Contract Incident Response Analyst
Location: Hybrid / London 2 days Per Week
Contract Type: Contract
Day Rate: Competitive
We are seeking an experienced Incident Response Analyst to support a specialist Cyber Security function responsible for identifying, investigating and responding to cyber threats across a complex enterprise environment.
This role is ideal for a hands-on cyber security professional with strong experience in incident response, threat hunting, security operations and digital forensics. You will play a key role in protecting critical systems and data by managing security incidents through their full lifecycle while collaborating with technical and business stakeholders.
Key Responsibilities
- Monitor and investigate security alerts generated by SIEM, EDR/XDR, identity, email, cloud and network security tools.
- Lead and support cyber security incident investigations, including phishing, malware, account compromise, unauthorised access and data loss events.
- Perform incident triage, determine business impact and coordinate containment, eradication and recovery activities.
- Collect, preserve and analyse forensic artefacts from endpoints, servers, cloud platforms, networks and email systems.
- Identify indicators of compromise (IOCs), attacker tactics and techniques, and document findings.
- Conduct proactive threat hunting activities using threat intelligence and security telemetry.
- Develop and improve detection content, monitoring rules and incident response playbooks.
- Produce clear technical and management-level incident reports and post-incident reviews.
- Support cyber exercises, simulations and continuous improvement initiatives.
- Contribute to incident metrics, trend analysis and security governance reporting.
Essential Experience
- Experience working within Incident Response, Cyber Security Operations or SOC environments.
- Strong hands-on experience with SIEM and EDR/XDR technologies.
- Proven ability to investigate and respond to cyber security incidents.
- Knowledge of Windows and Linux security investigations, authentication events, security logs and network traffic analysis.
- Understanding of the incident response lifecycle, including detection, analysis, containment, eradication and recovery.
- Knowledge of frameworks such as MITRE ATT&CK, Cyber Kill Chain and NIST.
- Understanding of enterprise networking, identity and access management, cloud security and email security technologies.
- Excellent communication and stakeholder management skills.
- Ability to work effectively in high-pressure environments and manage multiple priorities.
Desirable Experience
- Experience within financial services or other regulated environments.
- Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.
- Threat intelligence, malware analysis, detection engineering or security automation.
- PowerShell, Python, KQL or similar scripting languages.
- Exposure to tools such as Wireshark, Velociraptor, EnCase, FTK or Volatility.
- Experience investigating incidents across Microsoft 365 and Azure environments.
Qualifications
- Degree in Cyber Security, Computer Science or a related discipline, or equivalent practical experience.
- Relevant certifications such as GCIH, GCFA, GCIA, GNFA, SC-200, CySA+ or CISSP are highly desirable.
If you are a proactive cyber security professional with a passion for incident response and threat investigation, we would like to hear from you.