Location: London (4 days per week in office)
We are supporting a global investment bank in the search for a Senior Incident Response Analyst (VP) to join their Global Incident Response function.
The role sits within a highly experienced cyber security team and will be responsible for investigating and responding to security incidents across both the banking and securities businesses. You will take ownership of incidents ranging from initial triage through to containment, eradication, recovery and post-incident review.
This is a hands-on role suited to an experienced Incident Response professional who enjoys technical investigations, threat analysis and working across complex enterprise environments.
Key Responsibilities
- Lead and support the investigation of low to high-severity cybersecurity incidents
- Conduct incident triage, investigation, containment, eradication and recovery
- Investigate security alerts and suspicious activity to determine scope, impact, root cause and remediation requirements
- Perform detailed threat and forensic analysis using SIEM, EDR, network telemetry and threat intelligence
- Analyse endpoint and network activity, including packet captures and endpoint telemetry
- Develop detailed incident timelines, collect and preserve evidence, and maintain investigation documentation
- Apply knowledge of attacker TTPs and MITRE ATT&CK to identify and investigate malicious activity
- Escalate significant or business-impacting incidents and support major incident and crisis response activities
- Provide technical guidance and support to SOC analysts and other Incident Response team members
- Develop and continuously improve Incident Response playbooks, workflows and escalation procedures
- Participate in post-incident reviews and lessons-learned sessions
- Work closely with SOC, Threat Intelligence, Threat Hunting, Cyber Security and Infrastructure teams
- Collaborate with global Incident Response teams on cross-regional investigations and response activities
- Ensure incident response activities align with relevant regulatory and security standards
- Participate in an on-call and out-of-hours incident response rotation
Skills & Experience
- 8+ years' experience in Security Operations, with at least 3 years specialising in Incident Response
- Strong experience across threat analysis, incident triage and security investigations
- Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel or QRadar
- Strong understanding of attacker Tactics, Techniques and Procedures (TTPs) and MITRE ATT&CK
- Practical understanding of established Incident Response methodologies, including NIST and SANS
- Experience with both host-based and network-based threat analysis
- Hands-on experience analysing endpoint telemetry, network traffic and packet captures
- Strong understanding of security technologies including EDR, firewalls and IDS/IPS
- Experience with threat hunting and forensic investigation using query languages such as Splunk SPL and CrowdStrike Query Language
- Strong analytical and problem-solving skills with the ability to work effectively during high-severity incidents
- Excellent communication skills, with the ability to translate complex technical findings into clear, actionable information for non-technical stakeholders
- Awareness of relevant regulatory and security frameworks, including GDPR, DORA, ISO 27001, NIST CSF and CIS Controls