SOC Analyst

Incident Response Analyst

We are seeking an experienced Incident Response Analyst to support the detection, triage, investigation, containment and resolution of cyber security incidents across a complex enterprise environment.

Key Responsibilities

  • Monitor and investigate alerts from SIEM, EDR/XDR, identity, email, cloud and network security technologies.

  • Triage incidents, assess severity and business impact, and coordinate containment, eradication and recovery.

  • Investigate phishing, malware, account compromise, data loss, unauthorised access and suspicious network activity.

  • Collect, preserve and analyse endpoint, server, identity, network, email and cloud artefacts.

  • Analyse logs, packet captures, forensic images and security telemetry to establish scope, root cause and attacker activity.

  • Identify IOCs, attacker behaviours, TTPs and map findings to MITRE ATT&CK where appropriate.

  • Develop and execute threat hunts and contribute to detection rule, monitoring and logging improvements.

  • Maintain incident records, investigation timelines, evidence and post-incident reports.

  • Develop and maintain incident response playbooks, procedures and communication processes.

  • Conduct post-incident reviews, root-cause analysis and lessons-learned activities.

  • Provide clear technical and management updates to senior stakeholders.

Essential Skills & Experience

  • Practical experience in cyber security incident response, security monitoring or a SOC environment.

  • Hands-on experience with SIEM and EDR/XDR technologies.

  • Experience investigating Windows and Linux systems, authentication activity, security logs and network traffic.

  • Strong understanding of the incident response lifecycle.

  • Knowledge of MITRE ATT&CK, Cyber Kill Chain and NIST.

  • Good understanding of enterprise networking, IAM, cloud, email and endpoint security.

  • Experience with digital forensics and evidence handling.

  • Strong communication, investigation and analytical skills.

Desirable

  • Banking, financial services or other regulated-sector experience.

  • Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.

  • KQL, PowerShell, Python or similar scripting/automation.

  • Threat hunting, malware analysis and detection engineering.

  • Azure and Microsoft 365 investigation experience.

  • EnCase, FTK, Velociraptor, Volatility or Wireshark.

  • Certifications such as GCIH, GCIA, GCFA, GNFA, SC-200, CySA+ or CISSP.

Qualifications

Relevant cyber security experience, degree or equivalent practical experience. Knowledge of NIST, CIS Controls and recognised information security standards.

Job Details

Company
Tank Recruitment
Location
London, United Kingdom
Employment Type
Contract
Posted