Senior Security Incident Response Analyst

KPMG LLP

Greater London

Hybrid

GBP 70,000 - 90,000

Full time

42 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

KPMG LLP in London is seeking a Senior Security Incident Response Analyst to own complex investigations across a diverse technology environment for the UK and Switzerland. You will act as a senior escalation point for high-priority incidents, combining hands-on investigation with calm coordination and clear communication.

The role is based in the UK on a hybrid basis and requires participation in the on-call rota, including outside standard hours. Security clearance eligibility is required.

Qualifications

  • Experience in security operations, incident response or forensics with ownership of escalated incidents.
  • Ability to investigate threats across endpoints, identity, cloud, email and network.
  • Knowledge of attacker tactics, techniques and procedures in investigations or threat hunting.
  • Experience leading technical investigations, creating incident timelines and post-incident reports.
  • Strong analytical and problem-solving skills with effective decision-making under pressure.
  • Clear written and verbal communication for technical and non-technical stakeholders.

Responsibilities

  • Lead investigations into complex and high-severity cyber security incidents, establishing scope, impact and risk.
  • Coordinate containment, eradication and recovery activities for incidents to reach controlled resolution.
  • Provide senior technical guidance to analysts and act as escalation point during major incidents, including on-call duty.
  • Conduct forensic investigation across endpoint, identity, cloud, email and network technologies.
  • Produce timelines, root cause analyses and post-incident reports for stakeholders.
  • Collaborate with Threat Intelligence and Detection Engineering to improve detection and investigations.
  • Lead proactive threat hunting to identify undetected activity and improve controls.
  • Improve incident response playbooks, processes and automation, sharing knowledge across the team.

Skills

Security operations
Incident response
Cyber defence
Digital forensics
Threat hunting
Cloud security
Communication

Tools

Microsoft Defender XDR
Microsoft Defender for Endpoint
Microsoft Sentinel
Microsoft Defender for Identity
Microsoft Defender for Cloud

Job description

Select how often (in days) to receive an alert:

Senior Security Incident Response Analyst
Location:

London

About the role

This role sits within Group Corporate Services, which supports KPMG's people and business through firmwide specialist services and operational capabilities. Within Security Operations, you will join the Tier 2 Incident Response team and take ownership of complex investigations across a diverse technology environment serving KPMG in the UK and Switzerland.

You will act as a senior escalation point for high-priority and major cyber security incidents, combining hands-on technical investigation with calm coordination and clear communication. The role is based in the UK on a hybrid basis and is at Grade D. Participation in the Security Operations on-call rota is required, including providing technical and operational leadership outside standard business hours. You must be eligible for Security Check clearance or able to obtain it.

Roles and responsibilities

Lead investigations into complex and high-severity cyber security incidents, establishing the scope, business impact and risk.

Coordinate containment, eradication and recovery activities so incidents progress efficiently to a controlled resolution.

Provide senior technical guidance to analysts and act as an escalation point during high-priority and major incidents, including through the on-call rota .

Conduct forensic investigation and evidence collection across endpoint, identity, cloud, email and network technologies.

Produce clear investigation timelines, root cause analysis and post-incident reports for technical and business stakeholders.

Work with Threat Intelligence and Detection Engineering teams to apply knowledge of emerging threats, improve detection coverage and strengthen investigations.

Lead proactive threat hunting to identify previously undetected activity, security weaknesses and opportunities to improve controls.

Improve incident response playbooks, processes, automation and operational standards, sharing knowledge across the wider cyber security function.

Experience and skills needed

Demonstrable experience in security operations, incident response, cyber defence or digital forensics, including ownership of escalated security incidents.

Evidence of investigating threats across endpoint, identity, cloud, email and network environments and translating findings into appropriate response actions.

Practical knowledge of attacker tactics, techniques and procedures, with experience applying this knowledge to investigations or threat hunting.

Experience leading technical investigations, building incident timelines and completing root cause analysis and post-incident reporting.

Strong analytical and problem-solving skills, with evidence of making sound decisions and coordinating activity during high-pressure incidents.

Clear written and verbal communication skills, with experience explaining technical findings to technical and non-technical stakeholders and collaborating across security teams.

Experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, Microsoft Purview, digital forensics and incident response tools, security orchestration and automation platforms, threat hunting methods, or cloud security technologies across Microsoft Azure, Amazon Web Services or Google Cloud Platform would be beneficial. Relevant certifications, such as Microsoft Certified: Security Operations Analyst Associate (SC-200), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), Microsoft Certified: Azure Security Engineer Associate (AZ-500), or an equivalent qualification, would also be advantageous.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Incident Response Manager
Security Incident Response Manager

KPMG LLP • Greater London

Hybrid
GBP 90,000 - 120,000
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG LLP • Greater London

On-site
GBP 90,000 - 130,000
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)
Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG Careers • Greater London

On-site
GBP 90,000 - 130,000
Senior Security Analyst
Senior Security Analyst

Spencer Rose • Greater London

Hybrid
GBP 70,000 - 90,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Bonhill Partners • Greater London

Hybrid
GBP 72,000 - 120,000
Manager, Global Cyber Security Incident Response (Global CSIRT)
Manager, Global Cyber Security Incident Response (Global CSIRT)

KPMG International Cooperative • City of Westminster

On-site
GBP 90,000 - 130,000
Security Analyst
Security Analyst

Talion Cyber Security • Wakefield

On-site
GBP 32,000 - 52,000
2nd/3rd Line Security Analyst
2nd/3rd Line Security Analyst

Xact Placements Limited • Reading

Hybrid
GBP 50,000 - 60,000
Hybrid work arrangement
Competitive salary
SOC Analyst
SOC Analyst

Inforcer • Richmond

On-site
GBP 42,000 - 64,000
Steep learning curve
Real impact
Transparent culture
+3
Cyber Security Analyst
Cyber Security Analyst

Synapri • Greater London

Hybrid
GBP 50,000 - 70,000