Digital Forensics Specialist Location: Cheltenham, Gloucestershire (hybrid working) We’re seeking a highly skilled Digital Forensics Specialist to join our Cyber Incident Response Team. In this pivotal role, you will lead forensic acquisition, analysis, and evidence preservation across endpoint, cloud, identity, and network environments. You’ll play a critical part in high-severity incident response investigations, providing deep technical expertise, uncovering attacker activity, and strengthening the organisation’s overall forensic readiness. If you thrive in complex investigations, excel at uncovering the truth hidden in digital artifacts, and enjoy working in a fast-paced cyber defence environment - this role is for you. Key Responsibilities: Conduct forensic acquisition and analysis across: Windows, Linux, and macOS endpoints, Cloud environments (e.g., M365, Azure), Email systems and mobile devices. Collect and preserve evidence following chain-of-custody and legal standards. Perform disk, filesystem, and memory forensics including: Process analysis, persistence identification, malware process tree investigation, registry and artifact analysis, and timeline reconstruction. Support all phases of incident response, from detection through post-incident review. Provide expert forensic insight during high-severity cyber incidents. Analyse endpoint and cloud telemetry to determine root cause, attack paths, and impact. Document clear, defensible forensic reports and investigation summaries. Identify malicious scripts, binaries, macros, and LOLBin activity. Collaborate with threat intelligence teams to map findings to known campaigns or malware families. Recommend detection improvements and develop SIEM/XDR analytics based on forensic findings. Build KQL-based hunting queries to identify hidden or emerging threats. Contribute to IR playbooks and broader forensic readiness initiatives. Experience Required: 5 years hands-on experience in digital forensics or incident response. Proven forensic acquisition and analysis experience in enterprise environments. Strong background in cloud forensics (M365/Azure preferred). Experience building timelines from diverse data sources (endpoint, cloud, email, network). Practical knowledge of industry tools and frameworks such as: KAPE, Velociraptor, Autopsy, EnCase, FTK, Cellebrite, Magnet Axiom, Volatility/memory forensics tools, and Sysinternals Suite (Autoruns, Procmon, PsTools). Qualifications & Skills: Bachelor’s degree in Cybersecurity, Digital Forensics, Computer Science, or related field (or equivalent experience). Preferred certifications include: GIAC GCFA, GREM, GDAT, GCIH, GCIA, Microsoft SC-200, SC-300, AZ-500, and CHFI, CFCE, or equivalent DFIR credentials. Strong understanding of: Disk structures, registry hives, OS and browser artifacts, attacker TTPs mapped to MITRE ATT&CK, and windows artifacts such as Event Logs, Prefetch, Shimcache, Amcache, MFT, USN Journal. Proficiency in memory forensics using Volatility or equivalent tools. Ability to identify persistence, privilege escalation, lateral movement, and malicious execution chains. Experience analysing M365 indicators (MailItemsAccessed, mailbox rules, token misuse, OAuth abuse, anomalous messaging). Ability to pivot across investigative data sources including: Defender XDR, Unified Audit Logs (UAL), Graph API, Microsoft Sentinel Spirax Group is a FTSE100 and FTSE4Good multi-national industrial engineering Group with expertise in the control and management of steam, electric thermal solutions, peristaltic pumping and associated fluid technologies. Our Purpose is to create sustainable value for all our stakeholders as we engineer a more efficient, safer and sustainable world. Our technologies play an essential role in critical industrial processes and industrial equipment across industries as diverse as Food & Beverage, Pharmaceutical & Biotechnology, Power Generation, Semiconductors and Healthcare. With customers in 165 countries, we provide the solutions that sit behind the production of many items used in daily life, from baked beans to mobile phones! Our Purpose, supported by our inclusive culture and Values, unites us, guides our decisions and inspires us everywhere that we operate. We support our colleagues to make their difference for each other as well as customers, communities, suppliers, our planet and shareholders by creating a truly equitable working environment where everyone feels included. Benefits You will receive a competitive salary (and a discretionary bonus), flexible working and excellent benefits including 27 days holiday allowance (before bank holidays), 3 days’ paid volunteering leave, comprehensive private healthcare, enhanced pension plan, life assurance, optional participation in a Share Ownership Plan, free onsite parking, flexible benefits, and access to a personal discounts’ portal. We also offer a range of additional support and benefits through our Everyone is Included Group Inclusion Plan, detailed below. Everyone is Included at Spirax Group We are passionate about creating inclusive and equitable working cultures where everyone can be themselves and achieve their full potential. For us, that means supportive teams and strong relationships where everyone’s contribution is valued - across social and cultural backgrounds, ethnicities, ages, genders, gender identities, abilities, neurodiversity, sexual orientation, religious beliefs, and everything else that makes us human and unique. We want everyone to be able to make their difference here, so we will always consider requests for flexible working. We know that everyone needs some extra help from time to time too, so we have introduced a range of additional benefits through our Group Inclusion Commitments. These include gender-neutral parental leave, 15 days of extra paid caregiver leave, paid time off and support for anyone experiencing pregnancy loss or domestic abuse, menopause-friendly workplace principles and more. Learn more at www.spiraxgroup.com/en/life-at-spirax/our-inclusive-group/our-inclusion-commitments. We are also a Disability Confident Committed Employer. If you would like to apply using this scheme, please select this option in our application form or notify our recruitment partners.