{"id":1774512,"url":"https://alion.io/job/cyberone-incident-response-analyst","title":"Incident Response Analyst","company":{"id":695879,"name":"CyberOne","domain":"cyberone.security","url":"https://alion.io/company/cyber-one","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Teamtailor","truth_index":{"grade":"A","score":85,"open_postings":12,"ghost_share":0,"stale_share":0.583,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-09T06:01:00Z"}},"role":"Security","role_family":"Security","seniority":null,"employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":71000,"max_usd":155000,"period":"year","method":"role_country_seniority_unknown","sample_n":108},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Copilot","optional":false},{"name":"Cyber Kill Chain","optional":false},{"name":"Linux","optional":false},{"name":"SIEM","optional":false},{"name":"Windows","optional":false},{"name":"Azure","optional":true},{"name":"EnCase","optional":true},{"name":"FTK","optional":true},{"name":"Microsoft Defender","optional":true},{"name":"Microsoft Defender for Cloud","optional":true},{"name":"Microsoft Sentinel","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true},{"name":"Velociraptor","optional":true},{"name":"Volatility","optional":true},{"name":"Wireshark","optional":true}],"status":"live","first_seen_at":"2026-10-02T09:39:16Z","employer_posted_date":"2026-10-02","last_verified_at":"2026-10-09T21:42:06Z","board_verified":true,"closed_at":null,"days_open":7,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":7},"description":"“I am hugely excited about my future and the future of CyberOne. I have enjoyed my time here immensely and have learnt a huge amount in a short space of time, year-for-year I've learnt more here than I have at Microsoft and PwC.” - CyberOne Consultant\nAbout CyberOne\nCyberOne is a pure-play Microsoft security partner dedicated to helping enterprises realise the full value of the Microsoft Security portfolio-across Defender XDR, Sentinel, Entra, Purview, Intune, Copilot for Security and more. We combine deep technical expertise with outcome-driven services that accelerate secure cloud adoption, modernise threat protection and simplify compliance.\nJob Title:Incident Response Analyst\nLocation: Hybrid; 1 day per month reporting in London office\nEmployment Type: Full-time\nProfile Summary\nCyberOne is seeking an experienced Incident Response Analyst to join our growing Cyber Security team. This is an exciting opportunity to play a critical role in protecting organisations from cyber threats by leading investigations, conducting digital forensics, performing threat hunting activities, and driving continuous improvements in incident detection and response.\nAs an Incident Response Analyst, you will work across a diverse range of client environments, collaborating with technical teams, stakeholders, and security specialists to investigate and contain cyber security incidents swiftly and effectively. You will help organisations strengthen their cyber resilience while contributing to the evolution of CyberOne's incident response capabilities and services.\nDuties and Responsibilities\nIncident Detection, Triage and Response\nMonitor and analyse alerts from SIEM, EDR/XDR, identity, email, cloud, network, and other security platforms to identify suspicious or malicious activity.\n\nTriage alerts, validate incidents, assess severity and business impact, and escalate in accordance with defined processes and service levels.\n\nLead or support investigations into cyber threats including phishing, malware, account compromise, unauthorised access, data loss, and network-based attacks.\n\nCoordinate containment, eradication, and recovery activities with internal teams and client stakeholders.\n\nMaintain comprehensive incident records, timelines, evidence, actions, and decision logs throughout the incident lifecycle.\n\nProduce timely incident reports, management updates, and post-incident summaries.\n\nDigital Forensics and Investigation\nCollect, preserve, and analyse endpoint, server, identity, network, email, and cloud artefacts in accordance with forensic best practices.\n\nPerform host and network analysis using security logs, packet captures, forensic images, and telemetry data.\n\nIdentify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs), and map findings to the MITRE ATT&CK framework.\n\nSupport sensitive investigations while maintaining evidence integrity and chain-of-custody requirements.\n\nEngage internal and external forensic specialists when appropriate.\n\nThreat Hunting and Detection Improvement\nDevelop and execute proactive, intelligence-led threat hunting activities.\n\nCreate, tune, and optimise detection rules, correlation logic, security monitoring content, and custom indicators.\n\nIdentify and address detection gaps uncovered during incident investigations.\n\nSupport purple-team exercises, penetration testing activities, and security control validation exercises.\n\nTransform findings into actionable improvements to CyberOne's detection and response capabilities.\n\nClient-Focused Incident Response\nAct as a trusted security advisor during cyber incidents, providing clear technical guidance and regular stakeholder updates.\n\nLead client communications throughout the incident response lifecycle.\n\nFacilitate incident review meetings and present findings, recommendations, and lessons learned.\n\nWork collaboratively with Security Operations, Professional Services, and Customer Success teams to deliver exceptional client outcomes.\n\nIncident Response Capability and Governance\nDevelop, maintain, and improve incident response plans, playbooks, runbooks, and standard operating procedures.\n\nConduct post-incident reviews and root cause analyses, ensuring lessons learned are captured and tracked through to completion.\n\nContribute to service reporting, key risk indicators, trend analysis, and operational metrics.\n\nSupport cyber simulations and tabletop exercises to validate response processes and stakeholder readiness.\n\nStay current with emerging threats, attack techniques, vulnerabilities, and industry best practices.\n\nSkills and Experience\nEssential\nHands-on experience in Cyber Incident Response, Security Operations (SOC), or Cyber Defence environments.\n\nHands-on experience investigating security incidents using SIEM and EDR/XDR platforms.\n\nStrong understanding of the incident response lifecycle, including preparation, detection, analysis, containment, eradication, recovery, and lessons learned.\n\nExperience analysing Windows and Linux systems, authentication events, network traffic, and security logs.\n\nAbility to create clear investigation reports, management updates, and technical documentation.\n\nKnowledge of MITRE ATT&CK, Cyber Kill Chain, and NIST Incident Response frameworks.\n\nUnderstanding of enterprise networking, identity and access management, cloud security, email security, endpoint protection, vulnerability management, and data protection controls.\n\nExcellent analytical, problem-solving, and communication skills.\n\nAbility to work effectively under pressure and manage multiple priorities.\n\nUnderstanding of evidence handling, forensic methodologies, and regulatory considerations relevant to cyber investigations.\n\nDesirable\nExperience working within an MSSP, consultancy, financial services, critical infrastructure, or other highly regulated environment.\n\nExperience with threat intelligence platforms, malware analysis, scripting, or automation using PowerShell, Python, KQL, or similar technologies.\n\nExperience developing threat hunts, response playbooks, detection rules, or security orchestration and automation workflows.\n\nExperience with Microsoft security technologies such as:\nMicrosoft Sentinel\n\nMicrosoft Defender XDR\n\nMicrosoft Defender for Identity\n\nMicrosoft Defender for Cloud\n\nExposure to forensic tools including EnCase, FTK, Velociraptor, Volatility, Wireshark, or equivalent technologies.\n\nExperience investigating incidents across Azure, Microsoft 365, or other cloud platforms.\n\nQualifications\nDegree in Cyber Security, Computer Science, Information Technology, or a related field, or equivalent practical experience.\n\nIndustry certifications are highly desirable, including:\nGCIH\n\nGCIA\n\nGCFA\n\nGNFA\n\nSC-200\n\nCySA+\n\nCISSP\n\nEquivalent cyber security certifications\n\nStrong understanding of recognised security frameworks and standards, including NIST, CIS Controls, and relevant data privacy regulations.\n\nWhy Join Us?\nWork with cutting-edge Azure technologies and drive cloud transformation projects.\n\nBe part of a dynamic team that values innovation, collaboration, and technical excellence.\n\nCompetitive compensation, career growth opportunities, and access to continuous learning and certifications.\n\nOpportunity to work on impactful cloud initiatives across various industries.\n\nWhy CyberOne:\nElite positioning: Microsoft Security Partner, CREST & NCSC-certified\n\nAccess to cutting-edge MXDR platform & proprietary SecOps tools\n\nNo glass ceilings: rapid growth, fast-track leadership opportunities\n\nCulture-first: bold values, open feedback, and relentless innovation\n\nLet’s redefine what it means to be secure. Together.\n#CyberDefenders","description_format":"text","description_chars":7665,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Continuous learning","Growth opportunities"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response","Security Operations","Managed Security"],"lifecycle":[{"event":"open","at":"2026-10-03T16:10:23Z"}],"visa":[],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.626,"p_room":1,"age_days":6,"expected_fill_days":34,"reasons":["conf:0","stale_co","velocity","win:early"],"computed_at":"2026-10-09T06:01:00Z"},"pay":null,"html_url":"https://alion.io/job/cyberone-incident-response-analyst","json_url":"https://alion.io/job/cyberone-incident-response-analyst.json","meta":{"generated_at":"2026-10-10T00:59:00Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1539,"day_limit":5000,"remaining_today":3461,"minute_limit":60,"resets_at":"2026-10-11T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":695879},"rest":"https://alion.io/mcp/rest/get_company?id=695879"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fcyberone-incident-response-analyst"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fcyberone-incident-response-analyst"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fcyberone-incident-response-analyst"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/cyberone-incident-response-analyst\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fcyberone-incident-response-analyst"}]}