Incident Response Analyst
“I am hugely excited about my future and the future of CyberOne. I have enjoyed my time here immensely and have learnt a huge amount in a short space of time, year-for-year I've learnt more here than I have at Microsoft and PwC.” - CyberOne Consultant
About CyberOne
CyberOne is a pure-play Microsoft security partner dedicated to helping enterprises realise the full value of the Microsoft Security portfolio—across Defender XDR, Sentinel, Entra, Purview, Intune, Copilot for Security and more. We combine deep technical expertise with outcome-driven services that accelerate secure cloud adoption, modernise threat protection and simplify compliance.
Job Title: Incident Response Analyst
Location: Hybrid; 1 day per month reporting in London office
Employment Type: Full-time
Profile Summary
CyberOne is seeking an experienced Incident Response Analyst to join our growing Cyber Security team. This is an exciting opportunity to play a critical role in protecting organisations from cyber threats by leading investigations, conducting digital forensics, performing threat hunting activities, and driving continuous improvements in incident detection and response.
As an Incident Response Analyst, you will work across a diverse range of client environments, collaborating with technical teams, stakeholders, and security specialists to investigate and contain cyber security incidents swiftly and effectively. You will help organisations strengthen their cyber resilience while contributing to the evolution of CyberOne's incident response capabilities and services.
Duties and Responsibilities
Incident Detection, Triage and Response
Monitor and analyse alerts from SIEM, EDR/XDR, identity, email, cloud, network, and other security platforms to identify suspicious or malicious activity.
Triage alerts, validate incidents, assess severity and business impact, and escalate in accordance with defined processes and service levels.
Lead or support investigations into cyber threats including phishing, malware, account compromise, unauthorised access, data loss, and network-based attacks.
Coordinate containment, eradication, and recovery activities with internal teams and client stakeholders.
Maintain comprehensive incident records, timelines, evidence, actions, and decision logs throughout the incident lifecycle.
Produce timely incident reports, management updates, and post-incident summaries.
Digital Forensics and Investigation
Collect, preserve, and analyse endpoint, server, identity, network, email, and cloud artefacts in accordance with forensic best practices.
Perform host and network analysis using security logs, packet captures, forensic images, and telemetry data.
Identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs), and map findings to the MITRE ATT&CK framework.
Support sensitive investigations while maintaining evidence integrity and chain-of-custody requirements.
Engage internal and external forensic specialists when appropriate.
Threat Hunting and Detection Improvement
Develop and execute proactive, intelligence-led threat hunting activities.
Create, tune, and optimise detection rules, correlation logic, security monitoring content, and custom indicators.
Identify and address detection gaps uncovered during incident investigations.
Support purple-team exercises, penetration testing activities, and security control validation exercises.
Transform findings into actionable improvements to CyberOne's detection and response capabilities.
Client-Focused Incident Response
Act as a trusted security advisor during cyber incidents, providing clear technical guidance and regular stakeholder updates.
Lead client communications throughout the incident response lifecycle.
Facilitate incident review meetings and present findings, recommendations, and lessons learned.
Work collaboratively with Security Operations, Professional Services, and Customer Success teams to deliver exceptional client outcomes.
Incident Response Capability and Governance
Develop, maintain, and improve incident response plans, playbooks, runbooks, and standard operating procedures.
Conduct post-incident reviews and root cause analyses, ensuring lessons learned are captured and tracked through to completion.
Contribute to service reporting, key risk indicators, trend analysis, and operational metrics.
Support cyber simulations and tabletop exercises to validate response processes and stakeholder readiness.
Stay current with emerging threats, attack techniques, vulnerabilities, and industry best practices.
Skills and Experience
Essential
Hands-on experience in Cyber Incident Response, Security Operations (SOC), or Cyber Defence environments.
Hands-on experience investigating security incidents using SIEM and EDR/XDR platforms.
Strong understanding of the incident response lifecycle, including preparation, detection, analysis, containment, eradication, recovery, and lessons learned.
Experience analysing Windows and Linux systems, authentication events, network traffic, and security logs.
Ability to create clear investigation reports, management updates, and technical documentation.
Knowledge of MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response frameworks.
Understanding of enterprise networking, identity and access management, cloud security, email security, endpoint protection, vulnerability management, and data protection controls.
Excellent analytical, problem-solving, and communication skills.
Ability to work effectively under pressure and manage multiple priorities.
Understanding of evidence handling, forensic methodologies, and regulatory considerations relevant to cyber investigations.
Desirable
Experience working within an MSSP, consultancy, financial services, critical infrastructure, or other highly regulated environment.
Experience with threat intelligence platforms, malware analysis, scripting, or automation using PowerShell, Python, KQL, or similar technologies.
Experience developing threat hunts, response playbooks, detection rules, or security orchestration and automation workflows.
Experience with Microsoft security technologies such as:
Microsoft Sentinel
Microsoft Defender XDR
Microsoft Defender for Identity
Microsoft Defender for Cloud
Exposure to forensic tools including EnCase, FTK, Velociraptor, Volatility, Wireshark, or equivalent technologies.
Experience investigating incidents across Azure, Microsoft 365, or other cloud platforms.
Qualifications
Degree in Cyber Security, Computer Science, Information Technology, or a related field, or equivalent practical experience.
Industry certifications are highly desirable, including:
GCIH
GCIA
GCFA
GNFA
SC-200
CySA+
CISSP
Equivalent cyber security certifications
Strong understanding of recognised security frameworks and standards, including NIST, CIS Controls, and relevant data privacy regulations.
Why Join Us?
Work with cutting-edge Azure technologies and drive cloud transformation projects.
Be part of a dynamic team that values innovation, collaboration, and technical excellence.
Competitive compensation, career growth opportunities, and access to continuous learning and certifications.
Opportunity to work on impactful cloud initiatives across various industries.
Why CyberOne:
Elite positioning: Microsoft Security Partner, CREST & NCSC-certified
Access to cutting-edge MXDR platform & proprietary SecOps tools
No glass ceilings: rapid growth, fast-track leadership opportunities
Culture-first: bold values, open feedback, and relentless innovation
Let’s redefine what it means to be secure. Together.
#CyberDefenders
- Location
- London
- Remote status
- Hybrid