Skip to main content
AfterDuty

Cyber Response and Recovery - Assistant Manager (Reactive)

KPMG · London, Greater London

Type
Full-time
Posted
3 days ago

Overview

Job details *Location:*London, Manchester *Capability:*Advisory *Experience Level:*Associate/Assistant Manager *Type:*Full Time *Business Area:*Cyber *Contract type:*Permanent Job description Cyber Response & Recovery Assistant Manager (Reactive DFIR) This role requires current SC or DV clearance,…

About this role

Job details

*Location:*London, Manchester

*Capability:*Advisory

*Experience Level:*Associate/Assistant Manager

*Type:*Full Time

*Business Area:*Cyber

*Contract type:*Permanent

Job description

Cyber Response & Recovery Assistant Manager (Reactive DFIR)

This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance.

The Cyber Response & Recovery Assistant Manager role will be working in the Cyber Response Services (CRS) Team within our Advisory practice.

Your specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a junior case manager on smaller cases, or part of a team (reporting to a case manager or senior case manager) on larger cases.

This is a hands-on role, and an opportunity to join a high performing team that works with a wide variety of clients, as KPMG are one of just nine tier 1 responders in the UK. As such, you will gain a huge amount of experience in a short space of time and will also have the opportunity to be put through a range of security certifications.

In this role we are looking for a person who can demonstrate an emerging strong technical background, experience in incident response and digital forensics and is looking to grow into an incident response manger role as part of a growing team. You will be expected to work in a team where there are a number of incident response cases ongoing.

When not responding to incidents, you may be helping our clients to build their in-house incident response capabilities, which could include: building and developing cyber-response tools, authoring and adapting runbooks/playbooks, assessing the incident response maturity, assisting in table-top cyber-scenario exercises. When not engaged in client work, you will be helping to develop our own delivery capability, including operational efficiency, standard operating procedures, team learning and development, tooling and platforms, lab development and orchestration.

Candidates should have a proven track record of incident management, with a strong competency in digital forensics. KPMG will provide training and coaching to help you continually improve both your management and technical skills. Strong technical competency and experience of managing a range of complex cyber incidents; from ransomware to advanced network intrusions is a pre-requisite.

Our clients expect that cyber-incidents will be tackled with urgency, therefore, there is an expectation that you will be flexible in terms of working hours and be on call (on a rotation basis). In addition, you should be prepared to travel on short notice for periods up to 2 or 3 weeks at a time.

Above all, KPMG is looking for someone who is passionate about helping our clients with their cyber security challenges, often at a time of critical need. In return, we are committed to helping you to enjoy the role and develop your skills and career within the KPMG with the objective of progressing into a senior leadership role.

Why join us?*

One of only nine UK Tier 1 incident response providers

Access to nationally significant incidents

Exposure across government and critical infrastructure

Investment in certifications and training

Opportunity to shape a rapidly growing capability

What will you be doing?*

Perform incident response activities during cyber security incidents for our clients (this includes being available to work on-call monthly).

Carry out digital forensics of relevant incident data (disk, volatile memory, network packets, log files).

Maintain a current view of the cyber threat and being able to advise clients on the threat landscape and attacks which may be relevant to them.

Liaising with clients on delivery, implementation and project issue.

Ability to generate well-structured responses to bids and requests for proposals.

The Person*

You should have a strong background in cyber-security and incident response. For example: You should be able to guide a client through an unstructured incident response process (such as an advanced network intrusion) – managing resources and defining objectives at each stage of the incident response process; scoping and triage, containment, evidence preservation and extraction, eradication, recovery, forensic analysis and investigation.

A broad understanding of the cyber security threat landscape.

Strong technical background in computers and networks, and programming skills.

Proven experience of dealing with cyber security incidents and associated response measures.

Understanding of a wide range of information security and IT methodologies, principles, technologies and techniques.

Excellent interpersonal, written and communication skills.

Skills we’d love to see/Amazing Extras:*

The successful candidate will demonstrate competency in computing and networks as well as in cyber-security either by having the relevant work experience, completed a degree or obtained industry relevant certification. Therefore the qualifications below should be seen as means to demonstrate competency and not as a requirement.

Preferred

Incident management certifications such as

CREST Certified Incident Manager (CCIM)

GIAC Certified Incident Handler (GCIH)

CREST Certified Practitioner Intrusion Analyst (CPIA)

Degree level qualified, MSc in Information Security, IT or relevant STEM subjects.

Our core hubs for this role are either

London (Canary Wharf); or

Manchester (St Peter’s Square).

You must be within commutable distance to one of these locations. Current KPMG policy is 60% of the week with clients or our offices, 40% elsewhere (that can include working from home).

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 90/100

  • Incident command & response
  • Investigative casework
  • Digital forensics & cybercrime
  • Working to legislation & regulation
  • Training & coaching delivery

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • IT Security Specialist

    Montu Group · London

    Full-time

    £55,000 – £60,000Estimated

    What is the job? Montu UK is entering an exciting new phase in its security journey: creating an independent, future-ready architecture for the UK and Europe.

    Posted 3 days ago

  • Security Analyst

    Kubrick Group · London

    Full-time

    The opportunity Join us at the forefront of cyber defence, where you'll play a critical role in protecting our business from evolving threats. You'll proactively monitor, investigate and respond to security incidents using Microsoft Sentinel, Microsoft Defender and leading EDR technologies, working…

    Posted 3 days ago

  • SOC Lead

    NCC Group · London

    Contract

    Description We are looking for a proactive SOC Analyst to monitor, detect, investigate, and respond to cyber security threats using the Splunk Enterprise Security toolset.

    Posted 3 days ago

  • Head of IT

    metropolitan gaming · London

    Full-time

    About Us Metropolitan Gaming is about more than the games or the buzz of the venue. It’s about energy. Atmosphere. Service that’s sharp and in sync with the moment.

    Posted 4 days ago