Embedded Cyber Detection and Response Analyst

Control Risks

Greater London

On-site

GBP 45,000 - 70,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Control Risks in London is seeking a Cyber Detection and Response Analyst to join the 24/7 DART, focusing on hands-on detection, investigation, and response across endpoints, networks, and cloud.

The role requires 3–5 years in cybersecurity, proficiency with SIEM/EDR/XDR, and strong analytical skills to produce incident reports and support root cause analysis.

Qualifications

  • 3–5 years of cybersecurity experience with a focus on incident response, SOC operations, or cyber defense.
  • Hands‑on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike).
  • Familiarity with MITRE ATT&CK and NIST incident response methodologies.
  • Knowledge of threat hunting, malware analysis, or forensic techniques.
  • Exposure to cloud environments (AWS, Azure, GCP) and modern enterprise architectures is preferred.

Responsibilities

  • Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems.
  • Support incident response activities including analysis, containment, remediation, and documentation.
  • Execute established incident response playbooks and contribute to their continuous improvement.
  • Perform threat hunting to identify compromises and gaps in detection coverage.
  • Leverage threat intelligence to inform investigations and detection tuning.
  • Collaborate with Security Engineering to tune detection logic and improve security controls.
  • Produce clear incident reports and support root cause analysis and remediation efforts.
  • Support on‑call rotations and escalation processes as part of a 24/7 capability.

Skills

Incident response
SOC operations
Threat hunting
Cloud security
Analytical thinking
Communication of findings

Tools

Splunk
Microsoft Sentinel
CrowdStrike Falcon

Job description

The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands‑on technical role focused on identifying, analysing, and responding to cyber threats across the client’s environment, working closely with Security Engineering and broader security stakeholders.

This role will be a part of a 24/7 team and cover one of two shifts: Sunday-Thursday 9:00 am-5:00 pm GMT or Tuesday-Saturday 9:00 am-5:00 pm GMT
Responsibilities
  • Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems.
  • Support incident response activities including analysis, containment, remediation, and documentation.
  • Execute established incident response playbooks and contribute to their continuous improvement.
  • Perform threat hunting activities to identify potential compromises and gaps in detection coverage.
  • Leverage threat intelligence to inform investigations and detection tuning.
  • Collaborate with Security Engineering to tune detection logic and improve security controls.
  • Produce clear, concise incident reports and support root cause analysis and remediation efforts.
  • Support on‑call rotations and escalation processes as part of a 24/7 detection and response capability.
Qualifications
  • 3–5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defense.
  • Hands‑on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike).
  • Practical understanding of incident response methodologies and frameworks such as MITRE ATT&CK and NIST.
  • Familiarity with threat hunting, malware analysis, or forensic investigation techniques.
  • Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred.
  • Strong analytical and problem‑solving skills, with the ability to communicate technical findings clearly.
  • Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Detection and Response Engineer
Senior Detection and Response Engineer

Jobtailor • Cambridge

On-site
GBP 65,000 - 95,000
Cybersecurity Incident Response Lead
Cybersecurity Incident Response Lead

Creative Artists Agency • Greater London

On-site
GBP 90,000 - 120,000
Cyber security Operation Manager
Cyber security Operation Manager

Agratas – A Tata Enterprise • Bridgwater

On-site
GBP 55,000 - 75,000
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response
Senior Manager – Associate Director Technical Incident Responder, Cyber Incident Response

Cyber UK • Greater London, Manchester

Hybrid
GBP 60,000 - 80,000
SOC / Cyber Threat Detection Analyst – SANS/GIAC
SOC / Cyber Threat Detection Analyst – SANS/GIAC

Cyber UK • Wokingham

On-site
GBP 45,000 - 70,000
Excellent benefits and training
Cyber Security Operations Specialist
Cyber Security Operations Specialist

Tank Recruitment • Bath

On-site
GBP 55,000 - 85,000
Operations Advisor, Cyber Defense Operations
Operations Advisor, Cyber Defense Operations

Cyderes • United Kingdom

Hybrid
GBP 70,000 - 90,000
Medical Insurance
Life Insurance
Retirement Match Program
+7
Incident Response Consultant - Systems Integrator
Incident Response Consultant - Systems Integrator

Hamilton Barnes Associates Limited • England

Hybrid
GBP 40,000 - 50,000
Mentorship
Exposure to advanced tools
Flexible working arrangement
Cyber Security SOC Analyst (L1)
Cyber Security SOC Analyst (L1)

Wavenet • Batley

On-site
GBP 28,000 - 36,000
Annual Leave 25 days
Private medical coverage
Wellbeing program
+1
Cyber Security Consultant
Cyber Security Consultant

Franklin Fitch • Greater London

Hybrid
GBP 55,000 - 65,000
Bonus