Security Incident Response Analyst

KPMG International Cooperative

Birmingham

Hybrid

GBP 90,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

KPMG in the UK is seeking a Senior Incident Response professional to join the Tier 2 team within Security Operations. The role sits in Group Corporate Services on a hybrid basis from the UK, with responsibility for high-priority investigations across a diverse tech stack for UK and Switzerland.

You will be a senior escalation point, coordinating containment, eradication and recovery with calm leadership. Eligible for Security Check clearance or able to obtain it, you will provide technical

Qualifications

  • Experience leading high-severity cyber security incidents and investigations.
  • Ability to produce timelines, RCAs and post-incident reports for stakeholders.
  • Clear written and verbal communication to technical and non-technical audiences.

Responsibilities

  • Lead investigations into complex and high-severity cyber security incidents.
  • Coordinate containment, eradication and recovery activities for timely resolutions.
  • Provide senior technical guidance to analysts and act as escalation point during major incidents.
  • Conduct forensic investigations across endpoints, identities, cloud, email and networks.
  • Develop incident timelines, root cause analyses and post-incident reports.

Skills

Incident response leadership
Senior escalation point
Analytical thinking
Communication with stakeholders
Cross-functional collaboration

Education

Security certifications

Tools

Microsoft Sentinel
Defender XDR
Defender for Endpoint
Defender for Identity
Defender for Cloud
Microsoft Purview
Digital forensics tools
SOAR / automation platforms

Job description

This role sits within Group Corporate Services, which supports KPMG's people and business through firmwide specialist services and operational capabilities. Within Security Operations, you will join the Tier 2 Incident Response team and take ownership of complex investigations across a diverse technology environment serving KPMG in the UK and Switzerland. You will act as a senior escalation point for high-priority and major cyber security incidents, combining hands-on technical investigation with calm coordination and clear communication. The role is based in the UK on a hybrid basis and is at Grade D. Participation in the Security Operations on-call rota is required, including providing technical and operational leadership outside standard business hours. You must be eligible for Security Check clearance or able to obtain it.

Roles and responsibilities
  • Lead investigations into complex and high-severity cyber security incidents, establishing the scope, business impact and risk.
  • Coordinate containment, eradication and recovery activities so incidents progress efficiently to a controlled resolution.
  • Provide senior technical guidance to analysts and act as an escalation point during high-priority and major incidents, including through the on-call rota.
  • Conduct forensic investigation and evidence collection across endpoint, identity, cloud, email and network technologies.
  • Produce clear investigation timelines, root cause analysis and post-incident reports for technical and business stakeholders.
  • Work with Threat Intelligence and Detection Engineering teams to apply knowledge of emerging threats, improve detection coverage and strengthen investigations.
  • Lead proactive threat hunting to identify previously undetected activity, security weaknesses and opportunities to improve controls.
  • Improve incident response playbooks, processes, automation and operational standards, sharing knowledge across the wider cyber security function. Demonstrable experience in security operations, incident response, cyber defence or digital forensics, including ownership of escalated security incidents.
  • Evidence of investigating threats across endpoint, identity, cloud, email and network environments and translating findings into appropriate response actions.
  • Practical knowledge of attacker tactics, techniques and procedures, with experience applying this knowledge to investigations or threat hunting.
  • Experience leading technical investigations, building incident timelines and completing root cause analysis and post-incident reporting.
  • Strong analytical and problem-solving skills, with evidence of making sound decisions and coordinating activity during high-pressure incidents.
  • Clear written and verbal communication skills, with experience explaining technical findings to technical and non-technical stakeholders and collaborating across security teams.
  • Experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, Microsoft Purview, digital forensics and incident response tools, security orchestration and automation platforms, threat hunting methods, or cloud security technologies across Microsoft Azure, Amazon Web Services or Google Cloud Platform would be beneficial.
  • Relevant certifications, such as Microsoft Certified: Security Operations Analyst Associate (SC-200), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), Microsoft Certified: Azure Security Engineer Associate (AZ-500), or an equivalent qualification, would also be advantageous.

Digital is the firm's primary provider of internal business and technology services, data, and innovation. We deliver secure, resilient, and standardised technology solutions that ensure our operations run seamlessly and empower colleagues to provide exceptional client service. Our mission is to propel KPMG into the future. We drive our digital strategy, safeguard against cyber threats, manage data responsibly, and provide cutting-edge tools for seamless collaboration. Through innovation and accelerated adoption of digital and AI capabilities, we support growth and transformation, unlocking significant value for both our colleagues and clients.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Incident Response Manager
Security Incident Response Manager

KPMG International Cooperative • Birmingham

Hybrid
GBP 75,000 - 110,000
Security Incident Response Manager
Security Incident Response Manager

KPMG LLP • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG LLP • Greater London

On-site
GBP 90,000 - 130,000
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG Careers • Greater London

On-site
GBP 90,000 - 130,000
Cyber Response & Recovery Manager – German Speaker
Cyber Response & Recovery Manager – German Speaker

Cyber UK • Manchester

Hybrid
GBP 70,000 - 110,000
Senior Security Incident Response Lead - Hybrid UK
Senior Security Incident Response Lead - Hybrid UK

KPMG International Cooperative • Birmingham

Hybrid
GBP 90,000 - 130,000
Senior Incident Response Lead – Tier 2 & On-Call
Senior Incident Response Lead – Tier 2 & On-Call

KPMG LLP • Greater London

Hybrid
GBP 90,000 - 120,000
Cyber Response & Recovery – Manager (Remediation focus)
Cyber Response & Recovery – Manager (Remediation focus)

Cyber UK • United Kingdom

Hybrid
GBP 90,000 - 130,000
Senior Incident Response Lead - Cyber Resilience & Ops
Senior Incident Response Lead - Cyber Resilience & Ops

KPMG International Cooperative • Birmingham

Hybrid
GBP 75,000 - 110,000
Senior Global Cyber Security Incident Response Lead
Senior Global Cyber Security Incident Response Lead

KPMG Careers • Greater London

On-site
GBP 90,000 - 130,000