KEYSTONE CYBER

Home Disciplines Digital forensics & incident response

DIGITAL FORENSICS & INCIDENT RESPONSE

Digital forensics and incident response recruitment

DFIR hiring is unforgiving. The work is judged during the worst week a business has, and the difference between a competent responder and a confident one is only visible under pressure. We screen for evidence of real incidents worked, not incident-response training attended.

What we place

INCIDENT RESPONDER
Owns live incidents end to end: scoping, containment, eradication, and the write-up that has to survive scrutiny afterwards.
FORENSIC ANALYST
Disk, memory and mobile acquisition and analysis. Evidence handling that holds up in a disciplinary hearing or a courtroom.
MALWARE ANALYST
Static and dynamic analysis, reverse engineering, extracting indicators that feed detection back into the SOC.
CLOUD FORENSICS
Investigation in AWS, Azure and M365 where the disk you wanted no longer exists. A scarce and fast-growing specialism.
IR LEAD / MANAGER
Runs the response function, the retainer relationships and the communication with executives and regulators.
CONSULTANCY DFIR
Billable responders in MSSP and consulting practices, working multiple client environments a year.

How we screen

We ask candidates to talk us through an incident they responded to: how it was detected, what they scoped first, what they got wrong, and how the investigation closed. Real responders answer this readily and with caveats. People who have only shadowed a response give a clean narrative with no dead ends in it.

The second test is temperament. DFIR involves being woken up, working with incomplete information, and telling senior people things they do not want to hear. We ask directly about on-call reality and about the last time someone had to escalate bad news, because both are where DFIR placements fail.

The market, honestly

Genuine DFIR depth is thin in both our markets. South Africa has a small number of consultancies and banks doing real response work, so most experienced responders in the country know each other; that makes the search relational rather than volume-driven. In the UK, competition comes from established IR practices and from vendors who can offer variety no single in-house team matches.

The common substitution is to hire a strong SOC analyst and expect forensics. Sometimes that works, particularly at L3 with the right mentoring in place, and we will say when we think it will. Often it just means a first major incident handled by someone learning on the job.

If a brief wants court-defensible forensics, malware reverse engineering and cloud investigation in one mid-level hire, we will tell you which two you can realistically get.

Where we recruit

Cape Town and Johannesburg across South Africa, and London and the wider United Kingdom.

Common questions

What is the difference between DFIR and SOC hiring?

A SOC analyst works alerts inside a monitoring function. A DFIR specialist takes over when something is confirmed and needs to be scoped, contained and reconstructed. The skill sets overlap at senior level and diverge sharply on evidence handling and reporting.

Do you place forensic analysts for legal and HR investigations?

Yes. Corporate investigations, employee misconduct and fraud matters need documented chain of custody and analysts who can present findings to non-technical panels. It is a different screen from breach response.

Which certifications matter in DFIR?

GCFA, GCFE, GCIH and GREM are the ones clients recognise, and vendor training on your specific forensic tooling helps. None of them substitute for a candidate who can describe the incidents they have actually worked.

Can you recruit for incident response retainers and consultancies?

Yes. Billable consulting DFIR is a different sell to in-house response, and we screen for the client-facing and reporting load explicitly.

Related disciplines

Talk to us about your search

A short conversation is usually enough to tell you whether we can help.