Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Incident Response Consultant (North America)

Full-time

Quorum Cyber

At Quorum Cyber, we're on a mission to help good people win. Founded in Edinburgh in 2016, we're one of the fastest growing cyber security companies in the UK and North America, serving over 400 customers on four continents. We protect organisations against the rising threat of cyber-attacks, enabling them to thrive in an increasingly unpredictable and inhospitable digital landscape.

As a Microsoft-only security house, a Microsoft Solutions Partner for Security, a member of the Microsoft Intelligent Security Association (MISA), and winner of the Microsoft Security MSSP of the Year 2025 award, we offer a unified security ecosystem comprised of innovative services, all delivered through our customer platform, Clarity.

In September 2024, Quorum Cyber acquired Canada-based, Microsoft Solutions Partner for Security, Difenda. This was closely followed in December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities.

Role Purpose: 

Incident Response is a core and strategic component of Quorum Cyber's business. It is central to supporting our managed security services and MDR customers, providing specialist expertise when incidents require investigation, containment, remediation, and recovery beyond routine monitoring and response. 

The Incident Response Consultant supports investigations into cyber security incidents and, with appropriate guidance, takes ownership of defined investigative workstreams. The role provides sound technical analysis, contributes to customer guidance, and works closely with the SOC, MDR, Threat Intelligence, and wider cyber security teams to ensure that incidents are managed effectively. 

As an award-winning Microsoft Solutions Partner for Security, Quorum Cyber follows a Microsoft-first mission across its security services. The role develops practical expertise in Microsoft security technologies and telemetry while contributing to the evolution of Incident Response alongside Quorum Cyber's MDR and SOC capabilities. 

Agentic AI will increasingly support the collection, correlation, enrichment, prioritisation, and investigation of security data. The role will participate in the testing, validation, and safe adoption of AI-enabled Incident Response and MDR workflows, applying sound judgement, following defined processes, and escalating uncertainty or consequential decisions appropriately.

What I do is:

Incident Investigation & Analysis

  • Support investigations into cyber security incidents across diverse technologies and environments, taking ownership of defined investigative workstreams and seeking guidance when required.
  • Perform host, network, and memory forensics, including Windows, Linux, macOS, and multi-cloud artefact analysis.
  • Identify threat actor tools, tactics, and procedures (TTPs).
  • Analyse logs, network traffic, disk images, and volatile artefacts to determine attacker intent, actions, timelines, and impact.
  • Ensure evidence collection and handling follow best practice, including documentation and chain-of-custody standards.
  • Maintain awareness of emerging threats, malware families, and evolving threat actor behaviours.
  • Interact with customer stakeholders, legal teams, technical staff, and executive leadership during incidents.
  • Use lessons learned from incidents to improve internal and customer detection, escalation, containment, response, and recovery processes.
  • Work closely with the SOC, MDR, Threat Intelligence, and other specialist teams to coordinate investigations, improve escalation pathways, and enrich intelligence outputs.
  • Apply working knowledge of Microsoft security technologies and telemetry to investigate and respond to incidents affecting Microsoft-centric environments.
  • Participate in the testing, validation, and operationalisation of agentic AI-enabled Incident Response and MDR workflows.
  • Review AI-generated findings, investigative recommendations, and response actions using supporting evidence, defined processes, and appropriate escalation.
  • Identify and suggest opportunities to use AI and automation to improve the speed, consistency, and quality of incident investigation and response.
  • Feed incident findings, threat intelligence, and lessons learned back into SOC and MDR detection, triage, threat-hunting, and response capabilities.

Consulting, Advisory & Customer Engagement

  • Act as a technical point of contact for customers during incidents, communicating investigative findings, recommendations, and next steps clearly to technical and non-technical audiences.
  • Provide specialist Incident Response support to Quorum Cyber's MSS and MDR customers when incidents require escalation beyond routine monitoring, triage, and response activities.
  • Support customers in maximising the security value of Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 capabilities during investigations and recovery activities.
  • Provide consultative advice that links technical threats and vulnerabilities to business risk, helping customers make informed decisions.
  • Assist internal and external teams with technical and privacy/security risk mitigation activities.
  • Support or deliver defined elements of Incident Response Readiness Assessments covering customer plans, playbooks, processes, and response capability.
  • Support the preparation and delivery of customer briefings and training on cyber security and incident response, including material for executive audiences.
  • Support the preparation and facilitation of cyber incident tabletop exercises to help customers test and improve their readiness.

Other

  • Share knowledge with junior IR team members and contribute to peer support, technical guidance, and quality assurance.
  • Support the continued development of Incident Response through contributions to methodologies, tooling, services, and operating processes.

The Skills I Need Are:

Technical Skills

  • Practical forensic analysis across Windows, Linux, macOS, and cloud platforms.
  • Memory forensics.
  • Network traffic and log analysis, including firewall, endpoint, web, authentication, and cloud telemetry.
  • Good working understanding of enterprise security controls (e.g., Active Directory, identity systems, and network architectures).
  • Experience using EDR and SIEM platforms for investigation and threat hunting.
  • Experience with Microsoft-aligned security stacks.
  • Practical experience investigating Microsoft security telemetry and incidents across Microsoft Defender, Sentinel, Entra, Azure, and Microsoft 365 environments.
  • Understanding of how MDR and SOC operations support the wider Incident Response lifecycle, from detection and triage through to containment, eradication, and recovery.
  • Awareness of how agentic AI and automation can support security investigation and response activities.
  • Ability to review AI-generated outputs, identify errors or uncertainty, and escalate consequential decisions appropriately.
  • Ability to translate forensic findings, telemetry, threat intelligence, and AI-assisted analysis into clear customer advice and defensible response actions.
  • Ability to identify attacker behaviour patterns, extract IOCs, and map findings to threat actor TTPs.
  • Experience handling and preserving digital evidence to defensible standards, including chain of custody.
  • Ability to use or contribute to scripts, playbooks, or tooling that enhance investigation workflows.

Soft Skills / Behaviours

  • Strong written and verbal communication, able to convey complex findings with clarity.
  • Customer-centric mindset with an ability to build and maintain strong relationships.
  • Ability to think clearly and make sound decisions under pressure.
  • Analytical and detail-focused, with a curious and investigative mindset.
  • Effective collaboration across teams and disciplines.
  • Ability to support the development of junior colleagues through knowledge sharing and constructive feedback.

I Know I Have Done a Great Job if:

  • I contribute effectively to incident investigations and take ownership of defined workstreams, escalating issues appropriately.
  • MSS and MDR customers receive effective specialist support when incidents require escalation or deeper investigation.
  • I support impactful readiness assessments, training sessions, and cyber exercises that improve customer resilience.
  • I share knowledge with colleagues and contribute to the capability of the wider IR function.
  • I support improvements to Quorum Cyber's Incident Response methodologies, tooling, services, and processes.
  • Lessons learned from incidents are used to improve detection, monitoring, playbooks, readiness, and response capability.
  • I contribute to the evolution of Incident Response and MDR, using AI and automation to improve speed, consistency, and scale without compromising evidence, accountability, or customer trust.
  • I contribute to the safe and effective adoption of agentic AI within Quorum Cyber's SOC, MDR, and Incident Response capabilities.
  • I use Microsoft security technologies and telemetry effectively to investigate incidents and improve customer outcomes.
  • I demonstrate the technical, investigative, and consulting standards expected within a high-performing Incident Response function.

Other Information:

You will get an excellent salary, with world class benefits.

As leading-edge technology company you will have access to the latest technology, and an environment that will encourage and nurture your curiosity. We are passionate about your development, and you will be empowered to advance your skills and expertise.

Our Commitment to Equality & Diversity:

Our diversity is a huge part of our success, and collecting data during the hiring process helps us understand how to keep strengthening and supporting that diversity.

We are an equal opportunity employer. We are committed to fostering an inclusive, accessible, and equitable workplace where all qualified applicants receive fair consideration. We do not discriminate on the basis of race, national or ethnic origin, colour, religion, age, sex, sexual orientation, gender identity or expression, marital status, family status, disability, or any other characteristic protected under applicable federal, provincial, or territorial human rights legislation.

The information requested below is collected to help us meet our employment equity and reporting obligations, and to support our ongoing diversity and inclusion initiatives. Providing this information is entirely voluntary. It will not be shared with hiring managers and will not be used in any hiring decision. Declining to provide this information will not affect your application in any way.

Vacancy posted 17 days ago
Similar jobs that could be interesting for youBased on the Incident Response Consultant (North America) in United States vacancy
  •  ...growing cyber security companies in the UK and North America, serving over 400 customers on four...  ...December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities. Role Purpose:... 
    Suggested
    Permanent employment

    Quorum Cyber

    United States
    17 days ago
  • $140k - $160k

    ## Incident Response Analyst - AmericasApply: Hybrid: Washington, DC: Full time: Posted 3 Days Ago: R-00291**Company Profile**The Carlyle...  ...more than 2,500 professionals operating in 28 offices in North America, Europe, the Middle East, Asia and Australia.Carlyle’s purpose... 
    Suggested
    Full time
    Work at office

    Carlyle Group

    Eastern, KY
    4 days ago
  • $176.6k - $239k

     ...address customer threat detection and incident response requirements, and help them secure their...  ...professional who has the ability to consult and build a wide range of threat detection...  ...most security-conscious customers in North America. We hold the security relationship and... 
    Suggested
    Local area
    Worldwide
    Flexible hours

    AmazonWebServices

    San Francisco, CA
    1 day ago
  •  ...Director Automation - North America We are seeking a Director Automation – North America...  ...Canada, and Puerto Rico. This role is responsible for translating strategy into execution...  ...environmental training Report any accidents/incidents to supervisor Assist in... 
    Suggested

    BioDot

    Chicago, IL
    4 days ago
  • $138k - $200k

     ...customer teams to investigate and contain incidents.Recognize and codify attacker Tools,...  ...and malware triage in support of incident response investigations.Develop and present comprehensive...  ...project management skills.As a Security Consultant, you will be responsible for helping... 
    Suggested

    Google

    New York, NY
    4 days ago
  •  ...insurance brand for Toyota and Lexus in North America. While TFS is a separate business...  ...seeking an experienced and proactive Post Incident Review Lead to oversee and drive the post...  ...and incidents. This leadership role is responsible for managing the PIR team, ensuring thorough... 
    H1b

    TCC Toyota Motor Credit Corporation Company

    Plano, TX
    1 day ago
  •  ...Senior Consultant, Digital Forensic and Incident Response (DFIR) (Remote) Remote, USA / Exempt Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to cyber incidents such as ransomware, email compromise, malware, data... 
    Full time
    Local area
    Remote work
    Flexible hours
    Weekend work

    Surefire Cyber

    United States
    5 days ago
  •  ...Senior Consultant, Digital Forensic and Incident Response (DFIR) (Remote) Remote About Surefire Cyber Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to cyber incidents such as ransomware, email compromise, malware... 
    Full time
    Contract work
    For contractors
    For subcontractor
    Work at office
    Local area
    Remote work
    Flexible hours
    Weekend work

    Surefire Cyber Inc.

    United States
    1 day ago
  • $110k - $145k

     ...Job Description Senior Incident Response Consultant | $110,000 – $145,000 \n \n A specialist consulting client of ours is hiring a Senior Incident Response Consultant into an established DFIR practice, reporting to the Director of Incident Response. \n \n... 
    Immediate start

    Maestro Search

    Tysons Corner, VA
    7 days ago
  • Forensic Focus is seeking a Senior Incident Response Consultant to lead client-facing investigations across cloud, endpoint, and network environments. You will conduct threat hunting, malware triage, containment, and crisis management while documenting attacker TTPs and... 
    Remote job

    Forensic Focus

    Eastern, KY
    18 hours ago
  •  ...expected to contribute to a culture of responsible AI adoption, experimentation, and innovation...  ...motivated, self-driven, technical consultants dedicated to making a difference in global...  ...of engagements including front page incident response investigations for organizations... 
    Work experience placement
    Work at office

    NEPSE Trading

    Eastern, KY
    3 days ago
  •  ...NORTH AMERICA Human Resources Manager The North America Human Resources Manager is responsible for overseeing day to day Human Resources operations across the United States and Canada, including recruitment, onboarding, employee relations, benefits administration, compliance... 
    Hourly pay
    Full time
    Work at office
    Local area
    Remote work
    Monday to Friday
    Flexible hours

    Caudalie

    New York, NY
    1 day ago
  •  ...with Infrastructure and business teams.This role has a strong incident response and security operations focus, with opportunities to apply...  ...requiring five days per week in our Salt Lake City, Utah or Raleigh, North Carolina office, designed to foster the collaboration and... 
    Full time
    Work at office
    Flexible hours
    Afternoon shift

    Western Governors University

    Salt Lake City, UT
    20 hours ago
  • $75k - $150k

     ...where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As an Incident & Response Consultant within PNC's SRC First Response organization, you will be based in Phoenix, AZ, Strongsville, OH, or Pittsburgh, PA.... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office
    Shift work

    Fairygodboss

    Phoenix, AZ
    5 days ago
  • $115k - $160k

     ...expected to contribute to a culture of responsible AI adoption, experimentation, and innovation...  ...motivated, self-driven, technical consultants dedicated to making a difference in global...  ...of engagements including front page incident response investigations for organizations... 
    Remote job
    Work experience placement
    Work at office
    Local area

    CrowdStrike Holdings, Inc.

    New York, NY
    3 days ago
  •  ...at the same time.   Social Media & Influencer Manager — North America Chicago (preferred) or US remote · Hybrid · Full-time The...  ...calls demanding money, recognize these as scams. Groupon is not responsible for losses from such dealings. For legitimate job openings (... 
    Permanent employment
    Full time
    Work at office
    Local area
    Remote work

    Groupon

    Chicago, IL
    a month ago
  •  ...compliant decision-making.The roleWe're looking for an East Coast-based marketer owning integrated field marketing and campaigns across North America, with a strong focus on the major financial hubs around the New York financial districts. Working in close partnership with the... 
    Shorter hours
    Local area
    Work from home

    Ideals

    New York, NY
    1 day ago
  • $110k - $120k

     ...hands-on, Talent Acquisition Manager to lead recruitment across North America. This role will shape and execute recruiting strategies...  ...for corporate positions while partnering with the TA Partner responsible for retail and field hiring Provide recruitment support and... 
    Full time
    Work at office

    Puig

    New York, NY
    1 day ago
  • $174.1k - $287.27k

     ...ēz Global LLC (MDLZ) is seeking a Sr. Director - Global Law, North America and Global Professional Services Spend Area to serve as the lead...  ...small team of lawyers, including one in Mexico, you will be responsible to:Drive solutions and enable business objectives in a... 
    Full time
    Contract work
    Relocation package

    Mondelēz International

    Chicago, IL
    3 days ago
  • Position: Director - Fresh Produce - North AmericaLocation: OPENEuropean Seed Company...  ...their Fresh Produce division in North America.This position is a combination of business...  ...individuals at those Key Accounts.Responsibilities:Structuring a long-term product development... 

    Tri-S Recruiters

    Chicago, IL
    5 days ago
  • $238k - $278k

    This position is with Recordati Rare Diseases, Inc. (RRD), North America, an affiliate of Recordati.Recordati Rare Diseases, Inc. (RRD)...  ...will serve as our field-based scientific expert and leader, responsible for managing and guiding a national team of Associate Regional... 
    Work at office
    Local area
    Night shift
    Weekend work

    EUSA Pharma

    Bridgewater, NJ
    3 days ago
  • $246.8k - $333.9k

     ...startups build, grow, and scale on AWS. Within this organization, North America Startups represents one of our largest and most...  ...management of an entire market segment with substantial P&L responsibility, direct influence on AWS product strategy through customer and... 
    Local area
    Worldwide
    Flexible hours
    Shift work

    AmazonWebServices

    San Francisco, CA
    1 day ago
  •  ...strategic, organized, and results-driven North America Tax Team Leader (NATT) to provide...  ...review annual studies prepared by external consulting firmsR&E Tax CreditTransfer Pricing2. State...  ...as warrantedPrepare and submit written responses and supporting documentation to... 
    Full time
    Temporary work
    For contractors
    Local area
    Immediate start

    LG Electronics

    Englewood Cliffs, NJ
    5 days ago
  •  ...Pharma is a dynamic and fast-paced organization that has been responsive to the needs of individual employees throughout its history....  ...Assurance (QA), GCP Clinical Site, Laboratory & Vendor Oversight North America and South America Ascentage Pharma is seeking an... 
    Full time

    Ascentage Pharma

    United States
    3 days ago
  • $177k - $237k

     ...2025. Learn more at .About the TeamCoreWeave’s North America Environmental, Health & Safety (EHS) team is responsible for ensuring safe, compliant, and audit-ready operations...  ...where CoreWeave operates.Own regional incident reporting, investigation, and root-cause analysis... 
    Permanent employment
    Full time
    Temporary work
    Casual work
    Work at office
    Local area
    Flexible hours

    CoreWeave

    Livingston, NJ
    2 days ago
  • $97.5k - $130k

     ...Manager Utilities- Refrigeration/PSM, North AmericaPosition Type: Regular - Full-Time...  ...Utilities (PSM/Refrigeration), North America is responsible for leading the ongoing development...  ...North American production facilities.Lead incident investigations and root cause analyses... 
    Full time
    For contractors
    Work experience placement
    Work at office
    Remote work
    Work from home
    2 days per week

    McCain

    Chicago, IL
    3 days ago
  •  ...experience serving residential and commercial customers across North America. As part of a global leader in pest control and related...  ...Vice President, Human Resources for Orkin is a senior HR leader responsible for developing and executing the people strategy for a large,... 
    Work at office
    Local area

    Orkin

    Atlanta, GA
    5 days ago
  • $140k - $160k

     ...environments?Join Artefact, a global data and AI consulting firm helping organizations turn data...  ....com.The RoleAs Head of People, North America, you will own and shape the people strategy...  ....Managers and employees experience responsive, high-quality People support.Leadership... 
    Work at office
    Local area
    Worldwide
    Free visa
    Shift work

    Artefact

    New York, NY
    2 days ago
  • $110k - $120k

     ...hands-on, Talent Acquisition Manager to lead recruitment across North America. This role will shape and execute recruiting strategies...  ...for corporate positions while partnering with the TA Partner responsible for retail and field hiringProvide recruitment support and guidance... 
    Work at office

    Puig

    New York, NY
    2 days ago
  • $130.9k - $196.3k

     ...Our Security Operations Center (SOC) team is responsible for a broad range of security operations, including monitoring, incident response, risk assessment, policy...  ...week in our Salt Lake City, Utah or Raleigh, North Carolina office, designed to foster the collaboration... 
    Full time
    Work at office
    Flexible hours

    Western Governors University

    Raleigh, NC
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Incident Response Consultant (North America). Be the first to apply!