Skip to main content
AfterDuty

Cyber Incident Responder

CYFOR · Manchester, Greater Manchester

Salary
£40,000 – £50,000Estimated
Type
Full-time
Posted
Yesterday

Overview

Your experience investigating digital evidence and managing incidents in policing gives you a strong foundation for this role, particularly in forensic acquisition, log analysis, and producing evidential reports. The requirement for clear client communication and structured investigation aligns with your interview and case-file skills, though you would need to build specific technical knowledge of cloud environments and EDR tools.

About this role

CYFOR is a leading nationwide provider of cyber security services, digital forensics and eDiscovery. Providing services to all business sectors, including law firms, insurance providers and law enforcement agencies, CYFOR are looking for talented cyber security professionals to lead the growth of our cyber security services.

Here at CYFOR we look for people who can make a real difference, passionate and high performing people who thrive on technology and thinking outside the box.

Our employees are what makes CYFOR truly great, and as they grow so do we.

So if you’d like a varied and highly fulfilling role, working with great colleagues in a fantastic atmosphere, we’d like to hear from you.

The Role

Due to our continued growth, we are looking for an experienced Cyber Incident Responder to add to the CYFOR Secure team.

The ideal candidate will have at least 2 years’ experience responding to and investigating a range of cyber incidents and demonstrate in-depth knowledge of common cyber incident types and threat actor methodologies. You’ll have a deep technical knowledge of incident response, digital forensics, M365, cloud environments and investigations processes, along with excellent client facing skills and a can-do attitude. You’ll also be able to demonstrate flexibility, commitment and integrity.

In return, you’ll receive a salary commensurate with experience; plus training, overtime and excellent career prospects. You’ll enjoy a varied and highly fulfilling role, working with great colleagues in a fantastic atmosphere.

This is a unique opportunity to join a highly successful business that truly focuses on its main asset, its team members.

Security Clearance

Please note that this role will require NPPV3 clearance in addition to National security clearance to SC level. Applicants MUST have been continuously resident in the United Kingdom for the last 5 years. If you do not hold an active SC clearance, please familiarise yourself with the vetting process before applying.

Main responsibilities

· Perform emergency incident response for customers; including containment (credential resets, network quarantine and EDR rollouts) to prevent further compromise and gathering of relevant forensic evidence.

· Investigate forensic evidence from compromised devices and networks to determine the root-cause of incidents and understand the actions taken by threat actors.

· Acquire and investigate server logs, firewall logs, intrusion detection system alerts, traffic logs and host system logs to determine what data has been impacted during a cyber incident using open-source tools and industry standard forensics software.

· Conduct forensic acquisitions from relevant servers and workstations

· Analyse malware to understand and communicate its impact on systems and data

· Delivering high quality technical investigation and forensic reports to clients

· Deliver regular, high-quality updates to clients throughout an investigation

You will also be required to travel at short notice for Cyber Incident response.

Skills and Experience

· Experience collecting forensic evidence from compromised systems.

· Experience investigating cyber incidents to understand malicious activity.

· Proven understanding of the Cyber Kill Chain, MITRE ATT&CK and other information security defence and intelligence frameworks.

· Comprehensive knowledge of incident handling, threat hunting and threat intelligence.

· Ability to correlate events from various sources to create incident timelines.

· Experience in cloud-based infrastructure including Microsoft Azure and Office 365, Amazon AWS, and Google Cloud.

· Excellent client facing skills, with the ability to communicate at all levels, adapting the style of communication to meet the needs of the audience.

· An excellent attitude and the willingness to learn and study for certifications.

· Ability to effectively plan and coordinate projects.

· Excellent written and verbal communication skills,

· An investigative mindset with a high level of attention to detail

· Demonstrate a flexible approach to work and a high level of self-motivation.

· Ability to exercise discretion and confidentiality.

Desirable Skills

· Previous exposure to enterprise scale infrastructure and technology stacks.

· Appropriate incident response certifications (E.g., CREST Intrusion Analyst or Incident Manager)

· Experience deploying and monitoring endpoint protection (e.g. SentinelOne) across a variety of systems during incident response

Benefits

  • Flexible working
  • Company pension scheme (3% employer contribution)
  • 24 Days annual Holiday plus Bank holidays
  • Extra days holiday for your birthday
  • Annual holiday loyalty bonus (increasing to 30 days after 3 years)
  • MediCash Cashplan
  • Life Assurance (Death in Service)
  • Annual Media Subscriptions (from a choice of Netflix HD, Amazon Prime, etc)

Job Type: Full-time

Pay: £40,000.00-£50,000.00 per year

Benefits

  • Additional leave
  • Casual dress
  • Company events
  • Company pension
  • Cycle to work scheme
  • Discounted or free food
  • Free flu jabs
  • Free parking
  • Life insurance
  • On-site parking
  • Work from home

Application question(s)

  • Permanently Resident in United Kingdom for last 5 years?

Experience

  • Cyber Incident Response: 2 years (required)

Work authorisation

  • United Kingdom (required)

Work Location: Hybrid remote in Manchester M24 1SW

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in Manchester

Why this fits a police background — match score 65/100

  • Police experience explicitly valued
  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Digital forensics & cybercrime

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Cybercrime Operational Lead

    HM Revenue & Customs · Manchester

    Full-time

    £65,869 – £72,711Estimated

    This role directly taps into your investigative and cybercrime expertise from policing, requiring you to lead digital forensics, intelligence operations, and complex criminal investigations. Your experience with evidence handling, interviewing, and operational command under pressure translates seamlessly into managing cyber threats and coordinating multi-agency responses at HMRC.

    Posted 9 days ago

  • Threat Analyst

    SCC · Birmingham

    Full-time

    Your background in intelligence analysis and threat assessment from policing maps directly to producing structured threat intelligence deliverables. You are used to researching hostile actors, evaluating sources, and writing concise briefings for different audiences, which is exactly what this role demands. Your incident response experience and disciplined approach to evidence and reporting would let you contribute from day one, while any gaps in specific tooling can be trained.

    Posted Today

  • Full-time

    This role focuses on information security management, risk assessment, and incident response — areas where your experience in operational policing, threat assessment, and managing critical incidents translates directly. Your background in following strict procedures, handling sensitive information, and coordinating multi-agency responses aligns well with the security governance and compliance aspects of the job. While the role requires specific technical cyber security knowledge, your investigative mindset and ability to work under pressure are strong foundations that employers in this sector

    Posted Yesterday

  • Full-time

    Your experience in policing has given you a strong foundation in risk assessment, threat identification, and incident management, which are directly applicable to IT risk management. You are used to working under pressure, making decisions based on incomplete information, and communicating complex risks to senior stakeholders. While you may need to develop specific technical knowledge of IT frameworks like ISO 31000 or NIST, your core skills in evaluating threats, implementing controls, and ensuring compliance are highly transferable to this role.

    Posted Yesterday