Quick Overview
Job Description
Incident Response Analyst
We are seeking an experienced Incident Response Analyst to support the detection, triage, investigation, containment and resolution of cyber security incidents across a complex enterprise environment.
Key Responsibilities
Monitor and investigate alerts from SIEM, EDR/XDR, identity, email, cloud and network security technologies.
Triage incidents, assess severity and business impact, and coordinate containment, eradication and recovery.
Investigate phishing, malware, account compromise, data loss, unauthorised access and suspicious network activity.
Collect, preserve and analyse endpoint, server, identity, network, email and cloud artefacts.
Analyse logs, packet captures, forensic images and security telemetry to establish scope, root cause and attacker activity.
Identify IOCs, attacker behaviours, TTPs and map findings to MITRE ATT&CK where appropriate.
Develop and execute threat hunts and contribute to detection rule, monitoring and logging improvements.
Maintain incident records, investigation timelines, evidence and post-incident reports.
Develop and maintain incident response playbooks, procedures and communication processes.
Conduct post-incident reviews, root-cause analysis and lessons-learned activities.
Provide clear technical and management updates to senior stakeholders.
Essential Skills & Experience
Practical experience in cyber security incident response, security monitoring or a SOC environment.
Hands-on experience with SIEM and EDR/XDR technologies.
Experience investigating Windows and Linux systems, authentication activity, security logs and network traffic.
Strong understanding of the incident response lifecycle.
Knowledge of MITRE ATT&CK, Cyber Kill Chain and NIST.
Good understanding of enterprise networking, IAM, cloud, email and endpoint security.
Experience with digital forensics and evidence handling.
Strong communication, investigation and analytical skills.
Desirable
Banking, financial services or other regulated-sector experience.
Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.
KQL, PowerShell, Python or similar scripting/automation.
Threat hunting, malware analysis and detection engineering.
Azure and Microsoft 365 investigation experience.
EnCase, FTK, Velociraptor, Volatility or Wireshark.
Certifications such as GCIH, GCIA, GCFA, GNFA, SC-200, CySA+ or CISSP.
Qualifications
Relevant cyber security experience, degree or equivalent practical experience. Knowledge of NIST, CIS Controls and recognised information security standards.
Similar jobs
- AP
Security Engineer
NewAE Partners
Wakefield, Yorkshire🇬🇧Hybrid1 hour agoTechnology - BT
Junior Cyber Security Specialist
NewBack TO Work
Newcastle Upon Tyne, Tyne And Wear🇬🇧Hybrid1 hour agoTechnology - BT
Junior Cyber Security Specialist
NewBack TO Work
Gateshead, Tyne And Wear🇬🇧Hybrid1 hour agoTechnology - HT
Principal Security Architect
NewHays Technology
City, London🇬🇧On-site1 hour agoStakeholder ManagementTechnology - SO
Security Architect
NewSoCode Limited
Cambridge, Cambridgeshire🇬🇧Hybrid1 hour agoIoTEmbedded SystemsTechnology - KN
Cybersecurity Threat Researcher (Position located in Cheltenham, United Kingdom)
NewAuto ApplyKnowBe4
Cheltenham🇬🇧Hybrid11 hours agoSQLPythonTriageTechnology - CM
IT Security Engineer
NewAuto ApplyCambridge Mobile Telematics
Cambridge🇬🇧Hybrid5 hours agoAWSTableauDatadog+1Technology - S-
Lead Technical Security Engineer - SC Cleared
NewSR2 - Socially Responsible Recruitment
London🇬🇧Hybrid3 hours agoMFAAzureZero TrustTechnology - EV
Security Engineer
NewAuto ApplyEvervault
London🇬🇧On-site6 hours agoNode.jsRustAWS+3Technology - CG
Group Head of Security
NewAuto ApplyCulina Group
Warrington🇬🇧On-site10 hours agoContinuous ImprovementProcurementRisk Assessment+2Logistics - EX
Junior Information Security Officer
NewAuto ApplyExperian
London🇬🇧Hybrid5 hours agoScrumAdministrative - SE
Mobile Patrol Officer
NewAuto ApplySecuritas
Birmingham🇬🇧£13/hrOn-siteYesterdayOperations & Project Management