Remote job
Senior Windows IR Practitioner | Cyber Security Training
Job details
About this role
Role overview
A leading online cyber security training platform is hiring senior incident response practitioners to join its Content Engineering team. The core mission is converting real-world blue team and IR experience into scenario-driven, hands-on training labs and exercises. The position can be filled on a permanent basis or via short- or long-term contracts, and is fully remote.
Responsibilities
- Research, design, and build defensive cyber security training material, including supporting hands-on labs such as virtual machines and forensic datasets. - Create realistic, scenario-driven exercises that mirror how attacks unfold inside enterprise Windows environments. - Configure virtual machines and sample datasets that simulate genuine incident response conditions. - Collaborate with peers through knowledge sharing, peer review, and joint quality improvements. - Plan and design portions of the content development roadmap, and work with content leadership to refine the production process. - Track emerging tools, techniques, and attacker trends, and translate them into teachable learning content.
Requirements
- Significant hands-on industry experience in roles such as Incident Responder, Threat Hunter, Digital Forensics Investigator, or L3 SOC Analyst. - Proven experience responding to real incidents in Windows environments, including triage, artefact analysis, and timeline reconstruction. - Strong grounding in Windows forensics, including event logs, registry hives, NTFS artefacts, and memory or disk forensics. - Demonstrated ability to communicate complex technical concepts clearly to varied audiences through writing, presenting, teaching, or mentoring. - Relevant certifications such as GCIH, GCED, GCFA, or SAL2 are welcomed.
Nice to have
- Background in producing technical training content or learning material for cyber security audiences. - Familiarity with current attacker methodologies mapped to frameworks such as MITRE ATT&CK.
Benefits and work setup
- Fully remote with flexible hours, requiring at least 4 hours of overlap with the UK daytime window. - Dedicated work laptop and required accessories. - Annual personal development budget for certifications and training. - Annual fully paid company retreat, recurring virtual team lunches, and an onboarding swag pack. - Enhanced parental leave beyond statutory minimums, retirement or pension contributions, and health insurance support in countries without public healthcare.