Why This Role Stands Out
This hybrid role offers a fantastic opportunity to hone your incident response and threat hunting skills within a globally recognized security firm, working on impactful technical challenges. You'll thrive here if you have 3-5 years of cybersecurity experience and a passion for proactively defending against cyber threats, contributing to a 24/7 expert team. Apply to join a dynamic environment where your expertise will be highly valued and continuously developed.
Quick Overview
Job Description
The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands-on technical role focused on identifying, analysing, and responding to cyber threats across the client’s environment, working closely with Security Engineering and broader security stakeholders.
This role will be a part of a 24/7 team and cover one of two shifts: Sunday-Thursday 9:00 am-5:00 pm GMT or Tuesday-Saturday 9:00 am-5:00 pm GMT
Responsibilities
- Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems.
- Support incident response activities including analysis, containment, remediation, and documentation.
- Execute established incident response playbooks and contribute to their continuous improvement.
- Perform threat hunting activities to identify potential compromises and gaps in detection coverage.
- Leverage threat intelligence to inform investigations and detection tuning.
- Collaborate with Security Engineering to tune detection logic and improve security controls.
- Produce clear, concise incident reports and support root cause analysis and remediation efforts.
- Support on-call rotations and escalation processes as part of a 24/7 detection and response capability.
Qualifications
- 3–5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defence.
- Hands-on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike).
- Practical understanding of incident response methodologies and frameworks such as MITRE ATT&CK and NIST.
- Familiarity with threat hunting, malware analysis, or forensic investigation techniques.
- Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred.
- Strong analytical and problem-solving skills, with the ability to communicate technical findings clearly.
- Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus.
Similar jobs
- SE
Security Escort (DV Clearance)
NewAuto ApplySecuritas
Didcot🇬🇧£21/hrOn-siteYesterday - CL
IAM Analyst
NewAuto ApplyClearbank
London Office - Hybrid🇬🇧HybridYesterdayAzureComplianceEmployee Engagement+5 - FH
HIPAA Security Engineer
Auto ApplyFlo Health
London🇬🇧Hybrid4 weeks agoDockerAWSSOC 2+8Technology - VI
Security Project Supervisor UK (CCTV)
NewAuto ApplyVizzia
London🇬🇧HybridYesterdayComplianceTalent AcquisitionTechnical Support - BL
IT Security & Compliance Lead (Amsterdam, NLD)
NewAuto ApplyB Lab
Amsterdam🇬🇧€51k - €61k/yrHybridYesterdayMFASSOSalesforce+11Technology - BL
IT Security & Compliance Lead (London, UK)
NewAuto ApplyB Lab
Amsterdam🇬🇧£57.1k - £70k/yrHybridYesterdayMFASSOSalesforce+11Technology - BL
IT Security & Compliance Lead (São Paulo, BR)
NewAuto ApplyB Lab
Amsterdam🇬🇧$261.0k/yrHybridYesterdayMFASSOSalesforce+11Technology - WP
Business Security Services Director, WPP Production
NewAuto ApplyWPP
London🇬🇧HybridYesterdayComplianceGDPRRisk ManagementManufacturing - DK

Security Engineer (AppSec / GRC / AI Security)
NewAuto ApplyDavid Kennedy Recruitment
London🇬🇧RemoteYesterdayBashComplianceGenerative AI+5Technology - SE
Security Operations Centre Officer
NewAuto ApplySecuritas
Abingdon🇬🇧£15/hrOn-siteYesterdayTechnology - SE
Relief Security Officer
NewAuto ApplySecuritas
Edinburgh🇬🇧£13 - £15/hrOn-site2 days agoAdministrative - NE
IAM Service Operations Engineer
NewAuto ApplyNetcompany
London🇬🇧Hybrid2 days agoAgileAzureStakeholder ManagementTechnology