Incident Response Analyst | £45,000 – £55,000 | Fully Remote
This is a client-facing Incident Response position within a specialist cyber security consultancy, focused on leading and supporting the full lifecycle of cyber incident investigations across enterprise environments. You will work on high-impact, real-world breaches across host, network, and cloud environments, taking ownership from initial triage through to containment, eradication, and recovery while advising stakeholders throughout.
Why this role stands out:
- Exposure to complex, real-world incidents rather than repetitive alert handling
- The opportunity to directly influence client security posture and response maturity
- A clear path to senior incident responder through hands‑on experience, tooling exposure, and continuous improvement initiatives
- Own and lead the end-to-end lifecycle of cyber incidents, including triage, containment, eradication, recovery, and root cause analysis
- Conduct forensic investigations across endpoints, networks, and cloud platforms
- Perform live compromise assessments for organisations with suspected breaches
- Act as a key point of contact during incidents, managing communication and escalation with client stakeholders
- Develop, maintain, and improve incident response playbooks and standard operating procedures
- Support and guide junior analysts on complex investigations
- Deliver post-incident reviews, including lessons learned and remediation strategies
- Support incident readiness through tabletop exercises and simulation activities
- Recommend improvements to detection and response capabilities across SIEM, EDR, and SOAR platforms
- Produce clear, detailed incident and forensic reports for both technical and non-technical audiences
- 4+ years' experience in incident response, SOC, or security consulting with a strong focus on investigations and containment
- Proven experience handling complex, high-severity security incidents in client‑facing or consultancy environments
- Strong technical knowledge across networking, endpoint security, and digital forensics
- Hands‑on experience with EDR and SIEM platforms (e.g., Microsoft Defender, Sentinel, CrowdStrike, SentinelOne or similar)
- Solid understanding of attacker tactics, techniques, and procedures (TTPs) and incident response methodologies
- Ability to remain composed and methodical in high‑pressure situations
- Strong communication skills with the ability to translate technical findings into business impact
- Relevant certifications such as GCIH, ECIH, or equivalent are advantageous
- Fully remote working with occasional in-person collaboration
- Exposure to high‑impact, real‑world cyber incidents across multiple industries
- Ongoing training and professional development support
- Opportunity to work with modern detection and response tooling
- Structured career progression within incident response
#IncidentResponse #DFIR #DigitalForensics #CyberSecurity #ThreatHunting #SIEM #EDR #RemoteJobs #InfoSecJobs #UKJobs