Incident Response Consultant (North America)

Quorum Cyber

United States

Hybrid

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Quorum Cyber is seeking an experienced Incident Response professional in the United States to lead investigations, perform forensics, and coordinate with SOC, MDR and client teams. You will analyse Windows, Linux, macOS and cloud environments, identify attacker TTPs, and help shape response actions.

The role requires deep technical skills in security telemetry, Microsoft-aligned security stacks, and experience with AI-enabled incident workflows.

Qualifications

  • Experience performing host, network, and memory forensics.
  • Proficient in analysing logs, traffic, disks, and volatile artefacts.
  • Familiar with Windows, Linux, macOS and multi-cloud environments.
  • Strong understanding of enterprise security controls and attacker TTPs.
  • Experience with AI-enabled IR workflows is a plus.

Responsibilities

  • Support investigations into cyber security incidents across diverse technologies and environments.
  • Perform forensics and evidence handling with proper chain-of-custody.
  • Identify threat actor tools, tactics, and procedures (TTPs).
  • Analyse logs, network traffic, and artefacts to determine attacker actions and impact.
  • Interact with customers and stakeholders during incidents and provide guidance.
  • Collaborate with SOC, MDR, Threat Intelligence and other teams.
  • Contribute to improving detection, escalation, containment and recovery processes.

Skills

Forensic analysis
Memory forensics
Log & network analysis
EDR & SIEM usage
Microsoft security stack
Threat hunting
Scripting / automation
I/O and evidence handling
Communication

Tools

EDR
SIEM
Microsoft Defender
Azure/M365 security tools

Job description

At Quorum Cyber, we're on a mission to help good people win. Founded in Edinburgh in 2016, we're one of the fastest growing cyber security companies in the UK and North America, serving over 400 customers on four continents. We protect organisations against the rising threat of cyber-attacks, enabling them to thrive in an increasingly unpredictable and inhospitable digital landscape.

As a Microsoft-only security house, a Microsoft Solutions Partner for Security, a member of the Microsoft Intelligent Security Association (MISA), and winner of the Microsoft Security MSSP of the Year 2025 award, we offer a unified security ecosystem comprised of innovative services, all delivered through our customer platform, Clarity.

In September 2024, Quorum Cyber acquired Canada-based, Microsoft Solutions Partner for Security, Difenda. This was closely followed in December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities.

Role Purpose:

Incident Response is a core and strategic component of Quorum Cyber's business. It is central to supporting our managed security services and MDR customers, providing specialist expertise when incidents require investigation, containment, remediation, and recovery beyond routine monitoring and response.

The Incident Response Consultant supports investigations into cyber security incidents and, with appropriate guidance, takes ownership of defined investigative workstreams. The role provides sound technical analysis, contributes to customer guidance, and works closely with the SOC, MDR, Threat Intelligence, and wider cyber security teams to ensure that incidents are managed effectively.

As an award-winning Microsoft Solutions Partner for Security, Quorum Cyber follows a Microsoft-first mission across its security services. The role develops practical expertise in Microsoft security technologies and telemetry while contributing to the evolution of Incident Response alongside Quorum Cyber's MDR and SOC capabilities.

Agentic AI will increasingly support the collection, correlation, enrichment, prioritisation, and investigation of security data. The role will participate in the testing, validation, and safe adoption of AI-enabled Incident Response and MDR workflows, applying sound judgement, following defined processes, and escalating uncertainty or consequential decisions appropriately.

What I do is:
Incident Investigation & Analysis
  • Support investigations into cyber security incidents across diverse technologies and environments, taking ownership of defined investigative workstreams and seeking guidance when required.
  • Perform host, network, and memory forensics, including Windows, Linux, macOS, and multi-cloud artefact analysis.
  • Identify threat actor tools, tactics, and procedures (TTPs).
  • Analyse logs, network traffic, disk images, and volatile artefacts to determine attacker intent, actions, timelines, and impact.
  • Ensure evidence collection and handling follow best practice, including documentation and chain-of-custody standards.
  • Maintain awareness of emerging threats, malware families, and evolving threat actor behaviours.
  • Interact with customer stakeholders, legal teams, technical staff, and executive leadership during incidents.
  • Use lessons learned from incidents to improve internal and customer detection, escalation, containment, response, and recovery processes.
  • Work closely with the SOC, MDR, Threat Intelligence, and other specialist teams to coordinate investigations, improve escalation pathways, and enrich intelligence outputs.
  • Apply working knowledge of Microsoft security technologies and telemetry to investigate and respond to incidents affecting Microsoft-centric environments.
  • Participate in the testing, validation, and operationalisation of agentic AI-enabled Incident Response and MDR workflows.
  • Review AI-generated findings, investigative recommendations, and response actions using supporting evidence, defined processes, and appropriate escalation.
  • Identify and suggest opportunities to use AI and automation to improve the speed, consistency, and quality of incident investigation and response.
  • Feed incident findings, threat intelligence, and lessons learned back into SOC and MDR detection, triage, threat-hunting, and response capabilities.
Consulting, Advisory & Customer Engagement
  • Act as a technical point of contact for customers during incidents, communicating investigative findings, recommendations, and next steps clearly to technical and non-technical audiences.
  • Provide specialist Incident Response support to Quorum Cyber's MSS and MDR customers when incidents require escalation beyond routine monitoring, triage, and response activities.
  • Support customers in maximising the security value of Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 capabilities during investigations and recovery activities.
  • Provide consultative advice that links technical threats and vulnerabilities to business risk, helping customers make informed decisions.
  • Assist internal and external teams with technical and privacy/security risk mitigation activities.
  • Support or deliver defined elements of Incident Response Readiness Assessments covering customer plans, playbooks, processes, and response capability.
  • Support the preparation and delivery of customer briefings and training on cyber security and incident response, including material for executive audiences.
  • Support the preparation and facilitation of cyber incident tabletop exercises to help customers test and improve their readiness.
Other
  • Share knowledge with junior IR team members and contribute to peer support, technical guidance, and quality assurance.
  • Support the continued development of Incident Response through contributions to methodologies, tooling, services, and operating processes.
The Skills I Need Are:
Technical Skills
  • Practical forensic analysis across Windows, Linux, macOS, and cloud platforms.
  • Memory forensics.
  • Network traffic and log analysis, including firewall, endpoint, web, authentication, and cloud telemetry.
  • Good working understanding of enterprise security controls (e.g., Active Directory, identity systems, and network architectures).
  • Experience using EDR and SIEM platforms for investigation and threat hunting.
  • Experience with Microsoft-aligned security stacks.
  • Practical experience investigating Microsoft security telemetry and incidents across Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 environments.
  • Understanding of how MDR and SOC operations support the wider Incident Response lifecycle, from detection and triage through to containment, eradication, and recovery.
  • Awareness of how agentic AI and automation can support security investigation and response activities.
  • Ability to review AI-generated outputs, identify errors or uncertainty, and elevate consequential decisions appropriately.
  • Ability to translate forensic findings, telemetry, threat intelligence, and AI-assisted analysis into clear customer advice and defensible response actions.
  • Ability to identify attacker behaviour patterns, extract IOCs, and map findings to threat actor TTPs.
  • Experience handling and preserving digital evidence to defensible standards, including chain of custody.
  • Ability to use or contribute to scripts, playbooks, or tooling that enhance investigation workflows.
Soft Skills / Behaviours
  • Strong written and verbal communication, able to convey complex findings with clarity.
  • Customer-centric mindset with an ability to build and maintain strong relationships.
  • Ability to think clearly and make sound decisions under pressure.
  • Analytical and detail-focused, with a curious and investigative mindset.
  • Effective collaboration across teams and disciplines.
  • Ability to support the development of junior colleagues through knowledge sharing and constructive feedback.
I Know I Have Done a Great Job if:
  • I contribute effectively to incident investigations and take ownership of defined workstreams, escalating issues appropriately.
  • MSS and MDR customers receive effective specialist support when incidents require escalation or deeper investigation.
  • I support impactful readiness assessments, training sessions, and cyber exercises that improve customer resilience.
  • I share knowledge with colleagues and contribute to the capability of the wider IR function.
  • I support improvements to Quorum Cyber's Incident Response methodologies, tooling, services, and processes.
  • Lessons learned from incidents are used to improve detection, monitoring, playbooks, readiness, and response capability.
  • I contribute to the evolution of Incident Response and MDR, using AI and automation to improve speed, consistency, and scale without compromising evidence, accountability, or customer trust.
  • I contribute to the safe and effective adoption of agentic AI within Quorum Cyber's SOC, MDR, and Incident Response capabilities.
  • I use Microsoft security technologies and telemetry effectively to investigate incidents and improve customer outcomes.
  • I demonstrate the technical, investigative, and consulting standards expected within a high-performing Incident Response function.
Other Information:

You will get an excellent salary, with world class benefits.

As leading-edge technology company you will have access to the latest technology, and an environment that will encourage and nurture your curiosity. We are passionate about your development, and you will be empowered to advance your skills and expertise.

Our Commitment to Equality & Diversity:

Our diversity is a huge part of our success, and collecting data during the hiring process helps us understand how to keep strengthening and supporting that diversity.

We are an equal opportunity employer. We are committed to fostering an inclusive, accessible, and equitable workplace where all qualified applicants receive fair consideration. We do not discriminate on the basis of race, national or ethnic origin, colour, religion, age, sex, sexual orientation, gender identity or expression, marital status, family status, disability, or any other characteristic protected under applicable federal, provincial, or territorial human rights legislation.

The information requested below is collected to help us meet our employment equity and reporting obligations, and to support our ongoing diversity and inclusion initiatives. Providing this information is entirely voluntary. It will not be shared with hiring managers and will not be used in any hiring decision. Declining to provide this information will not affect your application in any way.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Incident Response Consultant (North America)
Senior Incident Response Consultant (North America)

Quorum Cyber • United States

On-site
USD 140,000 - 190,000
World class benefits
Senior Director, Security Architect (USA - Remote)
Senior Director, Security Architect (USA - Remote)

Quorum Software • United States

On-site
USD 180,000 - 260,000
Senior Director, Security Architect (USA - Remote)
Senior Director, Security Architect (USA - Remote)

Quorum Business Solutions • Houston (TX)

Remote
USD 180,000 - 260,000
Incident Response Engineer 2
Incident Response Engineer 2

Sophos • United States

Remote
USD 85,000 - 120,000
Remote-first
Flexible schedule
Incident Response Manager
Incident Response Manager

Fortuna Cysec • Atlanta (GA)

On-site
USD 100,000 - 150,000
Microsoft Consultant
Microsoft Consultant

eSentire, Inc. • Northern (KY)

Hybrid
USD 105,000 - 125,000
Annual bonus
Commission plan
Competitive benefits
+3
Microsoft Consultant
Microsoft Consultant

eSentire • United States

On-site
USD 105,000 - 125,000
Annual bonus or commission
Competitive benefits
Paid parental leave
+2
SOC Analyst - US
SOC Analyst - US

Inforcer Ltd. • Cerritos (CA)

On-site
USD 90,000 - 120,000
Technical Expert (AI Transformation) - Hybrid Work Model
Technical Expert (AI Transformation) - Hybrid Work Model

Quorum Software • Houston (TX)

Hybrid
USD 120,000 - 180,000
Hybrid work model
SOC Manager
SOC Manager

Qnity • Wilmington (DE)

On-site
USD 140,000 - 190,000
Competitive pay
Benefits package