← Back to jobs

Remote job

Senior Windows IR Practitioner | Cyber Security Training

Other Work from anywhere (UK timezone overlap required)

Job details

Not specified Salary
Work from anywhere (UK timezone overlap required) Eligibility
Senior Experience
Not specified Employment

About this role

Role overview

A leading online cyber security training platform is hiring senior incident response practitioners to join its Content Engineering team. The core mission is converting real-world blue team and IR experience into scenario-driven, hands-on training labs and exercises. The position can be filled on a permanent basis or via short- or long-term contracts, and is fully remote.

Responsibilities

- Research, design, and build defensive cyber security training material, including supporting hands-on labs such as virtual machines and forensic datasets. - Create realistic, scenario-driven exercises that mirror how attacks unfold inside enterprise Windows environments. - Configure virtual machines and sample datasets that simulate genuine incident response conditions. - Collaborate with peers through knowledge sharing, peer review, and joint quality improvements. - Plan and design portions of the content development roadmap, and work with content leadership to refine the production process. - Track emerging tools, techniques, and attacker trends, and translate them into teachable learning content.

Requirements

- Significant hands-on industry experience in roles such as Incident Responder, Threat Hunter, Digital Forensics Investigator, or L3 SOC Analyst. - Proven experience responding to real incidents in Windows environments, including triage, artefact analysis, and timeline reconstruction. - Strong grounding in Windows forensics, including event logs, registry hives, NTFS artefacts, and memory or disk forensics. - Demonstrated ability to communicate complex technical concepts clearly to varied audiences through writing, presenting, teaching, or mentoring. - Relevant certifications such as GCIH, GCED, GCFA, or SAL2 are welcomed.

Nice to have

- Background in producing technical training content or learning material for cyber security audiences. - Familiarity with current attacker methodologies mapped to frameworks such as MITRE ATT&CK.

Benefits and work setup

- Fully remote with flexible hours, requiring at least 4 hours of overlap with the UK daytime window. - Dedicated work laptop and required accessories. - Annual personal development budget for certifications and training. - Annual fully paid company retreat, recurring virtual team lunches, and an onboarding swag pack. - Enhanced parental leave beyond statutory minimums, retirement or pension contributions, and health insurance support in countries without public healthcare.

Skills detected in the listing

Information Security
Detected Sep 26, 2026
Last verified Sep 26, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Instant job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight