Incident Response & Forensics Lead

Anaplan · London, United Kingdom · Other

Posted 2026-10-09

Apply for this role →

Role Summary:

As Anaplan's Incident Response & Forensics Lead, you will lead and improve how we investigate, respond to, and learn from security incidents. This is a senior, hands-on role that combines deep digital forensics and incident response expertise with strong threat intelligence knowledge. You will lead complex investigations, perform forensic analysis, conduct threat hunting, and leverage intelligence to understand who we are up against and how they operate.

You'll help build a mature, intelligence-driven IR capability grounded in a clear understanding of who targets organisations like ours and how they operate, including state-sponsored actors, well-resourced criminal groups, and attackers making growing use of AI.

Your Impact:

Act as technical lead on our highest-severity incidents, owning the investigation end-to-end, from triage and scoping through containment, eradication, recovery, and post-incident review

Perform digital forensic analysis across endpoints, servers, cloud, SaaS, and identity environments, preserving evidence and reconstructing attacker activity and timelines

Apply an intelligence-driven approach to investigations, using what you find to understand adversary tradecraft, likely objectives, and related activity, and using that understanding to guide scoping and response decisions

Work alongside legal, privacy, and communications teams during major incidents, and with external incident response partners where needed

Lead proactive, hypothesis-led threat hunts informed by investigation findings, intelligence, and emerging tradecraft, and turn the results into tested, high-fidelity detections

Produce internal threat reporting that translates what we're seeing in our environment, and across the threat landscape relevant to us, into clear assessments and actions for security teams and leadership

Shape our threat intelligence capability, including intelligence requirements and the sources and tooling that support them, keeping it directly connected to investigation, hunting, and detection work

Expand incident response playbooks, forensic procedures, and evidence handling standards, raise the standard of how we run complex investigations, and coach SOC analysts through live investigations

Use AI as a core part of how you work, building and applying AI-assisted workflows and automation for evidence collection, enrichment, triage, and analysis, and integrating them with our security tooling

Your Skills:

Extensive hands-on experience in digital forensics and incident response, including leading complex, high-severity investigations across hybrid, cloud, and SaaS environments

Practical forensic skills across endpoint, memory, network, log, and cloud evidence, with a sound approach to evidence handling and chain of custody

An intelligence mindset developed through investigative work: you naturally ask who is behind activity, what they want, and what else they're likely to have done, and you can turn investigation findings into intelligence that drives hunting, detection, and reporting

Working knowledge of intelligence analysis fundamentals, such as intelligence requirements, structured analysis, confidence assessments, and models like the Diamond Model and F3EAD, and how they apply to incident response

Familiarity with the cybercrime underground, including how criminal forums and marketplaces, initial access brokers, and ransomware ecosystems operate. Experience safely operating and managing research personas is a strong plus

Experience leading hypothesis-driven threat hunting and converting findings into detections

Demonstrable, hands-on experience using AI in security work, such as building AI-assisted investigation or triage workflows, using LLMs to accelerate analysis, or developing automation and integrations, with a grounded view of where it helps and where it doesn't. Solid scripting ability (e.g. Python) to support this

Good knowledge of SIEM, SOAR, and EDR/XDR platforms and how they support investigation, hunting, and response

Strong understanding of attacker behaviour and the MITRE ATT&CK framework, particularly across enterprise, cloud, and SaaS environments

Ability to explain complex technical findings clearly and concisely, in writing and in person, to executive audiences, including CISO-level stakeholders

Calm, structured judgement during high-pressure incidents, with a drive to share knowledge and raise the capability of the wider team

Apply for this role →

← Back to all jobs