×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Information Security Incident Response Analyst

Job in London, Greater London, W1B, England, UK
Listing for: NTT
Full Time position
Listed on 2026-09-04
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
Make an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.

Job Description Summary The Information Security Incident Response Analyst supports clients during security incidents by performing technical investigations, analyzing digital forensic evidence, and assisting with containment and remediation activities. This role focuses on identifying indicators of compromise, reconstructing attacker activity, and communicating clear, actionable findings.

The analyst works as part of a global DFIR team, handling a variety of incident types across diverse environments. They contribute to process improvements, maintain strong client communication, and continue building advanced DFIR skills through hands‑on investigations and internal project work.

Job Description

Key Responsibilities Investigates security incidents by performing host, disk, memory, network, and cloud forensic analysis under established processes and guidance.

Analyzes artifacts across Windows, Linux, and macOS systems, helping reconstruct timelines and determine root cause.

Supports clients through containment and recovery efforts by providing technical recommendations and clear communication.

Participates in the team’s on‑call rotation for urgent incident response needs.

Completes internal and client tasks such as tabletop exercises, IR readiness assessments, basic forensic reviews, and environment hardening support.

Identifies observable gaps and risks within client environments and recommends improvements to strengthen security posture.

Produces accurate documentation—including investigation notes, status updates, and final reports.

Collaborates with global DFIR and other teams and stays current on threats, attacker techniques, and emerging forensic tools.

Knowledge and Attributes Solid understanding of digital forensics fundamentals, including host‑based analysis across major operating systems.

Working knowledge of network forensics, cloud log analysis (e.g., Azure, AWS, GCP), and common forensic tools.

Ability to clearly communicate technical findings to both technical and non‑technical audiences.

Strong analytical and problem‑solving skills, especially during time‑sensitive investigations.

Motivated to continuously learn deeper DFIR techniques and methodologies.

Required Experience Proven experience in incident response and digital forensics, with capability in host‑based, image, and log analysis.

Experience using SIEM, EDR, IDS/IPS, and other security tools to triage, investigate, and respond to incidents.

Ability to perform network analysis using tools such as Wireshark, tcpdump, and other tools.

Experience in cybersecurity operations, consulting, DFIR services, or related technical security roles.

Academic Qualifications, Certifications Bachelor’s degree or equivalent experience in Information Technology, Computer Science, Cybersecurity, or a related discipline (preferred).Relevant certifications such as:

SANS GIAC Security Essentials (GSEC) or equivalent preferred.

SANS GIAC Certified Intrusion Analyst (GCIA) or equivalent preferred.

SANS GIAC Certified Incident Handler (GCIH) or equivalent preferred.

GICSP – GIAC Global Industrial Cyber Security ProfessionalGRID – GIAC Response and Industrial DefenseGCIP – GIAC Critical Infrastructure ProtectionISA/IEC 62443 Cybersecurity Certificates (ISA/IEC 62443 Cybersecurity Fundamentals, etc.)IC32/IC33/IC34

Any additional DFIR‑related certifications.

Additional UK‑Specific Role Requirements UK Security Clearance Active UK Security Clearance is required to deliver services within sensitive or regulated client environments.

Operational Technology (OT) Incident Response & Digital Forensics Background and hands‑on experience in OT environments.

Experience investigating ICS/SCADA systems and industrial sectors such as manufacturing, energy, utilities, or critical infrastructure.

Ability to collect and analyze OT forensic artifacts, interpret OT protocols and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary