Senior Cyber Incident Response Analyst

Amach · Ankara, Ankara, Turkey · Data

Posted 2026-07-27

Apply for this role →

The Senior Cyber Incident Response Analyst is a senior technical specialist within the Cyber Defence function, responsible for leading hands-on incident response activities and managing the SOC. You will drive effective services including 24x7 monitoring, rapid incident response, and ongoing improvement of detection and response processes through automation, testing and strong operational governance.

Reporting into the Head of Cyber Defence, this role will work cross‑functionally with teams across Cyber Defence, Cyber Engineering and IT, supporting ongoing maturity of cyber monitoring coverage and incident management playbooks for timely detection and response processes.

Required Experience:

Essential Qualifications / Experience

10+ years cybersecurity and/or IT experience, with at least 6 years in SOC or Incident Response roles

Proven experience in direct involvement in cyber incidents, fulfilling investigation, digital forensics, event triaging and response responsibilities

Experience working with outsourced SOC security services

Relevant Cyber qualifications e.g. CISM, GIAC, OSCP, CEH, or similar

Essential Competencies / Skills

Strong crisis management, communication and cross‑functional collaboration skills.

Proactive and independent thinker, willing to challenge ways of working

Hands‑on proficiency with Cyber Defence technologies (e.g., SIEM, Threat Intelligence, SOAR, EDR platforms such as CrowdStrike, ZeroFox, Splunk or equivalent).

Demonstrated ability to develop and mature incident management capabilities, improving operational processes and playbooks, and development of detection use cases.

Ability to translate threat intelligence, control testing and incident learnings into measurable improvements in detections, controls and response automation.

Key responsibilities & duties include:

Support the execution of the Cyber Incident Management strategy defined by the Head of Cyber Defence

Act as the technical escalation for the customer's SOC

Senior member of the Incident Response team during cyber events, co-ordinating with the outsourced SOC and internal Cyber and IT teams on response, forensics and investigation activities and remediations.

Participate in analysis exercises with the SOC, identifying recurring root causes to incidents and champion remediations and improvements

Partner with Vulnerability Management and Offensive Security teams, to continually optimise monitoring and cyber use case colorations.

Lead improvements to monitor, detect and respond to threats in real time, leveraging SIEM, EDR, SOAR and automation to deliver at scale.

Ensure Cyber Defence evidence, reporting and assurance are fit for purpose (incident records integrity, audit trails, lessons learned and continuous improvement actions).

Part of on-call rota, as point of escalation in the event of a major cyber event

Partner with the outsourced SOC and Threat Management services, with daily, weekly and monthly operational cadences, to ensure full visibility of the current incident landscape, and holding them accountable for service KPIs and SLAs

Lead the development and maintenance of incident response playbooks

Support the Head of Cyber Defence to deliver regular incident testing to enhance readiness with technology and operational teams

Desirable skills

Familiarity with MITRE ATT&CK framework and modern attacker techniques.

Experience managing IR KPIs such as MTTD/MTTR, detection coverage and first-time remediation

Scripting and developing skills for integrating cyber tools, and automating playbook responses.

Familiarity with regulatory and incident reporting obligations and evidence requirements (e.g., NIS2, GDPR, aviation regulations such as IAA/EASA Part‑IS).

Apply for this role →

← Back to all jobs