Incident Response Analyst
The Opportunity
A growing cyber security organisation is seeking an experienced Cyber Security Incident Response Analyst to join its technical security team.
This role offers the opportunity to work across a broad range of cyber security engagements, helping organisations identify, investigate and respond to security incidents while also supporting proactive threat detection activities.
The successful candidate will work across diverse environments, investigating suspicious activity, analysing cyber threats, supporting incident management activities and helping customers strengthen their overall security posture.
This position would suit someone with experience in cyber defence, incident response, threat hunting or security operations who is looking to further develop their technical expertise within a highly collaborative environment.
Key Responsibilities
Incident Investigation & Response
- Investigate security incidents across endpoint, network and cloud environments.
- Support organisations throughout incident response engagements, helping to determine scope, impact and remediation requirements.
- Analyse security alerts and suspicious activity to identify potential threats and compromise.
- Assist with containment, recovery and post-incident activities.
- Contribute to the development and maintenance of response procedures, playbooks and operational documentation.
- Support stakeholders throughout security incidents by providing clear updates and technical guidance.
- Assist with the investigation of emerging attack techniques and cyber threats.
Threat Detection & Threat Hunting
- Conduct proactive threat hunting activities to identify malicious activity that may not have been detected through automated controls.
- Analyse threat intelligence and security telemetry to identify indicators of compromise and adversary behaviours.
- Develop and refine hunting methodologies to improve detection capabilities.
- Support the enhancement of security monitoring and detection coverage across customer environments.
Reporting & Client Engagement
- Produce high-quality technical reports and investigation findings.
- Deliver clear and concise updates to both technical and non-technical stakeholders.
- Participate in post-engagement reviews and lessons-learned activities.
- Provide recommendations to improve cyber resilience and security maturity.
Continuous Improvement
- Contribute to the ongoing development of cyber security services and operational processes.
- Support improvements to detection, monitoring and response capabilities.
- Maintain awareness of current cyber threats, attack techniques and industry developments.
- Share knowledge and best practice with colleagues across the wider security function.
Experience & Skills
Essential
- Previous experience working in a cyber security, security operations or incident response focused role.
- Strong understanding of modern cyber threats, attack techniques and defensive security controls.
- Experience investigating security incidents across multiple technology environments.
- Knowledge of endpoint, network and cloud security concepts.
- Strong analytical and problem-solving skills.
- Ability to communicate technical findings clearly to a variety of audiences.
- Experience working within fast-paced operational environments.
- A proactive and inquisitive approach to cyber security investigations.
Desirable
- Experience conducting threat hunting activities.
- Familiarity with security monitoring, endpoint detection and investigation platforms.
- Experience supporting incident response engagements or cyber investigations.
- Relevant cyber security certifications.
- Experience working within a managed service, consultancy or customer-facing environment.
- Knowledge of digital forensics, malware analysis or adversary behaviour analysis.
What's on Offer?
- Remote-first working environment.
- Exposure to a wide variety of cyber security challenges and technologies.
- Ongoing professional development and certification support.
- Opportunity to work alongside experienced cyber security practitioners.
- Clear progression opportunities within a growing technical team.
Additional Information
Successful applicants may be required to participate in an on-call rota to support critical incident response activities outside normal business hours