Microsoft‑Focused Incident Response Consultant

Quorum Cyber

City of Edinburgh

On-site

GBP 70,000 - 110,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Excellent salary
World-class benefits
Access to latest technology
Development opportunities

Job summary

Quorum Cyber, founded in Edinburgh, seeks an Incident Response Consultant to investigate and respond to cyber security incidents across diverse environments. You will own investigative workstreams, perform forensics, and identify TTPs, contributing to customer guidance and remediation for MDR and SOC engagements.

You will work with Microsoft security telemetry, Defender, Sentinel, Entra, and Azure environments, while advancing AI-enabled IR workflows and ensuring evidence integrity throughout

Qualifications

  • Experience conducting cyber security investigations across Windows, Linux, macOS, and cloud platforms.
  • Proficient in memory and host forensics with evidence-handling best practices.
  • Ability to translate technical findings into clear customer guidance.
  • Knowledge of MDR/SOC operations and incident lifecycle.
  • A mindset for AI-enabled incident response and automation.

Responsibilities

  • Support investigations into cyber security incidents and own defined workstreams.
  • Perform host, network, and memory forensics and artefact analysis.
  • Identify attacker TTPs and map to IOCs.
  • Analyse logs, traffic, and artifacts to establish timelines and impact.
  • Maintain chain-of-custody and evidence handling.
  • Collaborate with SOC, MDR, Threat Intelligence and other teams.
  • Advise customers on Microsoft security telemetry and Defender usage.
  • Contribute to testing and deployment of AI-enabled IR workflows.
  • Review AI-generated findings and escalate where needed.

Skills

Forensic analysis
Memory forensics
Network/log analysis
EDR/SIEM proficiency
Microsoft security stacks
Incident response
AI/automation in IR
Evidence handling
Customer advisory
Threat hunting

Tools

EDR
SIEM
Microsoft Defender
Sentinel
Entra
Azure
Microsoft 365
Playbooks/Scripts

Job description

Quorum Cyber, founded in Edinburgh, seeks an Incident Response Consultant to investigate and respond to cyber security incidents across diverse environments. You will own investigative workstreams, perform forensics, and identify TTPs, contributing to customer guidance and remediation for MDR and SOC engagements.

You will work with Microsoft security telemetry, Defender, Sentinel, Entra, and Azure environments, while advancing AI-enabled IR workflows and ensuring evidence integrity throughout

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Incident Response Specialist (Microsoft Security)
Remote Incident Response Specialist (Microsoft Security)

Hollybank Trustees Ltd • United Kingdom

Remote
GBP 70,000 - 100,000
World class benefits
Incident Response Consultant (UK)
Incident Response Consultant (UK)

Forensic Focus • City of Edinburgh

Hybrid
GBP 58,000 - 90,000
Incident Response Consultant (UK)
Incident Response Consultant (UK)

Hollybank Trustees Ltd • United Kingdom

On-site
GBP 70,000 - 100,000
World class benefits
Incident Response Consultant (UK)
Incident Response Consultant (UK)

Quorum Cyber • City of Edinburgh

On-site
GBP 70,000 - 110,000
Excellent salary
World-class benefits
Access to latest technology
+1
Senior Offensive Security Consultant
Senior Offensive Security Consultant

Cyber UK • City of Edinburgh

On-site
GBP 90,000 - 130,000
World class benefits
Incident Response Investigator (DFIR) - UK
Incident Response Investigator (DFIR) - UK

Forensic Focus • City of Edinburgh

Hybrid
GBP 58,000 - 90,000
Senior Incident Response Investigator - Remote UK
Senior Incident Response Investigator - Remote UK

GOOGLE • United Kingdom

On-site
GBP 90,000 - 130,000
Remote Incident Responder II — MDR & Forensics Expert
Remote Incident Responder II — MDR & Forensics Expert

Lever, Inc. • Oxford

Hybrid
GBP 60,000 - 90,000
Remote-first working model
Cyber Defence & Incident Response Lead
Cyber Defence & Incident Response Lead

Quadient • Greater London

Hybrid
GBP 140,000 - 180,000
Hybrid work model
Flexible work options
Global learning platform
Lead Incident Response & Forensics Consultant (Remote UK)
Lead Incident Response & Forensics Consultant (Remote UK)

Google • United Kingdom

Remote
GBP 120,000 - 180,000