At WithSecure(TM), we protect businesses all over the world. Our SaaS solutions safeguard against modern cyber threats, and our innovative Co-security approach reflects our belief that true protection requires collaboration and shared expertise. No one can solve every cyber security problem alone. Our vision is to become Europe's flagship in cyber security. Every day, our talented teams work to prevent cyber extortion, secure critical infrastructure, and prevent misuse of sensitive data. At WithSecure, it's our people who make us exceptional - a diverse community that values passion, purpose, and a commitment to workplace well-being. If you're ready to make an impact with a company that's transforming cybersecurity, we'd love to hear from you.
As a Principal Incident Response Investigator, you will be at the forefront of our IR practice, leading complex, high-profile cyber incident engagements for clients across government, critical national infrastructure, and the private sector.
This senior role requires exceptional technical expertise, the ability to manage incidents under pressure, and strong communication skills to brief both executives and technical stakeholders. Due to the sensitive nature of much of our work, DV clearance (or the ability to attain it) is essential, and ChCSP - Incident Response certification (or the ability to attain) is highly desirable.
You will serve as a trusted advisor to our clients, guiding them through critical incidents and helping them strengthen their resilience. Internally, you will drive capability development, mentor investigators, and contribute thought leadership to the wider security community.
Key Responsibilities
Client-Facing Investigations: Lead end-to-end incident response engagements, from triage and containment to forensic analysis and recovery.
Incident Leadership: Act as incident commander/advisor for major client breaches, co-ordinating efforts across client stakeholders, third parties, and law enforcement.
Forensic Expertise: Conduct advanced forensic investigations across endpoints, servers, networks, cloud platforms, and SaaS environments.
Threat Attribution: Analyse adversary behaviour and integrate threat intelligence to inform attribution, client reporting, and proactive defences.
Executive Engagement: Deliver concise, risk-focused briefings to client executives, boards, and regulators during and after incidents.
Advisory Role: Provide clients with guidance on incident readiness, detection engineering, and response capability improvements.
Playbook & Tooling Development: Evolve methodologies, tools, and processes to ensure delivery excellence and repeatability.
Mentorship & Leadership: Coach and mentor junior investigators and consultants, developing the next generation of responders.
Knowledge Sharing: Contribute to white papers, conference talks, and internal knowledge repositories to advance our consultancy's reputation and capabilities
What are we looking for?
MNCJobs.co.uk will not be responsible for any payment made to a third-party. All Terms of Use are applicable.