Senior CSIRT Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
Experteer Overview As a Senior CSIRT Analyst, you will strengthen G-Research’s Cyber Security Incident Response Team with expertise in cloud detection across AWS and hybrid environments. You’ll investigate, respond, and proactively hunt threats across cloud, on-prem, and high-performance compute settings, using SIEM and cloud-native tooling. The role includes red/purple team exercises, automation development, and mentoring junior analysts while supporting on-call incidents. You’ll collaborate with engineering to boost log ingestion, detection rules, and platform resilience. This is a hands-on, impact-driven position shaping security capabilities at scale. Pay / Benefits * Investigate and respond to complex security incidents across cloud, hybrid, and on-premise environments * Proactively hunt threats and develop detection logic across SIEM and cloud security systems * Participate in red and purple team exercises to test and enhance detection and response capabilities * Develop and maintain automation workflows using tools such as Tines and Python * Collaborate with engineering teams to improve log ingestion, detection rules and platform reliability * Mentor and support junior analysts through knowledge sharing and technical guidance * Participate in the on-call escalation rota for out-of-hours incidents * Improve CSIRT processes, playbooks and threat models Tasks * Significant experience in cyber incident response, detection engineering or SOC/CSIRT operations * Strong cloud security expertise across AWS and Azure, including hands-on incident investigation * Proficiency with SIEM platforms and log analysis * Experience with red and purple team exercises and adversary simulation * Knowledge of containerised environments and cloud-native infrastructure security * Programming or scripting experience, preferably in Python, and exposure to automation platforms * Strong understanding of modern attack techniques, threat actors and MITRE ATT&CK framework * Experience mentoring or leading within a security operations environment * Strong analytical skills with the ability to investigate complex threats under pressure * Collaborative approach with cross-team working style * Proactive mindset with interest in automation and improving detection and response Key requirements * Highly competitive compensation * Lunch provided by Just Eat for Business * 30 days’ annual leave * 9% company pension contributions * Comprehensive healthcare and life assurance * Cycle-to-work scheme
Requirements
cyber automation workflows using tools such as Tines and Python * Collaborate with engineering teams to improve log ingestion, detection rules and platform reliability * Mentor and support junior analysts through knowledge sharing and technical guidance * Participate in the on-call escalation rota for out-of-hours incidents * Improve CSIRT processes, playbooks and threat models Tasks * Significant experience in cyber incident response, detection engineering or SOC/CSIRT operations * Strong cloud security expertise across AWS and Azure, including hands-on incident investigation * Proficiency with SIEM platforms and log analysis * Experience with red and purple team exercises and adversary simulation * Knowledge of containerised environments and cloud-native infrastructure security * Programming or scripting experience, preferably in Python, and exposure to automation platforms * Strong understanding of modern attack techniques, threat actors and MITRE ATT&CK framework * Experience aaaaaaa of or leading within a security operations environment * Strong analytical skills with the ability to investigate complex threats under pressure * Collaborative approach with cross-team working style * Proactive mindset with interest in automation and improving detection and response Key requirements * Highly competitive compensation * Lunch provided by Just Eat for Business * 30 days’ annual leave * 9% company pension contributions * Comprehensive healthcare and life assurance * Cycle-to-work scheme
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on eu.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Dev Digest 134 - Where pixels sing?
IT Salaries in UK
Dev Digest 121 - AI goes offline