Incident Response Analyst
We are seeking an experienced Incident Response Analyst to support the detection, triage, investigation, containment and resolution of cyber security incidents across a complex enterprise environment.
Key Responsibilities
- Monitor and investigate alerts from SIEM, EDR/XDR, identity, email, cloud and network security technologies.
- Triage incidents, assess severity and business impact, and coordinate containment, eradication and recovery.
- Investigate phishing, malware, account compromise, data loss, unauthorised access and suspicious network activity.
- Collect, preserve and analyse endpoint, server, identity, network, email and cloud artefacts.
- Analyse logs, packet captures, forensic images and security telemetry to establish scope, root cause and attacker activity.
- Identify IOCs, attacker behaviours, TTPs and map findings to MITRE ATT&CK where appropriate.
- Develop and execute threat hunts and contribute to detection rule, monitoring and logging improvements.
- Maintain incident records, investigation timelines, evidence and post-incident reports.
- Develop and maintain incident response playbooks, procedures and communication processes.
- Conduct post-incident reviews, root-cause analysis and lessons-learned activities.
- Provide clear technical and management updates to senior stakeholders.
Essential Skills & Experience
- Practical experience in cyber security incident response, security monitoring or a SOC environment.
- Hands-on experience with SIEM and EDR/XDR technologies.
- Experience investigating Windows and Linux systems, authentication activity, security logs and network traffic.
- Strong understanding of the incident response lifecycle.
- Knowledge of MITRE ATT&CK, Cyber Kill Chain and NIST.
- Good understanding of enterprise networking, IAM, cloud, email and endpoint security.
- Experience with digital forensics and evidence handling.
- Strong communication, investigation and analytical skills.
Desirable
- Banking, financial services or other regulated-sector experience.
- Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.
- KQL, PowerShell, Python or similar scripting/automation.
- Threat hunting, malware analysis and detection engineering.
- Azure and Microsoft 365 investigation experience.
- EnCase, FTK, Velociraptor, Volatility or Wireshark.
- Certifications such as GCIH, GCIA, GCFA, GNFA, SC-200, CySA+ or CISSP.
Qualifications
- Relevant cyber security experience, degree or equivalent practical experience. Knowledge of NIST, CIS Controls and recognised information security standards
#J-18808-Ljbffr
SOC Analyst employer: Tank Recruitment
Join a dynamic technology team in London as a Lead Python Developer, where you will not only enhance your technical skills but also play a pivotal role in shaping the future of software development. Our hybrid working model promotes a healthy work-life balance, while our commitment to employee growth ensures you have ample opportunities for professional development and mentorship. Experience a collaborative culture that values innovation and encourages you to stay hands-on with coding, all within a vibrant city known for its tech advancements.