Incident Response & Forensics Lead
Role Summary:
As Anaplan's Incident Response & Forensics Lead, you will lead and improve how we investigate, respond to, and learn from security incidents. This is a senior, hands-on role that combines deep digital forensics and incident response expertise with strong threat intelligence knowledge. You will lead complex investigations, perform forensic analysis, conduct threat hunting, and leverage intelligence to understand who we are up against and how they operate.
You'll help build a mature, intelligence-driven IR capability grounded in a clear understanding of who targets organisations like ours and how they operate, including state-sponsored actors, well-resourced criminal groups, and attackers making growing use of AI.
Your Impact:
Act as technical lead on our highest-severity incidents, owning the investigation end-to-end, from triage and scoping through containment, eradication, recovery, and post-incident review
Perform digital forensic analysis across endpoints, servers, cloud, SaaS, and identity environments, preserving evidence and reconstructing attacker activity and timelines
Apply an intelligence-driven approach to investigations, using what you find to understand adversary tradecraft, likely objectives, and related activity, and using that understanding to guide scoping and response decisions
Work alongside legal, privacy, and communications teams during major incidents, and with external incident response partners where needed
Lead proactive, hypothesis-led threat hunts informed by investigation findings, intelligence, and emerging tradecraft, and turn the results into tested, high-fidelity detections
Produce internal threat reporting that translates what we're seeing in our environment, and across the threat landscape relevant to us, into clear assessments and actions for security teams and leadership
Shape our threat intelligence capability, including intelligence requirements and the sources and tooling that support them, keeping it directly connected to investigation, hunting, and detection work
Expand incident response playbooks, forensic procedures, and evidence handling standards, raise the standard of how we run complex investigations, and coach SOC analysts through live investigations
Use AI as a core part of how you work, building and applying AI-assisted workflows and automation for evidence collection, enrichment, triage, and analysis, and integrating them with our security tooling
Your Skills:
Extensive hands-on experience in digital forensics and incident response, including leading complex, high-severity investigations across hybrid, cloud, and SaaS environments
Practical forensic skills across endpoint, memory, network, log, and cloud evidence, with a sound approach to evidence handling and chain of custody
An intelligence mindset developed through investigative work: you naturally ask who is behind activity, what they want, and what else they're likely to have done, and you can turn investigation findings into intelligence that drives hunting, detection, and reporting
Working knowledge of intelligence analysis fundamentals, such as intelligence requirements, structured analysis, confidence assessments, and models like the Diamond Model and F3EAD, and how they apply to incident response
Familiarity with the cybercrime underground, including how criminal forums and marketplaces, initial access brokers, and ransomware ecosystems operate. Experience safely operating and managing research personas is a strong plus
Experience leading hypothesis-driven threat hunting and converting findings into detections
Demonstrable, hands-on experience using AI in security work, such as building AI-assisted investigation or triage workflows, using LLMs to accelerate analysis, or developing automation and integrations, with a grounded view of where it helps and where it doesn't. Solid scripting ability (e.g. Python) to support this
Good knowledge of SIEM, SOAR, and EDR/XDR platforms and how they support investigation, hunting, and response
Strong understanding of attacker behaviour and the MITRE ATT&CK framework, particularly across enterprise, cloud, and SaaS environments
Ability to explain complex technical findings clearly and concisely, in writing and in person, to executive audiences, including CISO-level stakeholders
Calm, structured judgement during high-pressure incidents, with a drive to share knowledge and raise the capability of the wider team