be able to work alongside senior stakeholders across the business and represent security operations with the technology risk teams. When not responding to and managing incidents, you will be expected to take part in threat hunting as well as driving forward the DFIR team with their strategic mission, which will consist of constant reviews of processes and procedures, developing new playbooks, running business-wide tabletop sessions (including extinction level attacks) and assessing our overall digital forensic and incident response maturity levels.
Being able to distil technical information to non-technical members of Admiral is vital. The successful candidate not being afraid to question what is being presented to them, constantly searching for answers to “why” something has happened and persisting with the resolutions to stop it from happening again.
Essential Skills:
- 4+ years of experience conducting incident response and forensic investigations.
- 1+ years of experience with incidents in the cloud (Azure and/or GCP).
- Hands-on experience with proxies, load balancers, virtual machines, containers, and/or serverless technologies.
- Experience with cloud-native security capabilities and features (e.g., GuardDuty, Sentinel, CloudTrail etc.), common enterprise security tools (SIEM, EDR, etc), and cloud-specific security tools.
- Proficient use of Linux, MacOS, and Windows Operating System tools (such as curl, wget, nslookup, etc).
- Practical programming knowledge or experience in writing scripts in Python, PowerShell, Java, etc.
- Broad understanding of networking and common enterprise technologies.
- A demonstrable understanding of the Cyber Kill Chain, MITRE ATT&CK and other information security defence and intelligence frameworks.
- Always demonstrate a professional, calm, and expert manner while showing leadership during stressful situations.
- Proven experience in driving strategic goals and stakeholder management, including third-party relationships.
- Certifications such as GCIH, GCFR, GCLD, and GDAT.
Our Commitment to You
At Admiral, we are committed to being a diverse and inclusive workplace. Admiral is proud to be an equal opportunities employer and does not discriminate on the basis of race, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), national origin, gender, gender identity, sexual orientation, disability, age, or any other legally protected status.
All qualified applicants will receive equal consideration for employment.
Benefits and Work-Life Balance
At Admiral, we are proud to be a diverse business where we put our people and customers first. We have great benefits to ensure employees have a great work-life balance; it's one of the reasons we’re consistently voted one of the Sunday Times Best Big Companies to Work For in the UK.
All colleagues will receive 33 days holiday (including banks holidays) when they join us, and this will increase with length of service, up to a maximum of 38 days (including banks holidays). You also have the option to buy or sell up to five days of annual leave in addition to your allocation.
You can also view some of our other key benefits here.
#LI-MB1
Related jobs
Related posts

Teaser
GeneralContent Type
BlogPublish date
30 Nov 2023
Summary
What does a successful career mean to you? For some, it could mean building up experience and strengthening your knowledge and skills. For others, it might involve doing something that has a
by
Ben Moriarty
Our Benefits
As one of our four pillars to our culture, Reward and Recognition is extremely important. We believe that happy staff make happy customers, so we have a huge range of great benefits to make sure everybody has something to smile about! Here are a few of our more popular ones.
Share
Schemes
Flexible
Working
Local
Discounts
Travel Season
Ticket loans
Groups
& Societies
Development
Opportunities