Incident Response / Digital Forensic Consultant.

  • develop
  • contract
  • Amsterdam, North Holland
  • £70-£75

Incident Response/Digital Forensics Consultant (Reactive Forensic)

Location - Hybrid, Amsterdam

Contract Length - 12-months

Start Date - ASAP

Industry - Cyber Security/Consulting

Are you a hands on DFIR professional who thrives under pressure and enjoys diving into high-stakes investigations? We're looking for a Senior Incident Response and Digital Forensics Consultant to support a major cybersecurity function working with high profile enterprise clients across Europe.

This is a hybrid role, based in Amsterdam with occasional travel across the UK and Europe required.

You'll serve as a tactical expert in live incident response and digital forensic investigations. You'll work closely with other forensic analysts, cyber risk consultants and client stakeholders to help organisations respond to and recover from cyber threats.

You'll also lead proactive resilience engagements, running breach simulations, improving IR plans and advising senior leadership on their cyber strategy.

Key Responsibilities Include

Reactive Forensic Investigations:

  • Leading large-scale digital forensic investigations into major cyber incidents
  • Analysing endpoints, networks, memory, and cloud environments to determine the root cause and extent of breaches
  • Acting as a technical SME in one or more key areas (host, memory, network, mobile, or cloud forensics)
  • Producing detailed, court-admissible forensic reports for clients and stakeholders

Proactive Resilience Work:

  • Conducting incident response capability assessments (IRCA) and helping clients build robust IR plans
  • Running tailored tabletop exercises and breach simulations for technical and executive teams
  • Advising leadership teams (including C-suite) on cyber risk, incident readiness, and long-term resilience strategies
  • Creating realistic threat scenarios such as ransomware attacks, insider threats, or APT simulations

Experience Required

  • Solid background in digital forensics and incident response (DFIR), ideally in a consulting or client-facing role
  • Comfortable working in high-pressure, flexible environments with sensitive or confidential information
  • Practical experience with tools and methodologies used in forensic analysis (e.g. EnCase, FTK, Velociraptor, XDR/EDR tools like CrowdStrike, SentinelOne, etc.)
  • Strong knowledge of Windows, Linux, macOS, or other enterprise operating systems
  • Fluent in English (verbal and written)
  • Willing to travel on short notice

Desirable Experience

  • Fluency in another European language (Dutch, German, French, etc.)
  • Experience in penetration testing, red teaming, or reverse engineering
  • Previous work in law enforcement, military intelligence or professional services
  • Certifications such as GCFA, GCFE, GCIH, GNFA, CISM or similar
  • Prior experience working in high pressure, incident response teams or PFI engagements