About this role
Due to continued growth, Bridewell's CSIRT is looking for a Senior Incident Responder to support our CNI and other clients. This role will investigate and respond to security incidents, contribute to incident preparation and recovery activities, and help clients strengthen their security posture.
This role focuses on supporting and maintaining incident response capabilities across endpoint, network, and cloud environments for both our SOC services and consulting engagements. The Senior Incident Responder will work with colleagues and clients to deliver effective investigations, improve response processes, and develop their technical expertise.
Requirements
Main Responsibilities:
- Support the delivery and ongoing improvement of incident response services, including maintaining technical documentation, playbooks, and response procedures for endpoint, network, and cloud environments.
- Follow established triage, investigation, and escalation processes when responding to alerts and security incidents across modern hybrid IT environments.
- Investigate security incidents across endpoint, network, and cloud platforms, working with senior responders to identify appropriate containment, remediation, and recovery actions.
- Carry out investigation, containment, and eradication activities for security incidents, escalating complex or high-priority matters when required.
- Support the forensic acquisition, preservation, examination, and analysis of digital evidence from endpoints and other relevant systems, maintaining appropriate evidential handling and investigation records.
- Undertake logical acquisition and forensic analysis of supported mobile devices, including Android, iOS, iPadOS, and Windows devices, using approved tooling and documented processes. Device access may require a valid passcode.
- Work collaboratively with other incident responders and SOC analysts to ensure consistent, high-quality delivery across client environments.
- Support customers in improving their detection and response capabilities across their IT estate.
- Contribute to the development and maintenance of incident response plans and playbooks in line with industry standards and good practice.
- Support and conduct threat hunts across endpoint, network, and cloud environments.
- Perform initial malware analysis and support more detailed analysis where required during incident response activities.
- Contribute to internal knowledge sharing and, where appropriate, technical blogs, webinars, or other industry content.
- Support incident coordination during active incidents, providing clear updates and maintaining accurate investigation records.
Experience :
- Practical experience of incident response, security operations, digital forensics, or a closely related cyber security role.
- Practical knowledge of digital forensic principles, including evidence preservation, forensic acquisition, chain of custody, artefact analysis, and clear documentation of findings.
- Experience using digital forensic tools to examine endpoint or mobile device data is desirable, familiarity with logical mobile extraction using tools such as Magnet AXIOM would be beneficial.
- Working knowledge of enterprise endpoint technologies, network infrastructure, and at least one major cloud platform such as AWS, Azure, or GCP.
- Relevant training or certifications, such as Security Blue Team Level 1 or 2, GCIH, GCFA, or equivalent incident response and digital forensics qualifications, are desirable.
- Experience working in a SOC, CSIRT, MSSP, consultancy, or internal security team is desirable.
- An understanding of incident response within regulated or CNI environments would be beneficial.
- Awareness of common security frameworks and standards, such as NIST CSF, ISO 27001, and the NIS Regulations.
- Ability to communicate technical findings clearly to both technical and non-technical audiences through written reports and verbal updates.
- Familiarity with SOC processes, security monitoring, and incident response procedures across hybrid IT environments.
- Some experience of threat hunting methodologies and tools across enterprise environments.
- A good understanding of common attack techniques, adversary behaviours, and TTPs, including familiarity with frameworks such as MITRE ATT&CK.
This position requires travel both UK and international to client locations, approximately 20-25% of working time, with expenses. The role will require on-call responsibilities as part of the incident response rotation
Benefits
Our vision is to create a safe, inclusive digital world where people and organisations can thrive. Our values of Do the Right Thing, One Team and Above and Beyond emphasises the importance of the part we play in society, and our commitment to our people and clients. Our story to-date has been phenomenal, but success doesn’t end here and as we continue to grow and scale, we want to keep the same culture, passion and commitment to high quality that has enabled us to get this far. Bridewell will provide a great career opportunity with continual development as well as the following:
- 25 Days Holiday - Plus buy and sell options and increasing for long service
- Flexible Working (around core office hours)
- Employee Shareholder Scheme and Performance Reward Model
- Private Healthcare (Bupa)
- Company Pension
- Personal Day & Birthday Off - After 1 year of service
- Family Leave – After 1 year of service
- Enhanced Maternity based on length of service
- Access to a Training Budget
- Life Assurance
- Electric Vehicle Scheme & Cycle to Work Scheme
Location: Bridewell operates a hybrid and flexible working policy, however you will be required to travel to different sites on occasion.
Note: To be eligible for this job you must either hold SC or be eligible and willing to go through security clearance.
Bridewell values diversity in the workplace and is a fair and equal opportunity employer. We are committed to creating an equal and inclusive working environment, with the aim that our employees will be truly representative of all sections of society and each person feels respected and able to give their best.