Contract Incident Response Analyst

Location: Hybrid / London 2 days Per Week

Contract Type: Contract

Day Rate: Competitive

We are seeking an experienced Incident Response Analyst to support a specialist Cyber Security function responsible for identifying, investigating and responding to cyber threats across a complex enterprise environment.

This role is ideal for a hands-on cyber security professional with strong experience in incident response, threat hunting, security operations and digital forensics. You will play a key role in protecting critical systems and data by managing security incidents through their full lifecycle while collaborating with technical and business stakeholders.

Key Responsibilities

  • Monitor and investigate security alerts generated by SIEM, EDR/XDR, identity, email, cloud and network security tools.
  • Lead and support cyber security incident investigations, including phishing, malware, account compromise, unauthorised access and data loss events.
  • Perform incident triage, determine business impact and coordinate containment, eradication and recovery activities.
  • Collect, preserve and analyse forensic artefacts from endpoints, servers, cloud platforms, networks and email systems.
  • Identify indicators of compromise (IOCs), attacker tactics and techniques, and document findings.
  • Conduct proactive threat hunting activities using threat intelligence and security telemetry.
  • Develop and improve detection content, monitoring rules and incident response playbooks.
  • Produce clear technical and management-level incident reports and post-incident reviews.
  • Support cyber exercises, simulations and continuous improvement initiatives.
  • Contribute to incident metrics, trend analysis and security governance reporting.

Essential Experience

  • Experience working within Incident Response, Cyber Security Operations or SOC environments.
  • Strong hands-on experience with SIEM and EDR/XDR technologies.
  • Proven ability to investigate and respond to cyber security incidents.
  • Knowledge of Windows and Linux security investigations, authentication events, security logs and network traffic analysis.
  • Understanding of the incident response lifecycle, including detection, analysis, containment, eradication and recovery.
  • Knowledge of frameworks such as MITRE ATT&CK, Cyber Kill Chain and NIST.
  • Understanding of enterprise networking, identity and access management, cloud security and email security technologies.
  • Excellent communication and stakeholder management skills.
  • Ability to work effectively in high-pressure environments and manage multiple priorities.

Desirable Experience

  • Experience within financial services or other regulated environments.
  • Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.
  • Threat intelligence, malware analysis, detection engineering or security automation.
  • PowerShell, Python, KQL or similar scripting languages.
  • Exposure to tools such as Wireshark, Velociraptor, EnCase, FTK or Volatility.
  • Experience investigating incidents across Microsoft 365 and Azure environments.

Qualifications

  • Degree in Cyber Security, Computer Science or a related discipline, or equivalent practical experience.
  • Relevant certifications such as GCIH, GCFA, GCIA, GNFA, SC-200, CySA+ or CISSP are highly desirable.

If you are a proactive cyber security professional with a passion for incident response and threat investigation, we would like to hear from you.

Apply