We have been made aware of a number of scams where fraudsters are claiming to represent our organisation or organisations we work with. Please click here to find out more details and what to do if you are contacted.

menu

Accessibility tools

Senior DFIR Analyst

Remote

  1. Full time

About the job

The Senior Digital Forensics and Incident Response Analyst role will sit within our Security Operations Department. This is a hands-on technical role which also requires operational management skills.

We are looking for someone with a strong technical background and significant experience across all types of incident response with a strong emphasis on cloud response. Someone with excellent documentation skills who is willing to mentor the members of the DFIR and other closely related teams. This person will be one of the main escalation points for our SOC and an active member of purple team activities.

The right candidate will be able to work alongside senior stakeholders across the business and represent security operations with the technology risk teams. When not responding to and managing incidents, you will be expected to take part in threat hunting as well as driving forward the DFIR team with their strategic mission, which will consist of constant reviews of processes and procedures, developing new playbooks, running business-wide tabletop sessions (including extinction level attacks) and assessing our overall digital forensic and incident response maturity levels.

Being able to distil technical information to non-technical members of Admiral is vital. The successful candidate should not be afraid to question what is being presented to them, constantly searching for answers to “why” something has happened and persisting with through resolution to learn as a business.

Key Responsibilities 

  • Incident Response Leadership: Act as a primary escalation point for the Security Operations Centre (SOC), leading investigations into complex security incidents across on-premise and cloud environments (Azure/GCP) and ensuring timely resolution.
  • Digital Forensics: Conduct forensic investigations using industry-standard tools (e.g. Wireshark, Volatility, EnCase, FTK, Autopsy), ensuring adherence to legal and procedural standards.
  • Threat Hunting: Proactively identify threats through structured threat hunting activities, leveraging frameworks like MITRE ATT&CK and tools such as Splunk.
  • Purple Team Engagement: Collaborate with red and blue teams to simulate and defend against advanced persistent threats, contributing to continuous improvement of detection and response capabilities.
  • Process & Playbook Development: Drive the evolution of DFIR processes by developing and refining incident response playbooks, conducting tabletop exercises (including extinction-level scenarios), and assessing DFIR maturity. 
  • Stakeholder Communication: Translate complex technical findings into clear, actionable insights for non-technical stakeholders and senior leadership.
  • Cloud Security Maturity: Lead efforts to mature Admiral’s cloud incident response capabilities, including building out the cloud portfolio and ensuring CMII levels reach 3 or above.
  • Mentorship & Knowledge Sharing: Mentor junior analysts and share best practices across the DFIR, SOC, and Threat Intelligence teams.

Essential Skills

  • 4+ years of experience conducting incident response and forensic investigations.
  • 1+ years of experience with incidents in the cloud (Azure and/or GCP).
  • Hands-on experience with proxies, load balancers, virtual machines, containers, and/or serverless technologies.
  • Experience with cloud-native security capabilities and features (e.g., GuardDuty, Sentinel, CloudTrail etc.), common enterprise security tools (SIEM, EDR, etc), and cloud-specific security tools.
  • Proficient use of Linux, MacOS, and Windows Operating System tools (such as curl, wget, nslookup, etc).
  • Practical programming knowledge or experience in writing scripts in Python, PowerShell, Java, etc.
  • Broad understanding of networking and common enterprise technologies.
  • A demonstrable understanding of the Cyber Kill Chain, MITRE ATT&CK and other information security defence and intelligence frameworks.
  • Always demonstrate a professional, calm, and expert manner while showing leadership during stressful situations.
  • Proven experience in driving strategic goals and stakeholder management, including third-party relationships.

Admiral: Where You Can

We take pride in being a diverse and inclusive business. It's a place where you can Be You, and show up as you are. We’re committed to fostering a people-first culture where everyone is accepted, supported, and empowered to be brilliant. You can, Grow And Progress at a pace and direction that suits you, Make A Difference for our customers and each other, and Share in Our Future with all colleagues eligible for up to £3,600 of free shares each year after one year of service.

Everyone receives 33 days holiday (including bank holidays) when they join us, increasing the longer you stay with us, up to a maximum of 38 days (including bank holidays). You also have the option to buy or sell up to an additional five days of annual leave.

We’re proud of our people-first culture. In fact, we've been recognised as a Great Place to Work for Women, a Great Place to Work for Wellbeing, and an overall Great Place to Work for over 25 years! We’re fully committed to making sure your progression is not slowed or halted by barriers related to race, gender, age, sexuality or any of the protected characteristics.

Our fantastic benefits make sure our colleagues have a great work-life balance; You can view some of our other key benefits here.

#LI-KG1

  1. Full time
  2. Admiral Tech

__jobinformationwidget.freetext.LocationText__

Remote

jobs

Related jobs

Operational Excellence Consultant

Salary

Location

Cardiff

Job Type

Full time

Location

Cardiff

Brand

Pioneer

Department

Veygo

Office address

Capital Tower, Greyfriars Road, Cardiff, CF10 3AZ

Description

Operational Excellence Consultant We’re looking for an Operational Excellence Consultant to join our team at Veygo!  About Veygo  At Veygo our world is learner and temporary pay-as-you-go car

Reference

10484

Expiry Date

01 Jan 0001

Eden Davies

Vacancy managed by

Eden Davies
Eden Davies

Vacancy managed by

Eden Davies
View Shortlist
Technical Senior Data Scientist

Salary

Location

Cardiff

Job Type

Full time

Location

Cardiff

Brand

Admiral Group

Department

Pricing and Analytics

Office address

Tŷ Admiral, David Street, Cardiff, CF10 2EH

Description

Are you a curious mind with a passion for machine learning and a drive to innovate? At Admiral, we’re on a mission to transform insurance through advanced analytics and AI. As a Senior Data Scientist

Reference

10165

Expiry Date

01 Jan 0001

Anna Braddock

Vacancy managed by

Anna Braddock
Anna Braddock

Vacancy managed by

Anna Braddock
View Shortlist
Data Quality Analyst

Salary

Location

Remote

Job Type

Full time

Location

Remote

Brand

Admiral Group

Department

Operational Support

Office address

Remote

Description

The Data Enablement Services includes Data Governance, Data Management, Customer Master, Data Confidentiality (working with Info Security), Data Quality Management, and Retention & Deletion as core co

Reference

10390

Expiry Date

01 Jan 0001

Georgia Needham

Vacancy managed by

Georgia Needham
Georgia Needham

Vacancy managed by

Georgia Needham
View Shortlist

Our Benefits

Admiral employees work hard to keep us at the top of our industry, and are rewarded for it—with competitive pay, a share package, career growth and development opportunities and some other great benefits, too!

People who like what they do, do it better.

Be You

Financial & Mortgage Advice

Financial & Mortgage
Advice

Ecare

24-Hour
Ecare

Cycle to Work Scheme

Cycle to Work
Scheme

Annual Holiday Allowance

Annual Holiday
Allowance

Flexible Working

Flexible
Working

Simply Health

Simply
Health

Private Health Cover

Private Health
Cover

Critical Illness Cover

Critical Illness
Cover

Grow & Progress

Learning and Development

Learning and
Development

Educational Sponsorship

Educational
Sponsorship

Accredited Qualifications ILM

Accredited
Qualifications ILM

iLearn

iLearn
Online Learning

Buy a Book Scheme

Buy a Book
Scheme

Developmental Coaching

Developmental
Coaching

Port of Calls

Port of
Calls

Internal Mobility

Internal
Mobility

Make a Difference

Groups & Societies

Groups and
Societies

Socials & Team Days Out

Socials and Team
Days Out

Multi Faith / Quiet Rooms

Multi Faith / Quiet
Rooms

Admiral Community Fund

Admiral Community
Fund

Give as You Earn

Give as You
Earn

Awards & Star Lunches

Awards and Star
Lunches

Corporate Social Responsibility

Corporate Social
Responsibility

Impact Hours

Impact
Hours

Share In Our Future

Share Schemes

Share
Schemes

Refer a Friend Bonus

Refer a Friend
Bonus

Colleague and Family Discount

Colleague and Family
Insurance Discount

Group Life Assurance

Group Life
Assurance

Pension

Pension
Scheme

Life Event Loan

Life Event
Loan

Tickets to Sponsored Events

Tickets to Sponsored
Events

Tusker

Tusker Salary
Sacrifice

Click here to download our full benefits brochure