JobRaahGet matched free

Jobs

Incident Response Analyst

CyberOne · London, United Kingdom · Hybrid

Posted Oct 2, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

“I am hugely excited about my future and the future of CyberOne. I have enjoyed my time here immensely and have learnt a huge amount in a short space of time, year-for-year I've learnt more here than I have at Microsoft and PwC.” - CyberOne Consultant About CyberOne CyberOne is a pure-play Microsoft security partner dedicated to helping enterprises realise the full value of the Microsoft Security portfolio—across Defender XDR, Sentinel, Entra, Purview, Intune, Copilot for Security and more. We combine deep technical expertise with outcome-driven services that accelerate secure cloud adoption, modernise threat protection and simplify compliance. Job Title: Incident Response Analyst Location: Hybrid ; 1 day per month reporting in London office Employment Type: Full-time Profile Summary CyberOne is seeking an experienced Incident Response Analyst to join our growing Cyber Security team. This is an exciting opportunity to play a critical role in protecting organisations from cyber threats by leading investigations, conducting digital forensics, performing threat hunting activities, and driving continuous improvements in incident detection and response. As an Incident Response Analyst, you will work across a diverse range of client environments, collaborating with technical teams, stakeholders, and security specialists to investigate and contain cyber security incidents swiftly and effectively. You will help organisations strengthen their cyber resilience while contributing to the evolution of CyberOne's incident response capabilities and services. Duties and Responsibilities Incident Detection, Triage and Response Monitor and analyse alerts from SIEM, EDR/XDR, identity, email, cloud, network, and other security platforms to identify suspicious or malicious activity. Triage alerts, validate incidents, assess severity and business impact, and escalate in accordance with defined processes and service levels. Lead or support investigations into cyber threats including phishing, malware, account compromise, unauthorised access, data loss, and network-based attacks. Coordinate containment, eradication, and recovery activities with internal teams and client stakeholders. Maintain comprehensive incident records, timelines, evidence, actions, and decision logs throughout the incident lifecycle. Produce timely incident reports, management updates, and post-incident summaries. Digital Forensics and Investigation Collect, preserve, and analyse endpoint, server, identity, network, email, and cloud artefacts in accordance with forensic best practices. Perform host and network analysis using security logs, packet captures, forensic images, and telemetry data. Identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs), and map findings to the MITRE ATT&CK framework. Support sensitive investigations while maintaining evidence integrity and chain-of-custody requirements. Engage internal…