Incident Response Consultant (UK) in Edinburgh

Incident Response Consultant (UK) in Edinburgh

Edinburgh Full-Time Working from home possible
Quorum Cyber

At Quorum Cyber, we're on a mission to help good people win. Founded in Edinburgh in 2016, we're one of the fastest growing cyber security companies in the UK and North America, serving over 400 customers on four continents. We protect organisations against the rising threat of cyber-attacks, enabling them to thrive in an increasingly unpredictable and inhospitable digital landscape.


As a Microsoft-only security house, a Microsoft Solutions Partner for Security, a member of the Microsoft Intelligent Security Association (MISA), and winner of the Microsoft Security MSSP of the Year 2025 award, we offer a unified security ecosystem comprised of innovative services, all delivered through our customer platform, Clarity.


In September 2024, Quorum Cyber acquired Canada-based, Microsoft Solutions Partner for Security, Difenda. This was closely followed in December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities.


Role Purpose:


Incident Response is a core and strategic component of Quorum Cyber’s business. It is central to supporting our managed security services and MDR customers, providing specialist expertise when incidents require investigation, containment, remediation, and recovery beyond routine monitoring and response.


The Incident Response Consultant supports investigations into cyber security incidents and, with appropriate guidance, takes ownership of defined investigative workstreams. The role provides sound technical analysis, contributes to customer guidance, and works closely with the SOC, MDR, Threat Intelligence, and wider cyber security teams to ensure that incidents are managed effectively.


As an award-winning Microsoft Solutions Partner for Security, Quorum Cyber follows a Microsoft-first mission across its security services. The role develops practical expertise in Microsoft security technologies and telemetry while contributing to the evolution of Incident Response alongside Quorum Cyber’s MDR and SOC capabilities.


Agentic AI will increasingly support the collection, correlation, enrichment, prioritisation, and investigation of security data. The role will participate in the testing, validation, and safe adoption of AI-enabled Incident Response and MDR workflows, applying sound judgement, following defined processes, and escalating uncertainty or consequential decisions appropriately.


What I do is:


Incident Investigation & Analysis

  • Support investigations into cyber security incidents across diverse technologies and environments, taking ownership of defined investigative workstreams and seeking guidance when required.
  • Perform host, network, and memory forensics, including Windows, Linux, macOS, and multi-cloud artefact analysis.
  • Identify threat actor tools, tactics, and procedures (TTPs).
  • Analyse logs, network traffic, disk images, and volatile artefacts to determine attacker intent, actions, timelines, and impact.
  • Ensure evidence collection and handling follow best practice, including documentation and chain-of-custody standards.
  • Maintain awareness of emerging threats, malware families, and evolving threat actor behaviours.
  • Interact with customer stakeholders, legal teams, technical staff, and executive leadership during incidents.
  • Use lessons learned from incidents to improve internal and customer detection, escalation, containment, response, and recovery processes.
  • Work closely with the SOC, MDR, Threat Intelligence, and other specialist teams to coordinate investigations, improve escalation pathways, and enrich intelligence outputs.
  • Apply working knowledge of Microsoft security technologies and telemetry to investigate and respond to incidents affecting Microsoft-centric environments.
  • Participate in the testing, validation, and operationalisation of agentic AI-enabled Incident Response and MDR workflows.
  • Review AI-generated findings, investigative recommendations, and response actions using supporting evidence, defined processes, and appropriate escalation.
  • Identify and suggest opportunities to use AI and automation to improve the speed, consistency, and quality of incident investigation and response.
  • Feed incident findings, threat intelligence, and lessons learned back into SOC and MDR detection, triage, threat-hunting, and response capabilities.


Consulting, Advisory & Customer Engagement

  • Act as a technical point of contact for customers during incidents, communicating investigative findings, recommendations, and next steps clearly to technical and non-technical audiences.
  • Provide specialist Incident Response support to Quorum Cyber’s MSS and MDR customers when incidents require escalation beyond routine monitoring, triage, and response activities.
  • Support customers in maximising the security value of Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 capabilities during investigations and recovery activities.
  • Provide consultative advice that links technical threats and vulnerabilities to business risk, helping customers make informed decisions.
  • Assist internal and external teams with technical and privacy/security risk mitigation activities.
  • Support or deliver defined elements of Incident Response Readiness Assessments covering customer plans, playbooks, processes, and response capability.
  • Support the preparation and delivery of customer briefings and training on cyber security and incident response, including material for executive audiences.
  • Support the preparation and facilitation of cyber incident tabletop exercises to help customers test and improve their readiness.


Other

  • Share knowledge with junior IR team members and contribute to peer support, technical guidance, and quality assurance.
  • Support the continued development of Incident Response through contributions to methodologies, tooling, services, and operating processes.


The Skills I Need Are:


Technical Skills

  • Practical forensic analysis across Windows, Linux, macOS, and cloud platforms.
  • Memory forensics.
  • Network traffic and log analysis, including firewall, endpoint, web, authentication, and cloud telemetry.
  • Good working understanding of enterprise security controls (e.g., Active Directory, identity systems, and network architectures).
  • Experience using EDR and SIEM platforms for investigation and threat hunting.
  • Experience with Microsoft-aligned security stacks.
  • Practical experience investigating Microsoft security telemetry and incidents across Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 environments.
  • Understanding of how MDR and SOC operations support the wider Incident Response lifecycle, from detection and triage through to containment, eradication, and recovery.
  • Awareness of how agentic AI and automation can support security investigation and response activities.
  • Ability to review AI-generated outputs, identify errors or uncertainty, and escalate consequential decisions appropriately.
  • Ability to translate forensic findings, telemetry, threat intelligence, and AI-assisted analysis into clear customer advice and defensible response actions.
  • Ability to identify attacker behaviour patterns, extract IOCs, and map findings to threat actor TTPs.
  • Experience handling and preserving digital evidence to defensible standards, including chain of custody.
  • Ability to use or contribute to scripts, playbooks, or tooling that enhance investigation workflows.


Soft Skills / Behaviours

  • Strong written and verbal communication, able to convey complex findings with clarity.
  • Customer-centric mindset with an ability to build and maintain strong relationships.
  • Ability to think clearly and make sound decisions under pressure.
  • Analytical and detail-focused, with a curious and investigative mindset.
  • Effective collaboration across teams and disciplines.
  • Ability to support the development of junior colleagues through knowledge sharing and constructive feedback.


I Know I Have Done a Great Job if:


  • I contribute effectively to incident investigations and take ownership of defined workstreams, escalating issues appropriately.
  • MSS and MDR customers receive effective specialist support when incidents require escalation or deeper investigation.
  • I support impactful readiness assessments, training sessions, and cyber exercises that improve customer resilience.
  • I share knowledge with colleagues and contribute to the capability of the wider IR function.
  • I support improvements to Quorum Cyber’s Incident Response methodologies, tooling, services, and processes.
  • Lessons learned from incidents are used to improve detection, monitoring, playbooks, readiness, and response capability.
  • I contribute to the evolution of Incident Response and MDR, using AI and automation to improve speed, consistency, and scale without compromising evidence, accountability, or customer trust.
  • I contribute to the safe and effective adoption of agentic AI within Quorum Cyber’s SOC, MDR, and Incident Response capabilities.
  • I use Microsoft security technologies and telemetry effectively to investigate incidents and improve customer outcomes.
  • I demonstrate the technical, investigative, and consulting standards expected within a high-performing Incident Response function.


Other Information:


You will get an excellent salary, with world class benefits.


As leading-edge technology company you will have access to the latest technology, and an environment that will encourage and nurture your curiosity. We are passionate about your development, and you will be empowered to advance your skills and expertise.


Our Commitment to Equality & Diversity:


Our diversity is a huge part of our success, and collecting data during the hiring process helps us understand how to keep strengthening and supporting that diversity.


We are an equal opportunity employer. We are committed to fostering an inclusive, accessible, and equitable workplace where all qualified applicants receive fair consideration. We do not discriminate on the basis of race, national or ethnic origin, colour, religion, age, sex, sexual orientation, gender identity or expression, marital status, family status, disability, or any other characteristic protected under applicable federal, provincial, or territorial human rights legislation.


The information requested below is collected to help us meet our employment equity and reporting obligations, and to support our ongoing diversity and inclusion initiatives. Providing this information is entirely voluntary. It will not be shared with hiring managers and will not be used in any hiring decision. Declining to provide this information will not affect your application in any way.


Incident Response Consultant (UK) in Edinburgh employer: Quorum Cyber

At Quorum Cyber, we pride ourselves on being an exceptional employer, offering a dynamic work environment in the heart of Edinburgh. Our commitment to employee growth is evident through our world-class benefits and access to cutting-edge technology, fostering a culture of curiosity and innovation. Join us to be part of a diverse team dedicated to making a meaningful impact in the cyber security landscape while enjoying a supportive and inclusive workplace.

Quorum Cyber

Contact Details:

Quorum Cyber Recruitment Team