Overview
In this hands-on Detection and Response role, you will be at the frontline of JPMorganChase’s cyber defense, triaging alerts and driving end-to-end investigations. You will work within the London SOC to sustain 24/7 coverage across regions, collaborating with global teams to improve detections and response. You’ll apply threat hunting, detection engineering, and AI-assisted tooling to raise investigation speed and accuracy. This position offers meaningful work at scale in a fast-paced financial services environment.
Responsibilities
- Triage and analyze alerts from SIEM, EDR, and other detection tooling based on severity and business impact
- Investigate security incidents end-to-end from detection to containment, eradication and resolution
- Proactively hunt threats across endpoints, networks, cloud, and identity telemetry
- Contribute to detection engineering by tuning rules, use cases, and correlations
- Utilize AI-assisted tooling to accelerate investigations and improve efficiency
- Document findings, maintain case records, and produce incident reports and post-incident reviews
- Collaborate with global SOC teams, threat intel, IR, and engineering to ensure smooth handoffs under follow-the-sun model
- Contribute to playbooks, runbooks, and SOPs for continuous SOC improvement
- Stay current with threat landscape, ATT&CK techniques, and industry best practices
Key requirements
- 2+ years of SOC, incident response, or security analyst experience
- Solid understanding of security monitoring across SIEM, EDR/XDR, and network tooling
- Working knowledge of attack techniques, the cyber kill chain, and MITRE ATT&CK
- Strong networking concepts (TCP/IP, DNS, HTTP/S, proxies, firewalls) and OS internals (Windows, Linux)
- Experience investigating alerts across endpoint, network, cloud, and identity logs
- Ability to analyze logs, correlate events, and reconstruct incident timelines
- Strong written and verbal communication for documentation and updates
- Ability to work under pressure and participate in weekend rotation approximately every five weeks
- Clear communication
- Ability to work under pressure
- Collaborative mindset
- SIEM, EDR/XDR, and network security tooling
- MITRE ATT&CK framework
- Attack techniques and cyber kill chain knowledge
…
