Skip to main content
Post your CV and find your next job on Indeed!

Forensic Examiner jobs

Sort by: -

People also searched:

forensic science

Job Post Details

Corporate Forensic Analyst - job post

CYFOR
Remote
Responded to 51-74% of applications in the past 30 days, typically within 1 day.

Job details

Shift and schedule

  • Overtime

Benefits

Pulled from the full job description

  • Company pension

Full job description

Corporate Forensic Analyst
Location: Remote/Hybrid (UK-based)

The Role

Due to our continued growth, we are looking for an experienced Corporate Forensic Analyst to join the CYFOR Secure Incident Response team.

The successful candidate will primarily focus on corporate forensic investigations involving dead-box analysis across computers, mobile devices, cloud platforms and email environments. The role is centred around the forensic investigation and evidential analysis side of cyber security incidents, supporting clients through structured and defensible digital forensic examinations.

You will also work closely with the wider Incident Response team, supporting investigations into business email compromise (BEC), ransomware and other cyber incidents where forensic analysis is required. While the role is not primarily an incident response position, there will be opportunities to assist live investigations and support broader response activities where appropriate.

The ideal candidate will have experience conducting forensic examinations across Windows systems, mobile devices and cloud-based environments, with excellent attention to detail, strong reporting skills and a professional client-facing approach. You will also demonstrate integrity, flexibility and the ability to manage sensitive investigations with discretion.

In return, you'll receive a salary commensurate with experience; plus training, overtime and excellent career prospects. You'll enjoy a varied and highly fulfilling role, working with great colleagues in a fantastic atmosphere.

This is a unique opportunity to join a highly successful business that truly focuses on its main asset, its team members.

Main Responsibilities

  • Conduct forensic examinations of desktop computers, laptops, servers and mobile devices using forensically sound methodologies.
  • Acquire, preserve and analyse digital evidence from Windows systems, mobile devices, cloud platforms and email environments while maintaining evidential integrity.
  • Perform dead-box forensic investigations involving deleted data recovery, user activity analysis, timeline reconstruction and artefact examination.
  • Investigate cloud and email platforms including Microsoft 365, Exchange Online and associated audit logs to identify suspicious or malicious activity.
  • Support investigations into ransomware, business email compromise (BEC), insider threats, data theft and unauthorised access incidents.
  • Analyse forensic artefacts including browser history, registry data, event logs, user activity, USB usage, installed applications and communication records.
  • Conduct mobile device examinations using specialist forensic tooling including Cellebrite solutions.
  • Use forensic and case management tooling including Magnet Axiom and Salesforce throughout investigations and evidence handling workflows.
  • Produce high-quality forensic reports suitable for internal stakeholders, legal teams, law enforcement and corporate clients.
  • Assist with expert witness statements and provide court attendance when required.
  • Support the Incident Response team during active cyber incidents where forensic expertise is required.
  • Maintain accurate chain of custody documentation and evidence handling procedures throughout investigations.
  • Deliver clear and concise updates to clients and stakeholders throughout engagements.
  • Assist with forensic triage and evidence collection during onsite and remote engagements when required.
  • Contribute to the continuous improvement of forensic methodologies, processes and internal capabilities.
  • Keep up to date with emerging threats, forensic techniques and evolving technologies across endpoint, mobile and cloud ecosystems.
  • Support knowledge sharing and mentoring activities across the wider team where appropriate.


Skills and Experience

  • Minimum 3 years experience in digital forensics or cyber investigations.
  • Experience conducting dead-box forensic investigations across Windows systems and mobile devices.
  • Experience collecting, preserving and analysing digital evidence using industry-standard forensic methodologies.
  • Experience using Magnet Axiom, Encase or X-Ways and other digital forensic tooling.
  • Knowledge of Microsoft 365, Exchange Online and cloud-based investigations.
  • Ability to analyse forensic artefacts and reconstruct user and system activity timelines.
  • Understanding of ransomware and business email compromise investigations.
  • Experience producing detailed technical and client-facing forensic reports.
  • Excellent written and verbal communication skills.
  • Strong attention to detail and investigative mindset.
  • Ability to handle sensitive and confidential investigations professionally.
  • Excellent client-facing skills with the ability to communicate effectively at all levels.
  • Ability to work independently and manage multiple investigations simultaneously.
  • Demonstrate a flexible approach to work and a high level of self-motivation.
  • Ability to travel occasionally where required for onsite forensic collections or client support.

Desirable Skills

  • Experience with cloud forensic investigations involving Microsoft Azure or AWS.
  • Previous experience supporting cyber incident response investigations.
  • Experience with email header analysis and phishing investigations.
  • Knowledge of forensic acquisition methodologies for Apple and Android devices.
  • Experience with forensic scripting or automation using PowerShell or Python.
  • Understanding of evidential procedures and legal requirements relating to digital evidence.
  • Previous experience providing expert witness statements or attending court proceedings.
  • Relevant certifications such as GCFA, GCFE, CCE, CFCE or equivalent digital forensic qualifications.
  • Experience working within corporate, legal or law enforcement investigation environments.

Benefits

  • Flexible working
  • Company pension scheme (3% employer contribution)
  • 24 Days annual holiday plus Bank holidays
  • Extra day's holiday for your birthday
  • Annual holiday loyalty bonus (increasing to 30 days after 3 years)
  • MediCash Cashplan
  • Life Assurance (Death in Service)
  • Annual Media Subscriptions (from a choice of Netflix HD, Amazon Prime, etc)
  • An annual anniversary gift, rising in value each year


Security Clearance

Please note that this role may require National Security Vetting to SC level depending on client requirements. Applicants may be required to undergo background screening and vetting checks where necessary.

Let Employers Find YouUpload Your Resume