Senior Incident Response Analyst

Bonhill Partners

Greater London

Hybrid

GBP 72,000 - 120,000

Full time

2 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Bonhill Partners seeks an experienced security professional to lead L2/L3 SOC incident response. You will own investigations end-to-end, coordinating across SOC, infra and engineering teams to drive timely containment and recovery.

The role requires strong SIEM expertise (Splunk, Microsoft Sentinel, QRadar) and knowledge of MITRE ATT&CK, NIST/SANS guidelines. Hybrid London office presence is expected as part of a global security function.

Qualifications

  • Significant experience within L2/L3 SOC and Incident Response environments.
  • Proven track record of leading cyber investigations end-to-end.
  • Strong expertise across SIEM platforms and security telemetry.
  • Experience with MITRE ATT&CK framework and NIST/SANS practices.
  • Ability to guide analysts and coordinate cross-team investigations.

Responsibilities

  • Lead investigations from initial detection through containment and recovery.
  • Coordinate SOC, infrastructure and engineering teams during incidents.
  • Mentor junior analysts and establish incident handling processes.
  • Develop detection queries and support threat hunting efforts.
  • Communicate risk and remediation requirements to senior stakeholders.

Skills

L2/L3 SOC
Incident response
SIEM platforms
Splunk
MITRE ATT&CK
NIST & SANS
Threat hunting

Tools

Splunk
Microsoft Sentinel
QRadar
CrowdStrike Query Language

Job description

Location: London, City - 3-4 days in office.

Details: Initial 6 month contract, with guaranteed conversion to perm within that period.

Perm salary: up to 120k

Initial contract rate: TBC

Requirements:

  • Significant experience within L2/L3 SOC and Incident Response environments, ideally operating as part of a global security function across complex enterprise environments.
  • Proven track record of leading cyber investigations from initial detection through containment, eradication and recovery, taking ownership of incident prioritisation, escalation, coordination and resolution.
  • Strong expertise across SIEM and security monitoring platforms, including Splunk, Microsoft Sentinel and QRadar, with the ability to oversee complex investigations and guide analysts through effective use of security telemetry.
  • Extensive understanding of modern attack techniques, adversary behaviour and intrusion methodologies, with the ability to assess activity against frameworks such as MITRE ATT&CK and translate findings into actionable response strategies.
  • Strong knowledge of established incident response methodologies and industry best practice, including NIST and SANS, with experience developing, improving and embedding effective incident handling processes.
  • Demonstrable ability to lead investigations across multiple sources of evidence, including endpoint telemetry, network traffic, system and authentication logs, packet captures and other forensic data.
  • Broad technical understanding of enterprise security controls, including EDR, firewalls, IDS/IPS and network security technologies, with the ability to assess their effectiveness and direct their use during active incidents.
  • Advanced experience developing and leveraging investigative queries for incident response and threat hunting, including Splunk SPL and CrowdStrike Query Language, while supporting the development of detection and hunting capabilities across the wider SOC.
  • Experience providing technical leadership during high-severity incidents, coordinating activity across SOC, infrastructure, engineering, threat intelligence and other relevant teams to drive timely and effective resolution.
  • Ability to communicate complex security incidents, business impact, technical risk and remediation requirements clearly to senior leadership, risk functions and non-technical stakeholders.
  • Demonstrated ability to mentor and support junior analysts, provide investigative guidance and contribute to the development of SOC and Incident Response capability, processes and standards.
  • Strong analytical and investigative approach, with the judgement to make informed decisions under pressure and maintain clear direction throughout complex or high-impact security incidents.
  • Good understanding of the regulatory and control environment surrounding enterprise cybersecurity, including GDPR, DORA, ISO 27001, NIST Cybersecurity Framework and CIS Controls.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Franklin Fitch • Greater London

Hybrid
GBP 72,000 - 88,000
Senior SOC Analyst
Senior SOC Analyst

Franklin Fitch • City Of London

Hybrid
GBP 65,000 - 85,000
Incident Response Consultant - Systems Integrator
Incident Response Consultant - Systems Integrator

Hamilton Barnes Associates Limited • England

Hybrid
GBP 40,000 - 50,000
Mentorship
Exposure to advanced tools
Flexible working arrangement
Cyber Security Analyst
Cyber Security Analyst

Synapri • Greater London

Hybrid
GBP 50,000 - 70,000
Senior SOC Specialist
Senior SOC Specialist

Morson Talent • Crawley

Hybrid
GBP 65,000 - 80,000
3rd Line Security Analyst
3rd Line Security Analyst

Xact Placements Limited • Reading

On-site
GBP 51,000 - 69,000
2nd/3rd Line Security Analyst
2nd/3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary
Incident Response Lead (DFIR)
Incident Response Lead (DFIR)

LT Harper Recruitment Group • United Kingdom

Hybrid
GBP 99,000 - 121,000
Pension contribution
Private healthcare
Structured training programme
Senior SOC Analyst
Senior SOC Analyst

GCS Recruitment • England

On-site
GBP 90,000 - 120,000
Lead Incident Response Analyst
Lead Incident Response Analyst

IntaPeople: STEM Recruitment • Cardiff

Hybrid
GBP 55,000
Bespoke learning plans
Bonus plan