Senior Incident Responder (DFIR) – Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland

Company: Tesco
Apply for the Senior Incident Responder (DFIR) – Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland
Location: Welwyn Garden City
Job Description:

Overview

In this role you will lead DFIR investigations to understand the full extent of security incidents and guide containment and recovery. You will collaborate with security operations, threat intelligence and engineering teams to protect Tesco’s estate, translating complex findings into actionable decisions for leadership. As a senior responder, you’ll also automate workflows and innovate detection and prevention capabilities. You will model best practice for engineers and analysts while driving a security-focused culture.

Pay / Benefits

  • Annual bonus up to 20%
  • Holiday 25 days + personal day + bank holidays
  • Private medical insurance
  • Maternity/adoption leave 26 weeks (full pay) + 13 weeks statutory
  • 6 weeks fully paid paternity leave
  • 24/7 virtual GP and EAP for you and family

Responsibilities

  • Perform host, network, and cloud-based forensic analysis to understand incidents and drive containment, remediation, and recovery
  • Support incident managers with root cause analysis and recommendations for detection and prevention controls
  • Enhance processes and develop new methods to deliver DFIR services aligned with business tech requirements
  • Lead intelligence-based threat hunts to uncover anomalous behaviour and raise detections for the internal programme

Key requirements

  • 4+ years of relevant experience
  • Experience responding to incidents in large-scale on-premises and cloud environments (Azure preferred)
  • Forensic analysis across Windows, MacOS, and Unix with deep OS understanding
  • Static and dynamic analysis of suspicious scripts and executables
  • Experience with EDR, SOAR, and SIEM
  • Critical thinking and demonstrated ability to lead technical investigations
  • Calm, professional handling of high-pressure situations
  • Proficiency in at least one programming or scripting language
  • Clear and concise communication of technical information
  • Strong leadership and role-model behavior
  • Ability to work under pressure with composure
  • Azure cloud environment
  • Windows, MacOS, and Unix for forensics
  • Static and dynamic analysis of malware/scripts

Posted: September 15th, 2026