Senior Security Incident Response Analyst at KPMG UK | GB | Rezi

Senior Security Incident Response Analyst at KPMG UK

Senior Security Incident Response Analyst

KPMG UK · GB

Today

Senior Security Incident Response Analyst

KPMG UK · GB

a day ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Senior Security Incident Response Analyst role.

Rezi rewrites your resume against KPMG UK's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Senior Security Incident Response Analyst posting at KPMG UK — free, in seconds.

About the Role

This role is within Group Corporate Services, supporting KPMG's people and business through specialist services. Within Security Operations, you will join the Tier 2 Incident Response team, taking ownership of complex investigations across a diverse technology environment for KPMG in the UK and Switzerland. You will act as a senior escalation point for high-priority cyber security incidents, combining hands-on technical investigation with calm coordination and clear communication. Participation in the Security Operations on-call rota is required, including providing technical and operational leadership outside standard business hours.

Responsibilities

  • Lead investigations into complex and high-severity cyber security incidents, establishing scope, business impact, and risk.
  • Coordinate containment, eradication, and recovery activities for efficient incident resolution.
  • Provide senior technical guidance to analysts and act as an escalation point during high-priority and major incidents, including through the on-call rota.
  • Conduct forensic investigation and evidence collection across endpoint, identity, cloud, email, and network technologies.
  • Produce clear investigation timelines, root cause analysis, and post-incident reports for technical and business stakeholders.
  • Work with Threat Intelligence and Detection Engineering teams to apply knowledge of emerging threats, improve detection coverage, and strengthen investigations.
  • Lead proactive threat hunting to identify undetected activity, security weaknesses, and opportunities to improve controls.
  • Improve incident response playbooks, processes, automation, and operational standards, sharing knowledge across the wider cyber security function.

Requirements

  • Demonstrable experience in security operations, incident response, cyber defence, or digital forensics, including ownership of escalated security incidents.
  • Evidence of investigating threats across endpoint, identity, cloud, email, and network environments and translating findings into appropriate response actions.
  • Practical knowledge of attacker tactics, techniques, and procedures, with experience applying this knowledge to investigations or threat hunting.
  • Experience leading technical investigations, building incident timelines, and completing root cause analysis and post-incident reporting.
  • Strong analytical and problem-solving skills, with evidence of making sound decisions and coordinating activity during high-pressure incidents.
  • Clear written and verbal communication skills, with experience explaining technical findings to technical and non-technical stakeholders and collaborating across security teams.
  • Eligible for or able to obtain Security Check clearance.

Skills

  • Microsoft Sentinel
  • Microsoft Defender XDR
  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Cloud
  • Microsoft Purview
  • Digital forensics tools
  • Incident response tools
  • Security orchestration and automation platforms
  • Threat hunting methods
  • Cloud security technologies (Microsoft Azure, Amazon Web Services, Google Cloud Platform)

Location

  • UK
  • Hybrid

Work Type

  • Hybrid

Experience Level

  • Senior

Education Level

  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • CompTIA Cybersecurity Analyst (CySA+)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Equivalent qualification

About the Company

  • KPMG is a global network of professional services firms providing audit, tax, and advisory services.