via Indeed
$90K - 130K a year
Lead complex incident investigations, provide expert technical analysis and strategic advice, and mentor junior team members to enhance customer resilience and incident response capabilities.
Advanced forensic analysis skills across multiple platforms, deep knowledge of Microsoft security stack, experience with EDR and SIEM platforms, strong communication and mentoring abilities, and ability to manage complex incident response engagements.
At Quorum Cyber, we're on a mission to help good people win. Founded in Edinburgh in 2016, we're one of the fastest growing cyber security companies in the UK and North America, serving over 400 customers on four continents. We protect organisations against the rising threat of cyber-attacks, enabling them to thrive in an increasingly unpredictable and inhospitable digital landscape. As a Microsoft-only security house, a Microsoft Solutions Partner for Security, a member of the Microsoft Intelligent Security Association (MISA), and winner of the Microsoft Security MSSP of the Year 2025 award, we offer a unified security ecosystem comprised of innovative services, all delivered through our customer platform, Clarity. In September 2024, Quorum Cyber acquired Canada-based, Microsoft Solutions Partner for Security, Difenda. This was closely followed in December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities. Role Purpose: Incident Response is a core and strategic component of Quorum Cyber's business. It is central to supporting our managed security services and MDR customers, providing specialist expertise when incidents require investigation, containment, remediation, and recovery beyond routine monitoring and response. The Senior Incident Response Consultant leads and conducts complex cyber security investigations, providing expert technical analysis, guidance, and strategic advice to customers. This role combines advanced digital forensics, threat analysis, and incident response leadership with consulting, mentoring, and readiness activities that strengthen customer resilience and support Quorum Cyber's mission to protect organisations from harm. The role works closely with the SOC, MDR, Threat Intelligence, and wider cyber security teams to ensure that incidents are managed effectively and that lessons learned are used to strengthen detection, response, readiness, and overall customer resilience. The role also contributes to the continued development of Quorum Cyber's Incident Response capability through consulting, guiding, service improvement, and customer readiness activities. As an award-winning Microsoft Solutions Partner for Security, Quorum Cyber follows a Microsoft-first mission across its security services. The Senior Incident Response Consultant will apply expert knowledge of Microsoft security technologies and telemetry while helping Incident Response evolve alongside Quorum Cyber's MDR and SOC capabilities. Agentic AI will increasingly support the collection, correlation, enrichment, prioritisation, and investigation of security data. The role will contribute to the design, testing, validation, and safe adoption of AI-enabled Incident Response and MDR workflows, applying expert judgement to validate AI-generated findings, identify uncertainty, and ensure that investigative and response activity remains evidence-based, auditable, proportionate, and accountable. What I do is: Incident Investigation & Analysis • Lead complex incident investigations across diverse technologies, environments, and customer situations, including working outside core hours when required. • Perform advanced host, network, and memory forensics, including Windows, Linux, macOS, and multi-cloud artefact analysis. • Identify threat actor tools, tactics, and procedures (TTPs). • Analyse logs, network traffic, disk images, and volatile artefacts to determine attacker intent, actions, timelines, and impact. • Ensure evidence collection and handling follow best practice, including documentation and chain-of-custody standards. • Maintain deep situational awareness of emerging threats, malware families, and evolving threat actor behaviours. • Interact with customer stakeholders, legal teams, technical staff, and executive leadership during incidents. • Use lessons learned from incidents to improve internal and customer detection, escalation, containment, response, and recovery processes. • Work closely with the SOC, MDR, Threat Intelligence, and other specialist teams to coordinate investigations, improve escalation pathways, and enrich intelligence outputs. • Apply deep knowledge of Microsoft security technologies and telemetry to investigate and respond to incidents affecting Microsoft-centric environments. • Contribute to the design, testing, and operationalisation of agentic AI-enabled Incident Response and MDR workflows. • Validate findings, investigative recommendations, and response actions using expert technical judgement and supporting evidence. • Identify opportunities to use AI and automation to improve the speed, scale, consistency, and quality of incident investigation and response. • Feed incident findings, threat intelligence, and lessons learned back into SOC and MDR detection, triage, threat-hunting, and response capabilities. Consulting, Advisory & Customer Engagement • Act as a senior technical point of contact for customers during significant cyber security incidents, communicating investigative findings, recommendations, and strategic guidance clearly to technical and non-technical audiences. • Provide specialist Incident Response support to Quorum Cyber's MSS and MDR customers when incidents require escalation beyond routine monitoring, triage, and response activities. • Help customers maximise the security value of Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 capabilities during investigations and recovery activities. • Provide consultative advice that links technical threats and vulnerabilities to business risk, helping customers make informed decisions. • Assist internal and external teams with technical and privacy/security risk mitigation activities. • Deliver Incident Response Readiness Assessments of customer IR plans, playbooks, and response capability. • Provide executive and board-level training on cyber security and incident response. • Facilitate cyber incident tabletop exercises to help customers test and improve their readiness. Other • Mentor junior IR team members through coaching, technical guidance, peer review, and quality assurance. • Contribute to the continued development of Incident Response as a strategic Quorum Cyber capability, including improvements to methodologies, tooling, services, and operating processes. The Skills I Need Are: Technical Skills • Advanced forensic analysis across Windows, Linux, macOS, and cloud platforms. • Memory forensics. • Network traffic and log analysis, including firewall, endpoint, web, authentication, and cloud telemetry. • Deep understanding of enterprise security controls (e.g., Active Directory, identity systems, network architectures). • Proficiency with EDR and SIEM platforms for investigation and threat hunting. Also leveraging them for compromise assessment scenarios. • Experience with Microsoft's security stack: practical experience investigating Microsoft security telemetry and incidents across Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 environments. • Understanding of how MDR and SOC operations support the wider Incident Response lifecycle, from detection and triage through to containment, eradication, and recovery. • Awareness of how agentic AI and automation can support security investigation and response activities. • Ability to critically assess AI-generated outputs, identify errors or uncertainty, and retain appropriate human oversight over consequential decisions. • Ability to translate forensic findings, telemetry, threat intelligence, and AI-assisted analysis into clear customer advice and defensible response actions. • Ability to identify attacker behaviour patterns, extract IOCs, and map findings to threat actor TTPs. • Experience handling and preserving digital evidence to defensible standards, including chain of custody. • Experience building scripts, playbooks, or tooling that automate or enhance investigation workflows. Soft Skills / Behaviours • Strong written and verbal communication, able to convey complex findings with clarity. • Customer-centric mindset with an ability to build and maintain strong relationships. • Ability to think clearly and make sound decisions under pressure. • Analytical and detail-focused, with a curious and investigative mindset. • Effective collaboration across teams and disciplines. • Ability to mentor, influence, and support the development of junior colleagues. I Know I Have Done A Great Job If: • I lead or support complex incident investigations that reach timely, effective, and well-evidenced outcomes. • MSS and MDR customers receive effective specialist support when incidents require escalation or deeper investigation. • I deliver impactful readiness assessments, training sessions, and cyber exercises that improve customer resilience. • I mentor junior team members and help raise the capability of the entire IR function. • I contribute to the continued maturity of Quorum Cyber's strategic Incident Response capability by improving methodologies, tooling, services, and processes. • Lessons learned from incidents are used to improve detection, monitoring, playbooks, readiness, and response capability. • I help Incident Response and MDR evolve together, using AI and automation to improve speed, consistency, and scale without compromising evidence, accountability, or customer trust. • I help drive the safe and effective adoption of agentic AI within Quorum Cyber's SOC, MDR, and Incident Response capabilities. • I use Microsoft security technologies and telemetry effectively to investigate incidents and improve customer outcomes. • I maintain the technical, investigative, and consulting standards expected of an elite Incident Response function. Other Information: You will get an excellent salary, with world class benefits. As leading-edge technology company you will have access to the latest technology, and an environment that will encourage and nurture your curiosity. We are passionate about your development, and you will be empowered to advance your skills and expertise. Our Commitment to Equality & Diversity: Our diversity is a huge part of our success, and collecting data during the hiring process helps us understand how to keep strengthening and supporting that diversity. We are an equal opportunity employer. We are committed to fostering an inclusive, accessible, and equitable workplace where all qualified applicants receive fair consideration. We do not discriminate on the basis of race, national or ethnic origin, colour, religion, age, sex, sexual orientation, gender identity or expression, marital status, family status, disability, or any other characteristic protected under applicable federal, provincial, or territorial human rights legislation. The information requested below is collected to help us meet our employment equity and reporting obligations, and to support our ongoing diversity and inclusion initiatives. Providing this information is entirely voluntary. It will not be shared with hiring managers and will not be used in any hiring decision. Declining to provide this information will not affect your application in any way.
This job posting was last updated on 9/22/2026