Location: London, City - 3-4 days in office.
Details: Initial 6 month contract, with guaranteed conversion to perm within that period.
Perm salary: up to 120k
Initial contract rate: TBC
Requirements:
- Significant experience within L2/L3 SOC and Incident Response environments, ideally operating as part of a global security function across complex enterprise environments.
- Proven track record of leading cyber investigations from initial detection through containment, eradication and recovery, taking ownership of incident prioritisation, escalation, coordination and resolution.
- Strong expertise across SIEM and security monitoring platforms, including Splunk, Microsoft Sentinel and QRadar, with the ability to oversee complex investigations and guide analysts through effective use of security telemetry.
- Extensive understanding of modern attack techniques, adversary behaviour and intrusion methodologies, with the ability to assess activity against frameworks such as MITRE ATT&CK and translate findings into actionable response strategies.
- Strong knowledge of established incident response methodologies and industry best practice, including NIST and SANS, with experience developing, improving and embedding effective incident handling processes.
- Demonstrable ability to lead investigations across multiple sources of evidence, including endpoint telemetry, network traffic, system and authentication logs, packet captures and other forensic data.
- Broad technical understanding of enterprise security controls, including EDR, firewalls, IDS/IPS and network security technologies, with the ability to assess their effectiveness and direct their use during active incidents.
- Advanced experience developing and leveraging investigative queries for incident response and threat hunting, including Splunk SPL and CrowdStrike Query Language, while supporting the development of detection and hunting capabilities across the wider SOC.
- Experience providing technical leadership during high-severity incidents, coordinating activity across SOC, infrastructure, engineering, threat intelligence and other relevant teams to drive timely and effective resolution.
- Ability to communicate complex security incidents, business impact, technical risk and remediation requirements clearly to senior leadership, risk functions and non-technical stakeholders.
- Demonstrated ability to mentor and support junior analysts, provide investigative guidance and contribute to the development of SOC and Incident Response capability, processes and standards.
- Strong analytical and investigative approach, with the judgement to make informed decisions under pressure and maintain clear direction throughout complex or high-impact security incidents.
- Good understanding of the regulatory and control environment surrounding enterprise cybersecurity, including GDPR, DORA, ISO 27001, NIST Cybersecurity Framework and CIS Controls.
#J-18808-Ljbffr
Senior Incident Response Analyst employer: Bonhill Partners
As a leading global investment bank, we pride ourselves on fostering a dynamic and inclusive work culture that empowers our employees to excel. Our Regulatory Reporting team offers unparalleled opportunities for professional growth, with access to cutting-edge training and development resources, all while working in a fast-paced environment that values collaboration and innovation. Join us in London, where you will be at the forefront of regulatory change initiatives, making a meaningful impact in the world of equities.