Quorum Cyber logo
Quorum Cyber
Posted 13 days agoVerified live 2d ago

Incident Response Consultant (North America)

Brief overview

Remote
UndergradOr in progress
3+ yrsMinimum
Digital ForensicsMemory ForensicsNetwork Traffic and Log AnalysisWindows, Linux, and macOSCloud PlatformsActive DirectoryEDR and SIEM PlatformsMicrosoft DefenderMicrosoft SentinelMicrosoft EntraMicrosoft AzureMicrosoft 365Customer Relationship Management

About the company

Quorum Cyber logo
Quorum Cyberquorumcyber.com

Quorum Cyber is a cybersecurity company that provides managed security and professional services to organizations.

Job description

Summary

Quorum Cyber is a Microsoft-focused cybersecurity company providing security services through its customer platform, Clarity. The Incident Response Consultant supports cyber incident investigations, performs forensic and telemetry analysis, advises customers, and collaborates with SOC, MDR, Threat Intelligence, and other specialist teams. The role also contributes to readiness assessments, customer training, incident response improvements, and the safe adoption of AI-enabled workflows.

Responsibilities

  • Support investigations into cyber security incidents across diverse technologies and environments, taking ownership of defined investigative workstreams and seeking guidance when required
  • Perform host, network, and memory forensics, including Windows, Linux, macOS, and multi-cloud artefact analysis
  • Identify threat actor tools, tactics, and procedures (TTPs)
  • Analyse logs, network traffic, disk images, and volatile artefacts to determine attacker intent, actions, timelines, and impact
  • Ensure evidence collection and handling follow best practice, including documentation and chain-of-custody standards
  • Maintain awareness of emerging threats, malware families, and evolving threat actor behaviours
  • Interact with customer stakeholders, legal teams, technical staff, and executive leadership during incidents
  • Use lessons learned from incidents to improve internal and customer detection, escalation, containment, response, and recovery processes
  • Work closely with the SOC, MDR, Threat Intelligence, and other specialist teams to coordinate investigations, improve escalation pathways, and enrich intelligence outputs
  • Apply working knowledge of Microsoft security technologies and telemetry to investigate and respond to incidents affecting Microsoft-centric environments
  • Participate in the testing, validation, and operationalisation of agentic AI-enabled Incident Response and MDR workflows
  • Review AI-generated findings, investigative recommendations, and response actions using supporting evidence, defined processes, and appropriate escalation
  • Identify and suggest opportunities to use AI and automation to improve the speed, consistency, and quality of incident investigation and response
  • Feed incident findings, threat intelligence, and lessons learned back into SOC and MDR detection, triage, threat-hunting, and response capabilities
  • Act as a technical point of contact for customers during incidents, communicating investigative findings, recommendations, and next steps clearly to technical and non-technical audiences
  • Provide specialist Incident Response support to Quorum Cyber's MSS and MDR customers when incidents require escalation beyond routine monitoring, triage, and response activities
  • Support customers in maximising the security value of Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 capabilities during investigations and recovery activities
  • Provide consultative advice that links technical threats and vulnerabilities to business risk, helping customers make informed decisions
  • Assist internal and external teams with technical and privacy/security risk mitigation activities
  • Support or deliver defined elements of Incident Response Readiness Assessments covering customer plans, playbooks, processes, and response capability
  • Support the preparation and delivery of customer briefings and training on cyber security and incident response, including material for executive audiences
  • Support the preparation and facilitation of cyber incident tabletop exercises to help customers test and improve their readiness
  • Share knowledge with junior IR team members and contribute to peer support, technical guidance, and quality assurance
  • Support the continued development of Incident Response through contributions to methodologies, tooling, services, and operating processes

Skills

  • Practical forensic analysis across Windows, Linux, macOS, and cloud platforms
  • Memory forensics
  • Network traffic and log analysis, including firewall, endpoint, web, authentication, and cloud telemetry
  • Good working understanding of enterprise security controls (e.g., Active Directory, identity systems, and network architectures)
  • Experience using EDR and SIEM platforms for investigation and threat hunting
  • Experience with Microsoft-aligned security stacks
  • Practical experience investigating Microsoft security telemetry and incidents across Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 environments
  • Understanding of how MDR and SOC operations support the wider Incident Response lifecycle, from detection and triage through to containment, eradication, and recovery
  • Awareness of how agentic AI and automation can support security investigation and response activities
  • Ability to review AI-generated outputs, identify errors or uncertainty, and escalate consequential decisions appropriately
  • Ability to translate forensic findings, telemetry, threat intelligence, and AI-assisted analysis into clear customer advice and defensible response actions
  • Ability to identify attacker behaviour patterns, extract IOCs, and map findings to threat actor TTPs
  • Experience handling and preserving digital evidence to defensible standards, including chain of custody
  • Ability to use or contribute to scripts, playbooks, or tooling that enhance investigation workflows
  • Strong written and verbal communication, able to convey complex findings with clarity
  • Customer-centric mindset with an ability to build and maintain strong relationships
  • Ability to think clearly and make sound decisions under pressure
  • Analytical and detail-focused, with a curious and investigative mindset
  • Effective collaboration across teams and disciplines
  • Ability to support the development of junior colleagues through knowledge sharing and constructive feedback

Qualifications

Must Haves

  • Practical forensic analysis across Windows, Linux, macOS, and cloud platforms
  • Memory forensics
  • Network traffic and log analysis, including firewall, endpoint, web, authentication, and cloud telemetry
  • Good working understanding of enterprise security controls (e.g., Active Directory, identity systems, and network architectures)
  • Experience using EDR and SIEM platforms for investigation and threat hunting
  • Experience with Microsoft-aligned security stacks
  • Practical experience investigating Microsoft security telemetry and incidents across Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 environments
  • Understanding of how MDR and SOC operations support the wider Incident Response lifecycle, from detection and triage through to containment, eradication, and recovery
  • Awareness of how agentic AI and automation can support security investigation and response activities
  • Ability to review AI-generated outputs, identify errors or uncertainty, and escalate consequential decisions appropriately
  • Ability to translate forensic findings, telemetry, threat intelligence, and AI-assisted analysis into clear customer advice and defensible response actions
  • Ability to identify attacker behaviour patterns, extract IOCs, and map findings to threat actor TTPs
  • Experience handling and preserving digital evidence to defensible standards, including chain of custody
  • Ability to use or contribute to scripts, playbooks, or tooling that enhance investigation workflows
  • Strong written and verbal communication, able to convey complex findings with clarity
  • Customer-centric mindset with an ability to build and maintain strong relationships
  • Ability to think clearly and make sound decisions under pressure
  • Analytical and detail-focused, with a curious and investigative mindset
  • Effective collaboration across teams and disciplines
  • Ability to support the development of junior colleagues through knowledge sharing and constructive feedback

Benefits

  • Access to the latest technology
  • An environment that will encourage and nurture your curiosity
  • Development opportunities and support to advance your skills and expertise
  • World class benefits

More jobs like this