DFIR Managing Consultant

Posted 3 hours 54 minutes ago by NCC Group plc

Permanent
Full Time
Other
Lancashire, Manchester, United Kingdom, M21 0
Job Description
DFIR Managing Consultant

Department: Cyber Services and Capabilities

Employment Type: Full Time

Location: GBR Manchester Hardman Boulevard

Role Purpose: To manage and service NCC Group clients within the Incident Response space.

The Managing Consultant plays a critical role within the DFIR team of experienced consultants, delivering high quality incident response and proactive services to clients. The role involves leading and contributing to detailed technical analysis, managing incident response activities, and ensuring effective communication and coordination throughout an engagement.

With a strong focus on technically supporting clients during live incidents, the Managing Consultant is also expected to contribute to projects enhancing the team's internal capabilities through continuous improvement of processes, tooling, and technical approaches. Applying strong foundational DFIR skills and a meticulous, detail oriented approach to analysis, the Managing Consultant provides trusted expertise and guidance to clients during complex and high pressure situations.

The role also includes line management responsibilities, with opportunities to mentor, support, and develop junior consultants, fostering technical excellence, professional growth, and a collaborative team culture.

Key Responsibilities
  • Leadership in coordinating a team of experienced DFIR consultants deployed during an engagement, promoting effective collaboration, clear communication, and high quality delivery throughout investigative and incident response engagements.
  • Actively responding to cyber security incidents, providing hands on technical analysis, containment, mitigation, and remediation support to clients.
  • Demonstrating calm, confident incident leadership and sound judgement in client Incident Management scenarios, including high pressure and time critical environments.
  • Delivering thorough, high quality incident response investigations that support client decision making and recovery.
  • Collaborating with clients and internal stakeholders to identify, resolve, document, and improve response to security incidents.
  • Delivery of proactive engagements, such as first responder training and technical tabletops to clients to aid in their improvement of handling incidents.
  • Supporting the development of team capability through mentoring, knowledge sharing, and line management of junior consultants.
Skills, Knowledge & Expertise
  • Extensive experience working in incident response, digital forensics, or security operations, with a demonstrable focus on incident response delivery.
  • Proven experience leading teams during cyber incidents, providing clear incident management and technical direction to clients.
  • Strong knowledge of enterprise security controls and common defensive technologies.
  • Ability to design and develop scripts, tooling, or automation to enhance investigative effectiveness and response efficiency.
  • Hands on experience triaging and investigating Windows, Linux, and macOS hosts.
  • Demonstrable experience delivering incident response engagements within cloud environments.
  • Ability to produce clear, high quality written and verbal outputs, including reports, presentations, recommendations, and executive level findings for clients.
  • Relevant professional certifications such as CREST CPIA, CRIA, CCNIA, or CCHIA, and or SANS certifications including GCFA, GNFA, or GCIH.
  • Experience delivering technical tabletop exercises and leading clients through incident scenarios to test and improve processes and response capability.
  • Strong understanding of common enterprise technologies and configurations, including cloud platforms such as Azure, Microsoft 365, AWS, and GCP.