SOC Analyst

BBBH97688_1791466872
  • Negotiable
  • London

Incident Response Analyst

We are seeking an experienced Incident Response Analyst to support the detection, triage, investigation, containment and resolution of cyber security incidents across a complex enterprise environment.

Key Responsibilities

  • Monitor and investigate alerts from SIEM, EDR/XDR, identity, email, cloud and network security technologies.

  • Triage incidents, assess severity and business impact, and coordinate containment, eradication and recovery.

  • Investigate phishing, malware, account compromise, data loss, unauthorised access and suspicious network activity.

  • Collect, preserve and analyse endpoint, server, identity, network, email and cloud artefacts.

  • Analyse logs, packet captures, forensic images and security telemetry to establish scope, root cause and attacker activity.

  • Identify IOCs, attacker behaviours, TTPs and map findings to MITRE ATT&CK where appropriate.

  • Develop and execute threat hunts and contribute to detection rule, monitoring and logging improvements.

  • Maintain incident records, investigation timelines, evidence and post-incident reports.

  • Develop and maintain incident response playbooks, procedures and communication processes.

  • Conduct post-incident reviews, root-cause analysis and lessons-learned activities.

  • Provide clear technical and management updates to senior stakeholders.

Essential Skills & Experience

  • Practical experience in cyber security incident response, security monitoring or a SOC environment.

  • Hands-on experience with SIEM and EDR/XDR technologies.

  • Experience investigating Windows and Linux systems, authentication activity, security logs and network traffic.

  • Strong understanding of the incident response lifecycle.

  • Knowledge of MITRE ATT&CK, Cyber Kill Chain and NIST.

  • Good understanding of enterprise networking, IAM, cloud, email and endpoint security.

  • Experience with digital forensics and evidence handling.

  • Strong communication, investigation and analytical skills.

Desirable

  • Banking, financial services or other regulated-sector experience.

  • Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.

  • KQL, PowerShell, Python or similar scripting/automation.

  • Threat hunting, malware analysis and detection engineering.

  • Azure and Microsoft 365 investigation experience.

  • EnCase, FTK, Velociraptor, Volatility or Wireshark.

  • Certifications such as GCIH, GCIA, GCFA, GNFA, SC-200, CySA+ or CISSP.

Qualifications

Relevant cyber security experience, degree or equivalent practical experience. Knowledge of NIST, CIS Controls and recognised information security standards.

Harrison Griffiths Associate Recruitment Consultant

Apply for this role