Senior Incident Response Analyst (VP)

Bonhill Partners Ltd

Greater London

On-site

GBP 120,000 - 180,000

Full time

29 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Bonhill Partners Ltd in London is seeking a Senior Incident Response Analyst (VP) to lead investigations across global banking operations. You will own incidents from triage to containment, eradication, recovery and post-incident review, coordinating with SOC, Threat Intelligence, and Infrastructure teams.

This hands-on role requires 8+ years in security operations, expert knowledge of MITRE ATT&CK, NIST/SANS methods, and experience with Splunk, Microsoft Sentinel and QRadar.

Qualifications

  • 8+ years in Security Operations with at least 3 years in Incident Response.
  • Hands-on experience with security investigations and triage.
  • Familiarity with SIEM platforms and threat analysis methodologies.
  • Experience with MITRE ATT&CK and regulatory considerations.

Responsibilities

  • Lead and support the investigation of cybersecurity incidents of varying severity.
  • Conduct incident triage, containment, eradication and recovery.
  • Investigate alerts to determine scope, impact and remediation needs.
  • Perform threat and forensic analysis using SIEM and telemetry.
  • Develop incident timelines and maintain investigation documentation.
  • Apply MITRE ATT&CK to identify malicious activity and escalate when needed.
  • Collaborate with SOC, Threat Intelligence and Infra teams on investigations.
  • Participate in post-incident reviews and lessons-learned sessions.
  • Contribute to playbooks, workflows, and escalation procedures.

Skills

Incident response
Threat analysis
Security investigations
Communication skills
NIST/SANS

Tools

Splunk
Microsoft Sentinel
QRadar
EDR
CrowdStrike Query Language

Job description

Location: London (4 days per week in office)

We are supporting a global investment bank in the search for a Senior Incident Response Analyst (VP) to join their Global Incident Response function.

The role sits within a highly experienced cyber security team and will be responsible for investigating and responding to security incidents across both the banking and securities businesses. You will take ownership of incidents ranging from initial triage through to containment, eradication, recovery and post-incident review.

This is a hands-on role suited to an experienced Incident Response professional who enjoys technical investigations, threat analysis and working across complex enterprise environments.

Key Responsibilities
  • Lead and support the investigation of low to high-severity cybersecurity incidents
  • Conduct incident triage, investigation, containment, eradication and recovery
  • Investigate security alerts and suspicious activity to determine scope, impact, root cause and remediation requirements
  • Perform detailed threat and forensic analysis using SIEM, EDR, network telemetry and threat intelligence
  • Analyse endpoint and network activity, including packet captures and endpoint telemetry
  • Develop detailed incident timelines, collect and preserve evidence, and maintain investigation documentation
  • Apply knowledge of attacker TTPs and MITRE ATT&CK to identify and investigate malicious activity
  • Escalate significant or business-impacting incidents and support major incident and crisis response activities
  • Provide technical guidance and support to SOC analysts and other Incident Response team members
  • Develop and continuously improve Incident Response playbooks, workflows and escalation procedures
  • Participate in post-incident reviews and lessons-learned sessions
  • Work closely with SOC, Threat Intelligence, Threat Hunting, Cyber Security and Infrastructure teams
  • Collaborate with global Incident Response teams on cross-regional investigations and response activities
  • Ensure incident response activities align with relevant regulatory and security standards
  • Participate in an on-call and out-of-hours incident response rotation
Skills & Experience
  • 8+ years' experience in Security Operations, with at least 3 years specialising in Incident Response
  • Strong experience across threat analysis, incident triage and security investigations
  • Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel or QRadar
  • Strong understanding of attacker Tactics, Techniques and Procedures (TTPs) and MITRE ATT&CK
  • Practical understanding of established Incident Response methodologies, including NIST and SANS
  • Experience with both host-based and network-based threat analysis
  • Hands-on experience analysing endpoint telemetry, network traffic and packet captures
  • Strong understanding of security technologies including EDR, firewalls and IDS/IPS
  • Experience with threat hunting and forensic investigation using query languages such as Splunk SPL and CrowdStrike Query Language
  • Strong analytical and problem-solving skills with the ability to work effectively during high-severity incidents
  • Excellent communication skills, with the ability to translate complex technical findings into clear, actionable information for non-technical stakeholders
  • Awareness of relevant regulatory and security frameworks, including GDPR, DORA, ISO 27001, NIST CSF and CIS Controls
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Incident Response Analyst
Incident Response Analyst

Harvey Nash Group • Greater London

Hybrid
GBP 83,000 - 120,000
Incident Response Analyst - Technology Vendor
Incident Response Analyst - Technology Vendor

Hamilton Barnes • United Kingdom

Remote
GBP 45,000 - 55,000
Fully remote work
Ongoing training
Career progression
+1
Incident Response Analyst Specialist
Incident Response Analyst Specialist

Vanguard • City Of London

On-site
GBP 70,000 - 110,000
Incident Response Analyst
Incident Response Analyst

Hamilton Barnes ? • United Kingdom

Remote
GBP 45,000 - 55,000
SOC Analyst
SOC Analyst

Tank Recruitment • Greater London

On-site
GBP 60,000 - 90,000
Senior Incident Response Lead - Threat Hunting & Forensics
Senior Incident Response Lead - Threat Hunting & Forensics

Bonhill Partners Ltd • Greater London

On-site
GBP 120,000 - 180,000
Snr Mgr, CyberSec Incident Response
Snr Mgr, CyberSec Incident Response

McGregor Boyall • Cambridgeshire and Peterborough

Hybrid
GBP 110,000 - 130,000
Benefits
Bonus
Senior Cyber Incident Response Specialist
Senior Cyber Incident Response Specialist

Royal London • Alderley Edge

Hybrid
GBP 65,000 - 90,000
28 days annual leave
Pension matching (up to 14%)
Private medical insurance
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Context Recruitment Limited • Greater London

On-site
GBP 72,000 - 88,000
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response

Cyber UK • Greater London, Manchester

On-site
GBP 60,000 - 80,000