Overview
The Incident Response Analyst will provide critical support to a large enterprise customer by monitoring and managing security incidents in a hybrid environment. Working closely with various stakeholders including technology, risk, and compliance teams, the analyst will be responsible for detecting, triaging, investigating, and containing security incidents from initiation to resolution, leveraging tools like Microsoft Sentinel and Defender XDR. This contract position offers a unique opportunity for hands-on engagement in a dynamic incident response role, with the potential for a varied workload and customer interaction in a regulated space.
Responsibilities
- Monitor and analyse alerts across Sentinel, Defender XDR, identity, email, cloud, and network controls, triaging and escalating by severity and business impact.
- Lead or support investigations into phishing, malware, account compromise, data loss, and unauthorised access.
- Coordinate containment, eradication, and recovery with infrastructure, identity, cloud, and business teams.
- Collect, preserve, and analyse endpoint, network, email, and cloud artefacts with proper evidence handling and chain of custody, mapping findings to MITRE ATT&CK.
- Run hypothesis-led threat hunts in KQL and tune detection content to close gaps found during incidents.
- Maintain incident response plans, playbooks, and procedures; run post-incident reviews and support cyber exercises.
- Produce clear incident records, investigation reports, and customer and management updates.
Requirements
- Hands-on incident response experience within an MSSP or MDR provider, handling live incidents across multiple customers.
- Customer facing experience, ideally supporting financial services or other regulated environments.
- Calm, confident communication skills with customers and senior stakeholders during live incidents.
- Proficiency in Microsoft Sentinel and Defender XDR, with strong skills in KQL for investigations and threat hunting.
- Experience analyzing Windows and Linux host artefacts, authentication activity, security logs, network traffic, and packet captures.
- Solid understanding of the incident response lifecycle, MITRE ATT&CK, the Cyber Kill Chain, and NIST guidance.
- Familiarity with PowerShell or Python scripting, and forensic tools such as Velociraptor, Volatility, FTK, EnCase, or Wireshark is desirable.
- Certifications such as GCIH, GCIA, GCFA, GNFA, SC 200, CySA+, or CISSP are a plus.