Incident Response Analyst

Harvey Nash Group

Greater London

Hybrid

GBP 83,000 - 120,000

Part time

37 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Harvey Nash Group is seeking an experienced Incident Response Analyst to support a specialist cyber security function across a complex enterprise. You will manage security incidents through their lifecycle and collaborate with technical and business stakeholders.

The role requires strong experience in incident response, threat hunting, security operations and digital forensics, with a focus on protecting critical systems and data.

Qualifications

  • Experience in incident response lifecycle across detection, containment, eradication and recovery.
  • Strong hands-on with SIEM and EDR/XDR technologies.
  • Proven ability to investigate and respond to cyber security incidents.
  • Good working knowledge of Windows and Linux security investigations and logs.
  • Familiarity with MITRE ATT&CK, NIST frameworks and threat intel concepts.

Responsibilities

  • Monitor and investigate security alerts from SIEM/EDR/XDR, identity, email and cloud tools.
  • Lead and support cyber security incident investigations and containment activities.
  • Coordinate eradication and recovery across endpoints, servers and networks.
  • Collect, preserve and analyse forensic artefacts from various platforms.
  • Identify IOCs and attacker techniques; document findings and learnings.
  • Conduct proactive threat hunting using intelligence and telemetry.
  • Develop and improve detection content, playbooks and rules.
  • Produce incident reports and post-incident reviews for technical and management audiences.
  • Support cyber exercises and continuous improvement initiatives.
  • Contribute to incident metrics and security governance reporting.

Skills

Incident response
Cyber security operations
SOC
SIEM
EDR/XDR
Forensics
Threat hunting
MITRE ATT&CK
NIST
Windows security
Linux security
Communication
Stakeholder mgmt

Education

Degree in Cyber Security or CS
Certifications such as GCIH/GCFA/GCIA/SC-200/CySA+/CISSP

Tools

Microsoft Sentinel
Defender XDR
EnCase
FTK
Wireshark
Velociraptor
PowerShell
Python
KQL

Job description

Contract Incident Response Analyst

Location: Hybrid / London 2 days Per Week

Contract Type: Contract

Day Rate: Competitive

We are seeking an experienced Incident Response Analyst to support a specialist Cyber Security function responsible for identifying, investigating and responding to cyber threats across a complex enterprise environment.

This role is ideal for a hands-on cyber security professional with strong experience in incident response, threat hunting, security operations and digital forensics. You will play a key role in protecting critical systems and data by managing security incidents through their full lifecycle while collaborating with technical and business stakeholders.

Key Responsibilities
  • Monitor and investigate security alerts generated by SIEM, EDR/XDR, identity, email, cloud and network security tools.
  • Lead and support cyber security incident investigations, including phishing, malware, account compromise, unauthorised access and data loss events.
  • Perform incident triage, determine business impact and coordinate containment, eradication and recovery activities.
  • Collect, preserve and analyse forensic artefacts from endpoints, servers, cloud platforms, networks and email systems.
  • Identify indicators of compromise (IOCs), attacker tactics and techniques, and document findings.
  • Conduct proactive threat hunting activities using threat intelligence and security telemetry.
  • Develop and improve detection content, monitoring rules and incident response playbooks.
  • Produce clear technical and management-level incident reports and post-incident reviews.
  • Support cyber exercises, simulations and continuous improvement initiatives.
  • Contribute to incident metrics, trend analysis and security governance reporting.
Essential Experience
  • Experience working within Incident Response, Cyber Security Operations or SOC environments.
  • Strong hands-on experience with SIEM and EDR/XDR technologies.
  • Proven ability to investigate and respond to cyber security incidents.
  • Knowledge of Windows and Linux security investigations, authentication events, security logs and network traffic analysis.
  • Understanding of the incident response lifecycle, including detection, analysis, containment, eradication and recovery.
  • Knowledge of frameworks such as MITRE ATT&CK, Cyber Kill Chain and NIST.
  • Understanding of enterprise networking, identity and access management, cloud security and email security technologies.
  • Excellent communication and stakeholder management skills.
  • Ability to work effectively in high-pressure environments and manage multiple priorities.
Desirable Experience
  • Experience within financial services or other regulated environments.
  • Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.
  • Threat intelligence, malware analysis, detection engineering or security automation.
  • PowerShell, Python, KQL or similar scripting languages.
  • Exposure to tools such as Wireshark, Velociraptor, EnCase, FTK or Volatility.
  • Experience investigating incidents across Microsoft 365 and Azure environments.
Qualifications
  • Degree in Cyber Security, Computer Science or a related discipline, or equivalent practical experience.
  • Relevant certifications such as GCIH, GCFA, GCIA, GNFA, SC-200, CySA+ or CISSP are highly desirable.

If you are a proactive cyber security professional with a passion for incident response and threat investigation, we would like to hear from you.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Analyst
SOC Analyst

Tank Recruitment • Greater London

On-site
GBP 60,000 - 90,000
Incident Response Analyst - Technology Vendor
Incident Response Analyst - Technology Vendor

Hamilton Barnes • United Kingdom

Remote
GBP 45,000 - 55,000
Fully remote work
Ongoing training
Career progression
+1
Incident Response Analyst
Incident Response Analyst

Hamilton Barnes ? • United Kingdom

Remote
GBP 45,000 - 55,000
Senior Incident Response Analyst (VP)
Senior Incident Response Analyst (VP)

Bonhill Partners Ltd • Greater London

On-site
GBP 120,000 - 180,000
Cyber Security Analyst
Cyber Security Analyst

Synapri • Greater London

On-site
GBP 50,000 - 70,000
Incident Response Analyst
Incident Response Analyst

CyberOne • City Of London

Hybrid
GBP 65,000 - 90,000
Career growth opportunities
Continuous learning & certifications
Access to MXDR platform & SecOps tools
Lead Incident Response Analyst
Lead Incident Response Analyst

IntaPeople: STEM Recruitment • Cardiff

On-site
GBP 55,000
Bespoke learning plans
Bonus plan
Incident Response Analyst Specialist
Incident Response Analyst Specialist

Vanguard • City Of London

On-site
GBP 70,000 - 110,000
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response

Cyber UK • Greater London, Manchester

On-site
GBP 60,000 - 80,000
Incident Response Specialist
Incident Response Specialist

Pontoon Solutions • Warwick

Hybrid
GBP 55,000 - 75,000