Incident Response Analyst
CyberOne · London, United Kingdom · Hybrid
Posted Oct 2, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
“I am hugely excited about my future and the future of CyberOne. I have enjoyed my time here immensely and have learnt a huge amount in a short space of time, year-for-year I've learnt more here than I have at Microsoft and PwC.” - CyberOne Consultant
About CyberOne
CyberOne is a pure-play Microsoft security partner dedicated to helping enterprises realise the full value of the Microsoft Security portfolio—across Defender XDR, Sentinel, Entra, Purview, Intune, Copilot for Security and more. We combine deep technical expertise with outcome-driven services that accelerate secure cloud adoption, modernise threat protection and simplify compliance.
Job Title: Incident Response Analyst
Location: Hybrid ; 1 day per month reporting in London office
Employment Type: Full-time
Profile Summary
CyberOne is seeking an experienced Incident Response Analyst to join our growing Cyber Security team. This is an exciting opportunity to play a critical role in protecting organisations from cyber threats by leading investigations, conducting digital forensics, performing threat hunting activities, and driving continuous improvements in incident detection and response.
As an Incident Response Analyst, you will work across a diverse range of client environments, collaborating with technical teams, stakeholders, and security specialists to investigate and contain cyber security incidents swiftly and effectively. You will help organisations strengthen their cyber resilience while contributing to the evolution of CyberOne's incident response capabilities and services.
Duties and Responsibilities
Incident Detection, Triage and Response
Monitor and analyse alerts from SIEM, EDR/XDR, identity, email, cloud, network, and other security platforms to identify suspicious or malicious activity.
Triage alerts, validate incidents, assess severity and business impact, and escalate in accordance with defined processes and service levels.
Lead or support investigations into cyber threats including phishing, malware, account compromise, unauthorised access, data loss, and network-based attacks.
Coordinate containment, eradication, and recovery activities with internal teams and client stakeholders.
Maintain comprehensive incident records, timelines, evidence, actions, and decision logs throughout the incident lifecycle.
Produce timely incident reports, management updates, and post-incident summaries.
Digital Forensics and Investigation
Collect, preserve, and analyse endpoint, server, identity, network, email, and cloud artefacts in accordance with forensic best practices.
Perform host and network analysis using security logs, packet captures, forensic images, and telemetry data.
Identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs), and map findings to the MITRE ATT&CK framework.
Support sensitive investigations while maintaining evidence integrity and chain-of-custody requirements.
Engage internal…