> Markdown version of [/jobs/ext/1598511-cyber-security-incident-response-analyst](https://www.wearedevelopers.com/jobs/ext/1598511-cyber-security-incident-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Incident Response Analyst - **Company:** Centrica - **Location:** Windsor, UK - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Data Loss, Digital Forensics, Github, Identity and Access Management, Network Security, Phishing, Security Information and Event Management, Software Repository, Cloud Platform System, Cyber Threat Analysis, Cybercrime, Operational Systems - **Published:** July 12, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=fabd75f2e6cdcff7 ## About the Role * Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end-to-end incident response lifecycle. * Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact. * Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish. * Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques. * Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non-technical audiences while collaborating across multiple teams. * A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement, helping us strengthen our cyber defences and stay ahead of emerging threats. ## Description * Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware, data loss and complex security events. * Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post-incident activities while ensuring stakeholders remain informed and aligned. * Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments. * Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes. * Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operational Technology (OT) environments, working closely with engineering and technology teams. * Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities, helping Centrica stay one step ahead of emerging cyber threats. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [How to Avoid LLM Pitfalls - Mete Atamel and Guillaume Laforge](https://www.wearedevelopers.com/videos/1328-how-to-avoid-llm-pitfalls-mete-atamel-and-guillaume-laforge) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [From Shadow AI to Secure Intelligence: Safe AI Usage in the Enterprise](https://www.wearedevelopers.com/videos/2093-from-shadow-ai-to-secure-intelligence-safe-ai-usage-in-the-enterprise) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)