Cyber Security Analyst - Incident Response
London - Hybrid | Up to £75,000 + benefits
A global specialist insurer is expanding its internal cyber defence capability & is seeking an experienced analyst to strengthen its Security Operations Centre.
This role is focused on incident response first & foremost. It suits someone who has spent 3-5 years in a SOC environment & is now taking ownership of investigations, leading response activity, & managing incidents end-to-end. Threat intelligence exposure is welcome but not essential.
The role
- Lead & coordinate responses to live security incidents including malware, phishing, credential compromise, & endpoint breaches
- Perform root cause analysis, containment, & recovery actions across infrastructure & endpoints
- Work closely with Wintel, network, & cloud teams during incident handling
- Improve detection & response processes & contribute to playbook development
- Document incident timelines & support post-incident review activity
- Support broader SOC improvements, including tuning & use case refinement
- No out-of-hours work - 24/7 alerting is handled by a managed service
Experience required
- 3-5 years in a SOC environment, ideally progressing into incident response
- Hands-on involvement in managing & responding to incidents in the last 12 months
- Proven ability to take ownership of investigations & lead response actions
- Experience with SIEM & EDR tooling (vendor agnostic)
- Solid understanding of Windows, Linux, & network security fundamentals
- Familiarity with common attack vectors & adversary techniques (MITRE ATT&CK, NIST)
- Strong communication skills for collaborating with technical teams during incidents
Desirable
- Exposure to SOAR or automation tooling
- PowerShell or Python for scripting or investigation
- GIAC or Microsoft security certifications
- Experience with cloud security monitoring
This is an opportunity to join a respected security function within the London Market, working directly with senior specialists in an environment that prioritises clarity, collaboration, & high-quality incident response.
We are shortlisting immediately. Contact Brushoth at brushoth@pioneer-search.com or apply via the link.