FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Cyber Incident Response and Security Operations, with a strong focus on incident analysis, threat hunting, and the application of frameworks such as MITRE ATT&CK and NIST. Proficient in developing and executing incident response plans, playbooks, and detection rules while maintaining evidence integrity.
Highest-signal resume keywords
Cyber Incident ResponseSIEM and EDR/XDR PlatformsMITRE ATT&CK FrameworkThreat HuntingIncident Response Plans
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Incident AnalysisForensic MethodologiesNetwork Traffic AnalysisMalware AnalysisScripting with PowerShellPython ProgrammingDetection Rule CreationSecurity Log AnalysisCloud SecurityVulnerability Management
Soft Skills
Analytical SkillsProblem-SolvingCommunication SkillsAbility to Work Under PressureTime Management
Tools & Technologies
Microsoft SentinelMicrosoft Defender XDRMicrosoft Defender for IdentityMicrosoft Defender for CloudEnCaseFTKWiresharkVelociraptorVolatilityThreat Intelligence Platforms
Certifications & Qualifications
GCIHGCIAGCFAGNFASC-200CySA+CISSP
Industry Keywords
Cyber SecuritySecurity Operations Center (SOC)Cyber DefenceData Protection ControlsRegulatory ConsiderationsCritical InfrastructureFinancial ServicesIncident Response LifecycleEmail SecurityIdentity and Access Management
Tech Stack
Tools & technologiesAzureCloudCyber SecurityLinuxPython
About the role
Key responsibilities & impact- Monitor and analyse alerts from SIEM, EDR/XDR, identity, email, cloud, network, and other security platforms
- Triage alerts, validate incidents, assess severity and business impact, and escalate according to defined processes and service levels
- Lead or support investigations into phishing, malware, account compromise, unauthorised access, data loss, and network-based attacks
- Coordinate containment, eradication, and recovery activities with internal teams and client stakeholders
- Maintain incident records, timelines, evidence, actions, and decision logs
- Produce incident reports, management updates, and post-incident summaries
- Collect, preserve, and analyse endpoint, server, identity, network, email, and cloud artefacts
- Perform host and network analysis using security logs, packet captures, forensic images, and telemetry data
- Identify indicators of compromise and attacker TTPs, mapping findings to MITRE ATT&CK
- Support sensitive investigations while maintaining evidence integrity and chain-of-custody requirements
- Develop and execute proactive, intelligence-led threat hunting activities
- Create, tune, and optimise detection rules, correlation logic, monitoring content, and custom indicators
- Identify detection gaps and improve detection and response capabilities
- Support purple-team exercises, penetration testing, and security control validation
- Act as a trusted security advisor during incidents and lead client communications
- Facilitate incident review meetings and present findings, recommendations, and lessons learned
- Collaborate with Security Operations, Professional Services, and Customer Success teams
- Develop, maintain, and improve incident response plans, playbooks, runbooks, and procedures
- Conduct post-incident reviews and root cause analyses
- Contribute to service reporting, risk indicators, trend analysis, and operational metrics
- Support cyber simulations and tabletop exercises
- Stay current with emerging threats, attack techniques, vulnerabilities, and industry best practices
Requirements
What you’ll need- Hands-on experience in Cyber Incident Response, Security Operations (SOC), or Cyber Defence environments
- Hands-on experience investigating security incidents using SIEM and EDR/XDR platforms
- Strong understanding of the incident response lifecycle
- Experience analysing Windows and Linux systems, authentication events, network traffic, and security logs
- Ability to create clear investigation reports, management updates, and technical documentation
- Knowledge of MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response frameworks
- Understanding of enterprise networking, identity and access management, cloud security, email security, endpoint protection, vulnerability management, and data protection controls
- Excellent analytical, problem-solving, and communication skills
- Ability to work effectively under pressure and manage multiple priorities
- Understanding of evidence handling, forensic methodologies, and regulatory considerations relevant to cyber investigations
- Experience in an MSSP, consultancy, financial services, critical infrastructure, or other highly regulated environment is desirable
- Experience with threat intelligence platforms, malware analysis, scripting, or automation using PowerShell, Python, KQL, or similar technologies is desirable
- Experience developing threat hunts, response playbooks, detection rules, or security orchestration and automation workflows is desirable
- Experience with Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Identity, or Microsoft Defender for Cloud is desirable
- Exposure to EnCase, FTK, Velociraptor, Volatility, Wireshark, or equivalent forensic technologies is desirable
- Experience investigating incidents across Azure, Microsoft 365, or other cloud platforms is desirable
- Degree in Cyber Security, Computer Science, Information Technology, or a related field, or equivalent practical experience
- Industry certifications are highly desirable, including GCIH, GCIA, GCFA, GNFA, SC-200, CySA+, CISSP, or equivalent cyber security certifications
- Strong understanding of NIST, CIS Controls, and relevant data privacy regulations
Benefits
Comp & perks- Competitive compensation
- Career growth opportunities
- Access to continuous learning and certifications
- Work with cutting-edge Azure technologies
- Opportunity to work on impactful cloud initiatives across various industries
- Access to cutting-edge MXDR platform and proprietary SecOps tools
- Fast-track leadership opportunities
- Culture-first environment with open feedback and innovation
