> Markdown version of [/jobs/ext/1636537-embedded-cyber-detection-and-response-analyst](https://www.wearedevelopers.com/jobs/ext/1636537-embedded-cyber-detection-and-response-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Embedded Cyber Detection and Response Analyst - **Company:** Control Risks Group Holdings Ltd - **Location:** London, UK - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Data Analysis, Microsoft Azure, Log Analysis, Security Information and Event Management, Cloud Platform System, Mitre Att&ck, Malware, Cybercrime, Dart, Cyber Warfare, Splunk - **Published:** July 15, 2026 - **Apply:** https://apply.workable.com/api/v1/accounts/control-risks-6/jobs/F7B7BD6054 ## About the Role * 3-5 years of experience in cybersecurity, with a focus on incident response, SOC operations, or cyber defense. * Hands-on experience with SIEM, EDR/XDR, and log analysis tools (e.g., Splunk, Sentinel, CrowdStrike). * Practical understanding of incident response methodologies and frameworks such as MITRE ATT&CK and NIST. * Familiarity with threat hunting, malware analysis, or forensic investigation techniques. * Exposure to cloud environments (AWS, Azure, or GCP) and modern enterprise architectures is preferred. * Strong analytical and problem-solving skills, with the ability to communicate technical findings clearly. * Relevant certifications (e.g., Security+, GCIH, GCIA, or equivalent) are a plus. ## Description The Cyber Detection and Response Analyst supports day-to-day detection, investigation, and response activities as part of a Cyber Detection and Response Team (DART). This is a hands-on technical role focused on identifying, analysing, and responding to cyber threats across the client's environment, working closely with Security Engineering and broader security stakeholders. This role will be a part of a 24/7 team and cover one of two shifts: Sunday-Thursday 9:00 am-5:00 pm GMT or Tuesday-Saturday 9:00 am-5:00 pm GMT, * Monitor, triage, and investigate security alerts and events across endpoint, network, cloud, and identity systems. * Support incident response activities including analysis, containment, remediation, and documentation. * Execute established incident response playbooks and contribute to their continuous improvement. * Perform threat hunting activities to identify potential compromises and gaps in detection coverage. * Leverage threat intelligence to inform investigations and detection tuning. * Collaborate with Security Engineering to tune detection logic and improve security controls. * Produce clear, concise incident reports and support root cause analysis and remediation efforts. * Support on-call rotations and escalation processes as part of a 24/7 detection and response capability. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Dart - a language believed dead, experiences a new bloom](https://www.wearedevelopers.com/videos/442-dart-a-language-believed-dead-experiences-a-new-bloom) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Full Spectrum File Uploads](https://www.wearedevelopers.com/videos/870-full-spectrum-file-uploads) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk)