Starting salary: £29,000
Team: Detection and Response Team (DART)
Location: Remote hybrid, with occasional travel to JUMPSEC’s London headquarters and client sites as required
Working pattern: Rotating shifts and participation in a paid on-call rota
DART Responder
The role
JUMPSEC is looking for a DART Responder to join our Detection and Response Team.
DART provides managed detection and response, threat hunting and incident response services to organisations across a range of industries. The team investigates suspicious activity across endpoint, identity, email, cloud and network environments, helping clients understand what has happened, contain threats and reduce the likelihood of recurrence.
This is not a traditional tiered SOC role where work is passed between separate levels of analyst. Our responders work in collaborative squads and are expected to take ownership of investigations, develop clear conclusions and communicate directly with clients.
You will initially work with support from experienced responders and security engineers. As your capability develops, you will take responsibility for increasingly complex investigations, participate in threat hunting and contribute to live incident response engagements.
What you will do
Security investigations
-
Investigate security alerts and suspicious activity across client environments.
-
Review endpoint, identity, email, cloud and network telemetry.
-
Establish what happened, how it happened and which systems or accounts may be affected.
-
Distinguish malicious activity from legitimate or benign behaviour.
-
Document evidence, investigative reasoning and conclusions clearly.
-
Escalate incidents based on risk, impact and the strength of available evidence.
-
Recommend appropriate containment, remediation and recovery actions.
Managed detection and response
-
Monitor and investigate activity across multiple client environments.
-
Take ownership of assigned cases through to an appropriate conclusion.
-
Work with client IT and security teams to validate activity and coordinate response actions.
-
Maintain accurate investigation records and provide clear operational updates.
-
Support authorised containment actions, including endpoint isolation and account restriction.
-
Contribute to shift handovers and ensure ongoing investigations are transferred effectively.
Threat hunting
-
Participate in structured threat hunting activities.
-
Develop and test hypotheses using available security telemetry.
-
Identify suspicious behaviours that may not have generated an alert.
-
Record hunting methodology, evidence and outcomes.
-
Help convert successful hunts into improved detections, playbooks or monitoring processes.
Incident response
-
Support the investigation of active security incidents.
-
Assist with evidence collection, scoping and timeline development.
-
Help identify affected users, systems and data.
-
Support containment, eradication and recovery activities.
-
Work effectively during time-sensitive incidents where information may be incomplete or uncertain.
-
Participate in the DART on-call rota once appropriately trained and assessed.
Client communication
-
Provide concise and accurate updates to clients.
-
Explain technical findings in language appropriate to the audience.
-
Clearly distinguish confirmed facts, reasonable assessments and outstanding questions.
-
Communicate recommendations that are practical, proportionate and evidence-led.
-
Escalate concerns when an incident may have significant operational or business impact.
Continuous improvement
-
Identify opportunities to improve detections, investigation processes and response playbooks.
-
Contribute to the DART Knowledge Hub and shared investigation guidance.
-
Share useful findings and investigative techniques with the wider team.
-
Participate in case reviews, training sessions and peer review.
-
Help reduce unnecessary alert volume without weakening security coverage.
What we are looking for
You do not need to be an expert in every area. We are looking for someone with strong foundations, practical curiosity and the ability to reason through technical problems.
You should have:
-
A practical understanding of common cyber threats and attack techniques.
-
A basic understanding of Windows systems and Microsoft 365 environments.
-
Familiarity with endpoint, identity, email or cloud security concepts.
-
The ability to interpret technical evidence and form a reasoned conclusion.
-
Clear written communication skills.
-
The ability to manage several tasks without losing attention to detail.
-
A willingness to ask questions, accept feedback and continue developing.
-
A calm and methodical approach when working with incomplete information.
-
An interest in security investigations, threat hunting and incident response.
Useful additional experience
Experience in any of the following would be beneficial, but is not essential:
-
Microsoft Defender XDR, Microsoft Defender for Endpoint or Microsoft Sentinel.
-
Endpoint detection and response platforms.
-
Security information and event management platforms.
-
Investigating suspicious PowerShell, command-line or scripting activity.
-
Microsoft Entra ID and identity-based attacks.
-
Email security and business email compromise investigations.
-
Malware triage or basic forensic analysis.
-
Kusto Query Language or another security query language.
-
MITRE ATT&CK.
-
TryHackMe, Hack The Box, home laboratories, capture-the-flag exercises or other practical security projects.
-
Previous work in a SOC, service desk, infrastructure, networking or technical support role.
Relevant certifications may support an application, but practical capability, reasoning and communication are more important than holding a particular qualification.
Working pattern and on-call
DART operates a rotating shift pattern to provide extended coverage for clients:
-
Two weeks working 08:00–16:30
-
Two weeks working 12:30–21:00
-
The shift pattern then repeats
Following successful onboarding and assessment, you will also participate in the DART on-call rota, which provides cover outside the normal shift window.
An additional stipend is paid for each period spent on call. Where an incident requires you to carry out work during an on-call period, overtime is paid in addition to the on-call stipend.
On-call responders must remain contactable, able to access the required systems and capable of responding within the applicable response time.
How you will work
DART operates through collaborative squads rather than a traditional L1, L2 and L3 structure. Responders work alongside experienced technical colleagues, with access to peer review, mentoring and structured development.
You will be expected to:
-
Take responsibility for the quality of your work.
-
Be open about uncertainty and avoid making unsupported conclusions.
-
Keep investigation records current and understandable.
-
Communicate early when you need assistance.
-
Support other members of your squad.
-
Treat client information with care and discretion.
-
Follow documented response authorities and escalation procedures.
-
Contribute positively to a remote and collaborative working environment.
The role is primarily remote, but you will be expected to attend JUMPSEC’s London headquarters and client sites occasionally where required for team activities, client engagements, exercises or incident response work.
Development
The role includes structured development across:
-
Security investigation methodology.
-
Endpoint and identity investigations.
-
Threat hunting.
-
Incident response.
-
Client communication.
-
Detection improvement.
-
Cloud and Microsoft security technologies.
Progression will be based on demonstrated capability, investigation quality, operational ownership and contribution to the team.
Role requirements
-
Eligibility to work in the United Kingdom.
-
Ability to work the rotating shift pattern.
-
Ability to participate in the paid on-call rota following training and approval.
-
Ability to travel occasionally to JUMPSEC’s London headquarters and client sites.
-
Willingness to undergo appropriate background screening.
How to apply
If you are interested in applying for this role, please provide a short cover letter outlining your experience and why you would be a good fit for JUMPSEC to [email protected]. Please reference JSDARTResp in the subject line.
For more information on who we are and what we do, please visit www.jumpsec.com.
Whilst we do our utmost to reply to each candidate, we are sometimes inundated with applications, and this can lead to slight delays in replies. If you do not hear back from us within 20 working days, please consider yourself unsuccessful and we thank you for your time and effort in applying for this role.
At JUMPSEC, we believe that great people drive our success, and we embrace diversity and inclusion as integral parts of our company culture. We welcome individuals from all backgrounds, ethnicities, cultures, and genders. Diverse perspectives and ideas contribute to the uniqueness of our brand and enable the creative problem-solving that our clients value. Join us on our mission to create a safer digital world!
