We are looking for an experienced Cyber Incident Response Analyst to join a growing Cyber Defence function. This is a hands-on role for someone with strong experience across Cyber Incident Response, SOC Operations, Digital Forensics and Offensive Security. You will work closely with internal Cyber Security and IT teams, alongside outsourced SOC and specialist security providers, helping to investigate and respond to cyber incidents while continuously improving detection and response capabilities.
What You'll Be Doing
- Lead and support cyber incident triage, investigation and response activities.
- Act as an escalation point for the Security Operations Centre (SOC) and coordinate response activities with internal teams and external security providers.
- Conduct digital forensics and incident investigations across systems, endpoints and other technology environments.
- Improve SOC detection use cases, incident response playbooks and operational processes.
- Work with SIEM, EDR, SOAR and Threat Intelligence platforms to improve monitoring, detection and response capabilities.
- Identify and validate security weaknesses using manual testing techniques and offensive security tools.
- Document security findings, including risk, business impact, technical impact and remediation recommendations.
- Support the development of incident response playbooks, procedures and standard operating processes.
- Help automate and integrate security tools and response processes using scripting and automation.
- Support tabletop exercises, cyber simulations and security control testing.
- Work closely with Cyber Defence, Cyber Engineering and IT teams to implement lessons learned from incidents and improve the overall security posture.
- Stay up to date with emerging cyber threats, vulnerabilities and attacker techniques.
- Participate in an on-call rota for major cyber security incidents.
What We're Looking For
- 8+ years' experience in Cyber Security and/or IT, with at least 4 years in SOC, Incident Response or Offensive Security.
- Strong hands-on experience managing and investigating cyber security incidents.
- Experience with incident triage, digital forensics, investigation and remediation.
- Hands-on experience with SIEM, EDR/XDR, SOAR and Threat Intelligence platforms.
- Experience with technologies such as Splunk, CrowdStrike, ZeroFox or similar security tools.
- Practical experience with offensive security tools including Burp Suite, Nmap and Metasploit.
- Experience using Python, PowerShell, Bash or another scripting/programming language.
- Ability to improve SOC processes, detection use cases and incident response playbooks.
- Strong understanding of the cyber incident lifecycle and the ability to independently manage low-to-medium severity incidents.
- A proactive mindset with the ability to identify opportunities for automation, process improvement and stronger security controls.
Nice to Have
- Experience with the MITRE ATT&CK framework and modern attacker techniques.
- Experience working with outsourced SOC or managed security service providers.
- Experience developing security dashboards and reporting on KPIs, SLAs and security trends.
- Experience automating incident response playbooks and security workflows.
- Experience in threat hunting or detection engineering.
- Experience planning and delivering tabletop exercises and cyber attack simulations.
- Relevant Cyber Security certifications such as GIAC, CISSP, OSCP, CEH or similar.
If you're a hands-on Cyber Security professional who enjoys investigating incidents, improving detection capabilities and strengthening an organisation's overall cyber resilience, we'd like to hear from you.
Must hold Stamp 4, EU or Irish passport - this is a hybrid role 3 days per week