Information Security Incident Response Analyst
Key details
- Compensation
- $55,000 - $95,000
Job Description
Salary: £55,000 - 95,000 per year
Requirements
- We are looking for solid understanding of digital forensics fundamentals, including host-based analysis across major operating systems.
- We need working knowledge of network forensics, cloud log analysis across Azure, AWS, and GCP, and common forensic tools.
- We expect the ability to communicate technical findings clearly to both technical and non-technical audiences.
- We value strong analytical and problem-solving skills, especially during time-sensitive investigations.
- We are looking for someone motivated to continuously learn deeper DFIR techniques and methodologies.
- We require proven experience in incident response and digital forensics, with capability in host-based, image, and log analysis.
- We need experience using SIEM, EDR, IDS/IPS, and other security tools to triage, investigate, and respond to incidents.
- We expect ability to perform network analysis using tools such as Wireshark, tcpdump, and similar tools.
- We require experience in cybersecurity operations, consulting, DFIR services, or related technical security roles.
- We prefer a bachelors degree or equivalent experience in Information Technology, Computer Science, Cybersecurity, or a related discipline.
- We prefer relevant certifications such as GSEC, GCIA, GCIH, GICSP, GRID, GCIP, ISA/IEC 62443 certifications, IC32, IC33, IC34, or other DFIR-related certifications.
- We require active UK Security Clearance to deliver services within sensitive or regulated client environments.
- We need background and hands-on experience in OT environments.
- We require experience investigating ICS/SCADA systems and industrial sectors such as manufacturing, energy, utilities, or critical infrastructure.
- We need the ability to collect and analyze OT forensic artifacts, interpret OT protocols and system behavior, and assess the impact of cyber incidents on physical processes.
- We prefer experience with tools such as Claroty CTD, Nozomi Guardian, Dragos Platform, Tenable.ot, or Forescout/SCADAfence.
Responsibilities
- We investigate security incidents by performing host, disk, memory, network, and cloud forensic analysis under established processes and guidance.
- We analyze artifacts across Windows, Linux, and macOS systems to help reconstruct timelines and determine root cause.
- We support clients through containment and recovery efforts by providing technical recommendations and clear communication.
- We participate in our teams on-call rotation for urgent incident response needs.
- We complete internal and client tasks such as tabletop exercises, IR readiness assessments, basic forensic reviews, and environment hardening support.
- We identify observable gaps and risks within client environments and recommend improvements to strengthen security posture.
- We produce accurate documentation, including investigation notes, status updates, and final reports.
- We collaborate with our global DFIR and other teams and stay current on threats, attacker techniques, and emerging forensic tools.
Technologies
- AWS
- Azure
- Cloud
- GCP
- Support
- Linux
- macOS
- Network
- Security
- Windows
- AI
More
We are NTT DATA, a $30+ billion business and technology services leader serving 75% of the Fortune Global 100. We are recognized for technical excellence, leading innovations, and responsible innovation that helps clients and society move confidently and sustainably into the digital future. We are a global Top Employer with experts in more than 70 countries and a strong ecosystem of innovation centers and partners. This is a remote working role within our global DFIR and information security organization, where we embrace diversity, inclusion, and career growth.
last updated 34 week of 2026
Company & context
Evidence is labeled so you can tell internal community data from public sources.
Range from 44 indexed roles at this employer: $38,000 - $95,000(mid ~71023)
Context reflects data collected at crawl time.
Trust-check this listing
Verify scam risk and ghost-job signals before you apply.
Related roles
Browse more remote Security Engineer jobs, or every remote job category.
Senior Integrations Engineer
Test Automation Engineer
Developer / Engineer
Source: DevITJobs • Last updated 1w ago