Incident Response Analyst in London

Incident Response Analyst in London

London Part-Time On-site
C

Incident Response Analyst

πŸ’° Β£500 to Β£550 per day DOE, outside IR35

πŸ“ Hybrid, London two days per week


Company & role

A specialist Microsoft security partner with its own managed detection and response service is bringing in contract incident responders to support a large enterprise customer. It is an initial contract running roughly November to March, with starts targeted within around three weeks.


You will sit within an incident response function covering EMEA, representing the partner in front of the customer. You will detect, triage, investigate and contain incidents from first alert to closure, combining security monitoring, incident handling, threat hunting and digital forensics across a Microsoft Sentinel and Defender XDR environment. Working alongside technology, risk, legal, compliance and third party stakeholders, you will be the calm, credible voice in the room when an incident is live.


Why This Role Stands Out

  • Full lifecycle incident response, from detection through to post incident review, not just alert triage.
  • A genuine mix of forensics, threat hunting and detection improvement, so no two weeks look the same.
  • Customer facing work on sensitive investigations in a regulated environment, where how you handle the room matters as much as the technical work.
  • Outside IR35 with a defined initial term, and a team that wants to move fast.


Key Responsibilities

  • Monitor and analyse alerts across Sentinel, Defender XDR, identity, email, cloud and network controls, triaging and escalating by severity and business impact
  • Lead or support investigations into phishing, malware, account compromise, data loss and unauthorised access
  • Coordinate containment, eradication and recovery with infrastructure, identity, cloud and business teams
  • Collect, preserve and analyse endpoint, network, email and cloud artefacts with proper evidence handling and chain of custody, mapping findings to MITRE ATT&CK
  • Run hypothesis led threat hunts in KQL and tune detection content to close gaps found during incidents
  • Maintain incident response plans, playbooks and procedures, run post incident reviews and support cyber exercises
  • Produce clear incident records, investigation reports, and customer and management updates


Ideal Experience

  • Hands on incident response experience within an MSSP or MDR provider, handling live incidents across multiple customers
  • Customer facing experience, ideally supporting financial services or other regulated customers
  • Calm, confident communication with customers and senior stakeholders when an incident is live
  • Hands on investigation in Microsoft Sentinel and Defender XDR, with confident KQL for investigations and threat hunting, including Defender advanced hunting
  • Analysing Windows and Linux host artefacts, authentication activity, security logs, network traffic and packet captures
  • Solid understanding of the incident response lifecycle, MITRE ATT&CK, the Cyber Kill Chain and NIST guidance
  • Desirable: PowerShell or Python scripting, forensic tools such as Velociraptor, Volatility, FTK, EnCase or Wireshark, and cloud investigations across Azure and Microsoft 365
  • Certifications such as GCIH, GCIA, GCFA, GNFA, SC 200, CySA+ or CISSP are a plus


If you have handled real incidents for MSSP customers and can keep a room calm when it matters, this is worth a look.


Incident Response Analyst in London employer: Cloud People

Cloud People is an exceptional employer, offering a dynamic work culture that fosters innovation and collaboration. With opportunities for professional growth and the flexibility of hybrid work, employees can thrive in a supportive environment while contributing to cutting-edge AI solutions for the finance sector. The unique blend of working in London with travel to the UAE enhances both personal and professional experiences, making it a rewarding place to build your career.

C

Contact Details:

Cloud People Recruitment Team