Consultant, Digital Forensics and Incident Response
Control Risks · London, England, United Kingdom · Hybrid
Posted Sep 2, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
We now have an exciting opportunity for a Consultant to join us in London. As the Consultant you will provide technical expertise and consultative solutions in the field of Digital Forensics, Incident Response, Cyber Security and eDiscovery for our clients. Our clients include Law Firms, Fortune 500 multi-nationals, and Government/Law Enforcement. You will be expected to be a technical lead on cases for our regional and international Discovery & Data Insights teams (DFIR/Legal Technologies/Data Analytics) as well as working closely with our Cyber Response and Crisis Management divisions as well as our Investigations teams. As the Consultant you will also support the business development effort for the department contributing subject matter expertise in articles, presentations and marketing campaigns.
Tasks and Responsibilities
Provide forensic/incident response consultancy and expertise in data collections, investigative/analysis & cyber security services to our clients
To support our Investigation teams across regions
To provide high quality deliverables to our clients in a timely and efficient manner
To ensure work is defensible and to an evidential standard as appropriate for tasks
To provide expert testimony in court as and when required
To be innovative and creative showing initiative in bringing teams together
To anticipate client needs and continually strive for ways to work efficiently
To respond to potential enquiries and convert these into sales leads and proposals
To actively engage in business development and marketing
Must be available for international travel (up to 25% of time)
Requirements
Essential
Previous, demonstrable, technical computer forensics experience for cyber incident response and investigations.
Thorough understanding of best practice procedures (NPCC, NIST, ISO17025) evidence handling, computer systems and tools of the trade
Thorough understanding of both the MITRE ATT&CK and Cyber Kill chain framework, network topology and EDR solutions
Previous expert understanding of multiple operating systems, particularly Microsoft and Linux infrastructure and networking systems, both on-premise and in the cloud, as well as dedicated cloud services such as Microsoft 365, Azure, AWS and Google Workspace
Previous experience and practical use of common computer forensic tools for imaging/acquisition and analysis (for example, Logicube Falcon, Velociraptor, EnCase, FTK, Nuix, X-Ways, Axiom, IEF, Blacklight, Kali, WinFE, DEFT, Cellebrite, XRY)
Expertise in PowerShell scripting, Bash scripts, Python, SQL and data wrangling for log analysis
Established track record for performing forensic collections, involvement in incident response and digital investigations alongside maintaining detailed contemporaneous notes
Production of expert reports and witness statements
Experience in performing mobile device forensics
Providing client-facing communications & consultative services
Preferred
Wide understanding of…