{"id":5961041,"shortcode":"F7B7BD6054","title":"Embedded Cyber Detection and Response Analyst","remote":false,"location":{"country":"United Kingdom","countryCode":"GB","city":"London","region":"England"},"locations":[{"country":"United Kingdom","countryCode":"GB","city":"London","region":"England","hidden":false}],"state":"published","isInternal":false,"code":"","published":"2026-07-15T00:00:00.000Z","type":"contract","language":"en","department":["Intelligence & Analysis","Intelligence & Investigations"],"accountUid":"01f327ed-a237-41ce-9eef-7af4dc031d9a","approvalStatus":"approved","workplace":"hybrid","description":"<p>The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands-on technical role focused on identifying, analysing, and responding to cyber threats across the client’s environment, working closely with Security Engineering and broader security stakeholders.</p><p><strong>This role will be a part of a 24/7 team and cover one of two shifts: Sunday-Thursday 9:00 am-5:00 pm GMT or Tuesday-Saturday 9:00 am-5:00 pm GMT</strong></p>","requirements":"<p><strong>Responsibilities </strong></p><p></p><ul><li>Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems.</li><li>Support incident response activities including analysis, containment, remediation, and documentation.</li><li>Execute established incident response playbooks and contribute to their continuous improvement.</li><li>Perform threat hunting activities to identify potential compromises and gaps in detection coverage.</li><li>Leverage threat intelligence to inform investigations and detection tuning.</li><li>Collaborate with Security Engineering to tune detection logic and improve security controls.</li><li>Produce clear, concise incident reports and support root cause analysis and remediation efforts.</li><li>Support on-call rotations and escalation processes as part of a 24/7 detection and response capability.</li></ul><p></p><p>Qualifications</p><p></p><ul><li>3–5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defense.</li><li>Hands-on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike).</li><li>Practical understanding of incident response methodologies and frameworks such as MITRE ATT&amp;CK and NIST.</li><li>Familiarity with threat hunting, malware analysis, or forensic investigation techniques.</li><li>Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred.</li><li>Strong analytical and problem-solving skills, with the ability to communicate technical findings clearly.</li><li>Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus.</li></ul>","benefits":""}