Senior Security Incident Response Analyst
Location: Aberdeen, Birmingham & Other locations
Capability: Corporate Services
Job details
Location: Aberdeen, Birmingham, Bristol, Cambridge, Cardiff, Edinburgh, Glasgow, Leeds, London, Manchester, Milton Keynes, Newcastle upon Tyne, Nottingham, Reading, South Coast - Southampton, Watford
Capability: Corporate Services
Experience Level: Associate/Assistant Manager
Type: Full Time
Business Area: Digital (Internal)
Contract type: Permanent
Job description
About the role
This role sits within Group Corporate Services, which supports KPMG's people and business through firmwide specialist services and operational capabilities. Within Security Operations, you will join the Tier 2 Incident Response team and take ownership of complex investigations across a diverse technology environment serving KPMG in the UK and Switzerland.
You will act as a senior escalation point for high-priority and major cyber security incidents, combining hands-on technical investigation with calm coordination and clear communication. The role is based in the UK on a hybrid basis and is at Grade D. Participation in the Security Operations on-call rota is required, including providing technical and operational leadership outside standard business hours. You must be eligible for Security Check clearance or able to obtain it.
Roles and responsibilities
Lead investigations into complex and high-severity cyber security incidents, establishing the scope, business impact and risk.
Coordinate containment, eradication and recovery activities so incidents progress efficiently to a controlled resolution.
Provide senior technical guidance to analysts and act as an escalation point during high-priority and major incidents, including through the on-call rota.
Conduct forensic investigation and evidence collection across endpoint, identity, cloud, email and network technologies.
Produce clear investigation timelines, root cause analysis and post-incident reports for technical and business stakeholders.
Work with Threat Intelligence and Detection Engineering teams to apply knowledge of emerging threats, improve detection coverage and strengthen investigations.
Lead proactive threat hunting to identify previously undetected activity, security weaknesses and opportunities to improve controls.
Improve incident response playbooks, processes, automation and operational standards, sharing knowledge across the wider cyber security function.
Experience and skills needed
Demonstrable experience in security operations, incident response, cyber defence or digital forensics, including ownership of escalated security incidents.
Evidence of investigating threats across endpoint, identity, cloud, email and network environments and translating findings into appropriate response actions.
Practical knowledge of attacker tactics, techniques and procedures, with experience applying this knowledge to investigations or threat hunting.
Experience leading technical investigations, building incident timelines and completing root cause analysis and post-incident reporting.
Strong analytical and problem-solving skills, with evidence of making sound decisions and coordinating activity during high-pressure incidents.
Clear written and verbal communication skills, with experience explaining technical findings to technical and non-technical stakeholders and collaborating across security teams.
Experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, Microsoft Purview, digital forensics and incident response tools, security orchestration and automation platforms, threat hunting methods, or cloud security technologies across Microsoft Azure, Amazon Web Services or Google Cloud Platform would be beneficial. Relevant certifications, such as Microsoft Certified: Security Operations Analyst Associate (SC-200), CompTIA Cybersecurity Analyst (CySA+), GIAC Certified Incident Handler (GCIH), GIAC Certified Forensic Analyst (GCFA), Microsoft Certified: Azure Security Engineer Associate (AZ-500), or an equivalent qualification, would also be advantageous.
Why Corporate Services at KPMG?
Corporate Services operates as a £multi-million business within our business and, through our combined efforts, we enable the firm to serve our people, our clients and wider society. The internal expertise, advice, support and services we provide to our client-facing business are fundamental to the success of our firm. Through collaboration, agility, fresh thinking and innovation, we help our people across the firm to work in a way that’s smarter and more sustainable. We’re a cross-functional team, bringing together technically knowledgeable experts across a wide range of critical activities to help grow, run and protect our business. Our areas span Corporate Affairs and Marketing, Digital, Finance and Commercial, People and Resourcing, and Risk and Legal.
Read about Corporate ServicesService Overview
Digital is the firm's primary provider of internal business and technology services, data, and innovation. We deliver secure, resilient, and standardised technology solutions that ensure our operations run seamlessly and empower colleagues to provide exceptional client service. Our mission is to propel KPMG into the future. We drive our digital strategy, safeguard against cyber threats, manage data responsibly, and provide cutting-edge tools for seamless collaboration. Through innovation and accelerated adoption of digital and AI capabilities, we support growth and transformation, unlocking significant value for both our colleagues and clients.
Read about DigitalAbout KPMG
With offices across the UK, we are part of a global network of firms providing Audit, Tax & Law, Consulting, and Technology Services to diverse clients.
Read moreOur Values
They provide us with a strong sense of identity, ensuring we can grow stronger. They bind us together, across our different backgrounds and cultures, and are common to each of us. Explore more about why Our Values matter.
Read moreFlexible hybrid working
From role sharing and flexible start and finish times to home working, we'll try and support the flexible work patterns that best suit you.
Read moreCommitted to inclusion
We’re committed to creating an inclusive environment where all colleagues thrive and reach their full potential, whatever their identity or background.
Read moreNeed support? Let us know
We're a member of the Business Disability Forum so please get in touch if you'd like to discuss any adjustments that you might need in the application process - and if you are successful beyond this.
Read moreDisability Confident Leader
We're a recognised leader in the Government's scheme. We offer a Guaranteed Interview Scheme for all experienced professional opportunities.
Read moreRecruitment agency policy
We don't accept speculative CVs from agencies - you can see our policy on agencies here:
Read more