Incident Response Analyst

Harvey Nash UK · London, London

Incident Response Analyst at Harvey Nash UK, based in London, London. This is a contract role with hybrid working.

Salary
Competitive
Location
London, London · Hybrid
Contract
Contract
Posted
9 hours ago
Closes
6 Nov 2026
Sector
Security

Reference BBBH124119_1791569383

About the role

Contract Incident Response Analyst

Location: Hybrid / London 2 days Per Week

Contract Type: Contract

Day Rate: Competitive

We are seeking an experienced Incident Response Analyst to support a specialist Cyber Security function responsible for identifying, investigating and responding to cyber threats across a complex enterprise environment.

This role is ideal for a hands-on cyber security professional with strong experience in incident response, threat hunting, security operations and digital forensics. You will play a key role in protecting critical systems and data by managing security incidents through their full lifecycle while collaborating with technical and business stakeholders.

Key Responsibilities

  • Monitor and investigate security alerts generated by SIEM, EDR/XDR, identity, email, cloud and network security tools.
  • Lead and support cyber security incident investigations, including phishing, malware, account compromise, unauthorised access and data loss events.
  • Perform incident triage, determine business impact and coordinate containment, eradication and recovery activities.
  • Collect, preserve and analyse forensic artefacts from endpoints, servers, cloud platforms, networks and email systems.
  • Identify indicators of compromise (IOCs), attacker tactics and techniques, and document findings.
  • Conduct proactive threat hunting activities using threat intelligence and security telemetry.
  • Develop and improve detection content, monitoring rules and incident response playbooks.
  • Produce clear technical and management-level incident reports and post-incident reviews.
  • Support cyber exercises, simulations and continuous improvement initiatives.
  • Contribute to incident metrics, trend analysis and security governance reporting.

Essential Experience

  • Experience working within Incident Response, Cyber Security Operations or SOC environments.
  • Strong hands-on experience with SIEM and EDR/XDR technologies.
  • Proven ability to investigate and respond to cyber security incidents.
  • Knowledge of Windows and Linux security investigations, authentication events, security logs and network traffic analysis.
  • Understanding of the incident response lifecycle, including detection, analysis, containment, eradication and recovery.
  • Knowledge of frameworks such as MITRE ATT&CK, Cyber Kill Chain and NIST.
  • Understanding of enterprise networking, identity and access management, cloud security and email security technologies.
  • Excellent communication and stakeholder management skills.
  • Ability to work effectively in high-pressure environments and manage multiple priorities.

Desirable Experience

  • Experience within financial services or other regulated environments.
  • Microsoft Sentinel, Defender XDR, Defender for Identity or Defender for Cloud.
  • Threat intelligence, malware analysis, detection engineering or security automation.
  • PowerShell, Python, KQL or similar scripting languages.
  • Exposure to tools such as Wireshark, Velociraptor, EnCase, FTK or Volatility.
  • Experience investigating incidents across Microsoft 365 and Azure environments.

Qualifications

  • Degree in Cyber Security, Computer Science or a related discipline, or equivalent practical experience.
  • Relevant certifications such as GCIH, GCFA, GCIA, GNFA, SC-200, CySA+ or CISSP are highly desirable.

If you are a proactive cyber security professional with a passion for incident response and threat investigation, we would like to hear from you.

Reference: BBBH124119_1791569383 · Posted 9 hours ago · Closes 6 Nov 2026 · Listed via Harvey Nash UK

Know someone who'd be great for this? Get a shareable card

Apply for this job

This role is listed via Harvey Nash UK. Applications are handled on the employer's site.

Apply on employer site

Opens the employer's website in a new tab.

Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.

Report this job
Salary Competitive
Apply now