Senior CSIRT Analyst

G-Research
London, UK
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Amazon Web Services Automation of Tests Microsoft Azure Cloud Computing Security Cyber Security Computer Programming Intrusion Detection and Prevention Python (Programming Language) Log Analysis Automation of Marketing Security Information and Event Management Scripting
+4 more
Cloud Platform System Data Ingestion Mitre Att&ck Purple Team (Cyber Security)

Job description

Experteer Overview As a Senior CSIRT Analyst, you will strengthen G-Research’s Cyber Security Incident Response Team with expertise in cloud detection across AWS and hybrid environments. You’ll investigate, respond, and proactively hunt threats across cloud, on-prem, and high-performance compute settings, using SIEM and cloud-native tooling. The role includes red/purple team exercises, automation development, and mentoring junior analysts while supporting on-call incidents. You’ll collaborate with engineering to boost log ingestion, detection rules, and platform resilience. This is a hands-on, impact-driven position shaping security capabilities at scale. Pay / Benefits * Investigate and respond to complex security incidents across cloud, hybrid, and on-premise environments * Proactively hunt threats and develop detection logic across SIEM and cloud security systems * Participate in red and purple team exercises to test and enhance detection and response capabilities * Develop and maintain automation workflows using tools such as Tines and Python * Collaborate with engineering teams to improve log ingestion, detection rules and platform reliability * Mentor and support junior analysts through knowledge sharing and technical guidance * Participate in the on-call escalation rota for out-of-hours incidents * Improve CSIRT processes, playbooks and threat models Tasks * Significant experience in cyber incident response, detection engineering or SOC/CSIRT operations * Strong cloud security expertise across AWS and Azure, including hands-on incident investigation * Proficiency with SIEM platforms and log analysis * Experience with red and purple team exercises and adversary simulation * Knowledge of containerised environments and cloud-native infrastructure security * Programming or scripting experience, preferably in Python, and exposure to automation platforms * Strong understanding of modern attack techniques, threat actors and MITRE ATT&CK framework * Experience mentoring or leading within a security operations environment * Strong analytical skills with the ability to investigate complex threats under pressure * Collaborative approach with cross-team working style * Proactive mindset with interest in automation and improving detection and response Key requirements * Highly competitive compensation * Lunch provided by Just Eat for Business * 30 days’ annual leave * 9% company pension contributions * Comprehensive healthcare and life assurance * Cycle-to-work scheme

Requirements

cyber automation workflows using tools such as Tines and Python * Collaborate with engineering teams to improve log ingestion, detection rules and platform reliability * Mentor and support junior analysts through knowledge sharing and technical guidance * Participate in the on-call escalation rota for out-of-hours incidents * Improve CSIRT processes, playbooks and threat models Tasks * Significant experience in cyber incident response, detection engineering or SOC/CSIRT operations * Strong cloud security expertise across AWS and Azure, including hands-on incident investigation * Proficiency with SIEM platforms and log analysis * Experience with red and purple team exercises and adversary simulation * Knowledge of containerised environments and cloud-native infrastructure security * Programming or scripting experience, preferably in Python, and exposure to automation platforms * Strong understanding of modern attack techniques, threat actors and MITRE ATT&CK framework * Experience aaaaaaa of or leading within a security operations environment * Strong analytical skills with the ability to investigate complex threats under pressure * Collaborative approach with cross-team working style * Proactive mindset with interest in automation and improving detection and response Key requirements * Highly competitive compensation * Lunch provided by Just Eat for Business * 30 days’ annual leave * 9% company pension contributions * Comprehensive healthcare and life assurance * Cycle-to-work scheme

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on eu.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · WWC Europe 2026

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

5:01 min

Bridging the gap between software development and security

Vandana Verma · LIVE

3:48 min

Leveraging multi-agent systems for autonomous software testing

Ondřej Gróf Ondřej Gróf · WWC Europe 2026

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all