Senior DFIR Analyst
Remote
- Full time
About the job
This vacancy has now expired. Please see similar roles below...
"The Senior Digital Forensics and Incident Response Analyst role will sit within our Security Operations Department. This is a hands-on technical role which also requires operational management skills.
We are looking for someone with a strong technical background and significant experience across all types of incident response with a strong emphasis on cloud response. Someone with excellent documentation skills who is willing to mentor the members of the DFIR and other closely related teams. This person will be one of the main escalation points for our SOC and an active member of purple team activities.
The right candidate will be able to work alongside senior stakeholders across the business and represent security operations with the technology risk teams. When not responding to and managing incidents, you will be expected to take part in threat hunting as well as driving forward the DFIR team with their strategic mission, which will consist of constant reviews of processes and procedures, developing new playbooks, running business-wide tabletop sessions (including extinction level attacks) and assessing our overall digital forensic and incident response maturity levels.
Being able to distil technical information to non-technical members of Admiral is vital. The successful candidate should not be afraid to question what is being presented to them, constantly searching for answers to “why” something has happened and persisting with through resolution to learn as a business.
Key Responsibilities
- Incident Response Leadership: Act as a primary escalation point for the Security Operations Centre (SOC), leading investigations into complex security incidents across on-premise and cloud environments (Azure/GCP) and ensuring timely resolution.
- Digital Forensics: Conduct forensic investigations using industry-standard tools (e.g. Wireshark, Volatility, EnCase, FTK, Autopsy), ensuring adherence to legal and procedural standards.
- Threat Hunting: Proactively identify threats through structured threat hunting activities, leveraging frameworks like MITRE ATT&CK and tools such as Splunk.
- Purple Team Engagement: Collaborate with red and blue teams to simulate and defend against advanced persistent threats, contributing to continuous improvement of detection and response capabilities.
- Process & Playbook Development: Drive the evolution of DFIR processes by developing and refining incident response playbooks, conducting tabletop exercises (including extinction-level scenarios), and assessing DFIR maturity.
- Stakeholder Communication: Translate complex technical findings into clear, actionable insights for non-technical stakeholders and senior leadership.
- Cloud Security Maturity: Lead efforts to mature Admiral’s cloud incident response capabilities, including building out the cloud portfolio and ensuring CMII levels reach 3 or above.
- Mentorship & Knowledge Sharing: Mentor junior analysts and share best practices across the DFIR, SOC, and Threat Intelligence teams.
Essential Skills
- 4+ years of experience conducting incident response and forensic investigations.
- 1+ years of experience with incidents in the cloud (Azure and/or GCP).
- Hands-on experience with proxies, load balancers, virtual machines, containers, and/or serverless technologies.
- Experience with cloud-native security capabilities and features (e.g., GuardDuty, Sentinel, CloudTrail etc.), common enterprise security tools (SIEM, EDR, etc), and cloud-specific security tools.
- Proficient use of Linux, MacOS, and Windows Operating System tools (such as curl, wget, nslookup, etc).
- Practical programming knowledge or experience in writing scripts in Python, PowerShell, Java, etc.
- Broad understanding of networking and common enterprise technologies.
- A demonstrable understanding of the Cyber Kill Chain, MITRE ATT&CK and other information security defence and intelligence frameworks.
- Always demonstrate a professional, calm, and expert manner while showing leadership during stressful situations.
- Proven experience in driving strategic goals and stakeholder management, including third-party relationships.
Admiral: Where You Can
We take pride in being a diverse and inclusive business. It's a place where you can Be You, and show up as you are. We’re committed to fostering a people-first culture where everyone is accepted, supported, and empowered to be brilliant. You can, Grow And Progress at a pace and direction that suits you, Make A Difference for our customers and each other, and Share in Our Future with all colleagues eligible for up to £3,600 of free shares each year after one year of service.
Everyone receives 33 days holiday (including bank holidays) when they join us, increasing the longer you stay with us, up to a maximum of 38 days (including bank holidays). You also have the option to buy or sell up to an additional five days of annual leave.
We’re proud of our people-first culture. In fact, we've been recognised as a Great Place to Work for Women, a Great Place to Work for Wellbeing, and an overall Great Place to Work for over 25 years! We’re fully committed to making sure your progression is not slowed or halted by barriers related to race, gender, age, sexuality or any of the protected characteristics.
Our fantastic benefits make sure our colleagues have a great work-life balance; You can view some of our other key benefits here.
#LI-KG1
- Full time
- Admiral Tech
__jobinformationwidget.freetext.LocationText__
Remote
Talent Partner - Tech & Data
What areas do you look after? I look after the CTO and Cyber, Risk and Resilience departments in the Tech area.
Tell us about you and your Admiral story? I started Admiral in 2019 straight after university in the Motor Claims department as a Claims Handler. I was successful in my application for the internal development programme 'TAP' in 2021, a rotational scheme which placed me in Household Product. I was offered a permanent role there and helped develop our home insurance product for 2 and a half years. My passion had always been people so applied for Talent Acquisition in 2023 and have been here ever since!
Why would you recommend Admiral? I think the internal progression opportunities are one of the best things about Admiral. If you work hard and apply yourself, doors will open for you. I now work in my dream career in People, and have completed my CIPD Level 5. The culture and staff here are also fantastic, from my induction class in Claims I have met my partner of 6 years and my best friend who I was a bridesmaid for this summer. Everyone is so friendly, and I feel fully supported here.
Guidance for using AI during the hiring process
We welcome you to use AI tools to support your application if you choose. Your use of AI won’t affect how you are assessed. However, if you do decide to use it, we encourage you to use it thoughtfully and effectively.
Find out MoreOur Achievements
Related jobs
Salary
Location
Cardiff
Job Type
Full time
Location
Cardiff
Brand
Admiral Money
Department
Finance Services
Description
Admiral Money is hiring! We’re looking for a Motor Underwriter who thrives in a fast‑paced and innovative environment. You’ll play a key role in shaping our new product offering, working closely wi
Reference
11549
Expiry Date
01 Jan 0001
Vacancy managed by
Eden DaviesVacancy managed by
Eden DaviesSalary
Location
Cardiff
Job Type
Full time
Location
Cardiff
Brand
Admiral Money
Department
Finance Services
Description
Customer Accounts Representative (CAR) – 12-Month Secondment/Fixed Term Contract About us Admiral Money is the dynamic lending arm of Admiral Group, offering personal loans, motor finance, and h
Reference
11653
Expiry Date
01 Jan 0001
Vacancy managed by
Eden DaviesVacancy managed by
Eden DaviesSalary
Location
Hybrid
Job Type
Full time
Location
Hybrid
Brand
Admiral Money
Department
Finance Services
Description
A vacancy has arisen within Admiral Money for a Data Engineering Chapter Lead within the Data & Analytics team. The Data Engineering Chapter Lead is responsible for defining, growing, and leading t
Reference
11652
Expiry Date
01 Jan 0001
Vacancy managed by
Georgia FarmerVacancy managed by
Georgia FarmerOur Benefits
We know our colleagues work hard to serve our customers and keep us innovating, so it’s important to us that they’re well-rewarded.
Alongside our competitive pay we also offer a share package, career growth and development opportunities and a whole host of other great benefits!
Explore our benefits below to discover Where You Can
Where You Can Be You
Financial & Mortgage
Advice
24-Hour
Ecare
Cycle to Work
Scheme
Annual Holiday
Allowance
Flexible
Working
Simply
Health
Private Health
Cover
Critical Illness
Cover
Where You Can Grow & Progress
Learning and
Development
Educational
Sponsorship
Accredited
Qualifications ILM
iLearn
Online Learning
Buy a Book
Scheme
Developmental
Coaching
Port of
Calls
Internal
Mobility
Where You Can Make a Difference
Groups and
Societies
Socials and Team
Days Out
Multi Faith / Quiet
Rooms
Admiral Community
Fund
Give as You
Earn
Awards and Star
Lunches
Corporate Social
Responsibility
Impact
Hours
Where You Can Share In Our Future
Share
Schemes
Refer a Friend
Bonus
Colleague and Family
Insurance Discount
Group Life
Assurance
Pension
Scheme
Life Event
Loan
Tickets to Sponsored
Events
Tusker Salary
Sacrifice



