Consultant, Digital Forensics and Incident Response

Company: Control Risks
Apply for the Consultant, Digital Forensics and Incident Response
Location: London
Job Description:

Overview

As a Consultant in London, you will deliver forensic, incident response, cyber security, and eDiscovery expertise to a diverse client base, shaping outcomes for law firms, multinational corporations, and government bodies. You will lead technical efforts on cases within DFIR/Legal Technologies/Data Analytics, collaborating with cyber response, crisis management, and investigations teams. You’ll contribute to business development through expert insights in articles, talks, and campaigns. This role blends hands-on investigation work with client engagement, travel, and cross‑functional teamwork to drive meaningful impact.

Pay / Benefits

  • Competitive compensation
  • Discretionary global bonus
  • Hybrid working arrangements
  • Flexible and remote work options
  • Equal opportunities employer
  • Support for reasonable adjustments in recruitment

Responsibilities

  • Provide forensic and incident response consultancy across data collections, investigations, and cybersecurity services
  • Support Investigation teams across regions
  • Deliver high-quality, timely deliverables defensible to evidential standards
  • Provide expert testimony in court when required
  • Collaborate across teams to drive innovative solutions and prepare for client needs
  • Identify opportunities with potential clients and convert them into sales leads and proposals
  • Engage in business development and marketing activities
  • Travel internationally up to 25%

Key requirements

  • Extensive technical computer forensics experience for cyber incident response and investigations
  • Strong understanding of best practice procedures for evidence handling (NPCC, NIST, ISO17025)
  • Knowledge of MITRE ATT&CK and Cyber Kill Chain frameworks; network topology and EDR solutions
  • Experience with Microsoft and Linux environments, on-premise and cloud services (Microsoft 365, Azure, AWS, Google Workspace)
  • Practical use of common forensic tools for imaging, acquisition, and analysis (e.g., Logicube Falcon, Velociraptor, EnCase, FTK, Nuix, X-Ways, Axiom, IEF, Blacklight, Kali, WinFE, DEFT, Cellebrite, XRY)
  • Expertise in PowerShell, Bash, Python, SQL and data wrangling for log analysis
  • Proven track record in forensic collections, incident response and digital investigations with detailed contemporaneous notes
  • Experience producing expert reports and witness statements
  • Mobile device forensics experience
  • Strong client-facing communication and consultative services
  • Excellent written and verbal communication
  • Presentation skills
  • Client-facing consultancy
  • PowerShell scripting
  • Bash scripting
  • Python

Posted: September 14th, 2026