Senior Cyber Incident Response Analyst
The Senior Cyber Incident Response Analyst is a senior technical specialist within the Cyber Defence function, responsible for leading hands-on incident response activities and managing the SOC. You will drive effective services including 24x7 monitoring, rapid incident response, and ongoing improvement of detection and response processes through automation, testing and strong operational governance.
Reporting into the Head of Cyber Defence, this role will work cross‑functionally with teams across Cyber Defence, Cyber Engineering and IT, supporting ongoing maturity of cyber monitoring coverage and incident management playbooks for timely detection and response processes.
Required Experience:
Essential Qualifications / Experience
10+ years cybersecurity and/or IT experience, with at least 6 years in SOC or Incident Response roles
Proven experience in direct involvement in cyber incidents, fulfilling investigation, digital forensics, event triaging and response responsibilities
Experience working with outsourced SOC security services
Relevant Cyber qualifications e.g. CISM, GIAC, OSCP, CEH, or similar
Essential Competencies / Skills
Strong crisis management, communication and cross‑functional collaboration skills.
Proactive and independent thinker, willing to challenge ways of working
Hands‑on proficiency with Cyber Defence technologies (e.g., SIEM, Threat Intelligence, SOAR, EDR platforms such as CrowdStrike, ZeroFox, Splunk or equivalent).
Demonstrated ability to develop and mature incident management capabilities, improving operational processes and playbooks, and development of detection use cases.
Ability to translate threat intelligence, control testing and incident learnings into measurable improvements in detections, controls and response automation.
Key responsibilities & duties include:
Support the execution of the Cyber Incident Management strategy defined by the Head of Cyber Defence
Act as the technical escalation for the customer's SOC
Senior member of the Incident Response team during cyber events, co-ordinating with the outsourced SOC and internal Cyber and IT teams on response, forensics and investigation activities and remediations.
Participate in analysis exercises with the SOC, identifying recurring root causes to incidents and champion remediations and improvements
Partner with Vulnerability Management and Offensive Security teams, to continually optimise monitoring and cyber use case colorations.
Lead improvements to monitor, detect and respond to threats in real time, leveraging SIEM, EDR, SOAR and automation to deliver at scale.
Ensure Cyber Defence evidence, reporting and assurance are fit for purpose (incident records integrity, audit trails, lessons learned and continuous improvement actions).
Part of on-call rota, as point of escalation in the event of a major cyber event
Partner with the outsourced SOC and Threat Management services, with daily, weekly and monthly operational cadences, to ensure full visibility of the current incident landscape, and holding them accountable for service KPIs and SLAs
Lead the development and maintenance of incident response playbooks
Support the Head of Cyber Defence to deliver regular incident testing to enhance readiness with technology and operational teams
Desirable skills
Familiarity with MITRE ATT&CK framework and modern attacker techniques.
Experience managing IR KPIs such as MTTD/MTTR, detection coverage and first-time remediation
Scripting and developing skills for integrating cyber tools, and automating playbook responses.
Familiarity with regulatory and incident reporting obligations and evidence requirements (e.g., NIS2, GDPR, aviation regulations such as IAA/EASA Part‑IS).