🎁 Before you apply, rehearse this interview. Create your free WorkMundi account and get an Interview Training on HelpsYouSpeak — no cost, no card. I want my training →
About UsACE Money Transfer is a UK-based multinational company headquartered in Manchester, United Kingdom. The company provides online remittance services to individuals across 29 countries in the UK, Europe, Canada, and Australia, enabling customers to send money securely to more than 100 countries worldwide. Role SummaryThe DFIR Analyst owns the Digital Forensics and Incident Response (DFIR) function at ACE Money Transfer. This role is responsible for receiving and acknowledging security incidents reported through any channel, triaging and investigating them, performing forensically sound acquisition and analysis of digital evidence, identifying the root cause, attack vector, and business impact, delivering clear remediation recommendations, and defining preventive controls to reduce the likelihood of recurrence. The role combines the rigor of digital forensicsincluding evidence preservation, forensic imaging, chain of custody, and deep host, network, and memory analysiswith the fast-paced demands of incident response, including containment, eradication, and recovery. The position operates within ACE's Information Security Management System (ISMS) and supports the organization's dual-jurisdiction regulatory obligations across the UK (FCA and UK GDPR) and Ireland (CBI, DORA, and EU GDPR), with PCI DSS v4.0.1 also within scope. Every investigation must produce a defensible, well-documented outcome capable of withstanding regulatory, legal, and audit scrutiny. Key ResponsibilitiesIncident Intake & TriageMonitor and respond to security incidents reported through any channel, including SIEM/SOAR alerts, email, ticketing systems, phishing reports, the service desk, direct escalations, or automated detection tools.Acknowledge reported incidents within defined SLA timeframes and accurately record them in the incident or case management system.Perform initial triage to classify severity, priority, and scope, and determine whether an event is a false positive, a security event, or a confirmed incident requiring a forensic response.Digital ForensicsPerform forensically sound acquisition and preservation of digital evidence across endpoints, servers, mobile devices, cloud environments, network infrastructure, and email systems.Create and verify forensic images (disk, memory, and logs) using write blockers and cryptographic hashing to ensure evidence integrity and admissibility.Conduct host forensics, including file system, registry, event log, and artifact analysis, as well as memory forensics, network packet analysis, and log analysis to reconstruct attack timelines.Perform malware triage and behavioral analysis in a controlled environment to determine malware capabilities, persistence mechanisms, and overall impact.Maintain strict chain-of-custody procedures and evidence-handling practices to support forensic, regulatory, and legal requirements.Investigation & AnalysisConduct end-to-end investigations of confirmed security incidents by correlating forensic evidence across SIEM, endpoints, networks, identity platforms, email systems, and cloud telemetry.Identify the root cause, initial access vector, affected assets and accounts, attack path, blast radius, lateral movement, data accessed or exfiltrated, and overall business impact.Map observed adversary activity to the MITRE ATT&CK framework and enrich indicators of compromise (IOCs) using threat intelligence sources.Determine the full scope of compromise and confirm whether personal data or cardholder data has been affected to support regulatory notification decisions.Containment, Eradication & RecoveryExecute or coordinate containment activities (such as host isolation, session revocation, credential resets, and blocking actions) within the approved bounded-autonomy framework, escalating for human approval where required.Lead or coordinate the eradication of attacker persistence mechanisms, malware, and unauthorized accounts, ensuring the environment is fully remediated.Provide clear, practical, and actionable remediation guidance to asset owners, IT teams, and system administrators.Verify the effectiveness of remediation efforts, support service restoration, and confirm the return to normal operations before formally closing incidents.Prevention & Continuous ImprovementRecommend and support the implementation of preventive controls and detection improvements to reduce the likelihood of recurring incidents.Propose new or optimized detection rules, forensic collection methods, incident response playbooks, and automation to strengthen DFIR capabilities.Maintain and enhance DFIR runbooks, forensic toolkits, evidence-handling procedures, and the SOC knowledge base.Contribute lessons learned during post-incident reviews and drive corrective and preventive actions through to completion.Documentation, Reporting & ComplianceProduce accurate incident investigation and forensic reports detailing timelines, root causes, supporting evidence, business impact, actions .