> Markdown version of [/jobs/ext/3525154-senior-csirt-analyst](https://www.wearedevelopers.com/jobs/ext/3525154-senior-csirt-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior CSIRT Analyst - **Company:** Eventsg-research - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Intrusion Detection and Prevention, Python (Programming Language), Red Team (Cyber Security), Security Information and Event Management, Scripting, Cloud Platform System, Data Ingestion, Mitre Att&ck, Purple Team (Cyber Security) - **Published:** October 1, 2026 - **Apply:** https://www.apply4u.co.uk/jobs/senior-csirt-analyst/49530611 ## About the Role detection rules and platform reliabilityMentoring and supporting junior analysts through knowledge sharing and technical guidanceParticipating in the on-call escalation rota for out-of-hours incidentsImproving CSIRT processes, playbooks and threat modelsWho are we looking for?The ideal candidate will have the following skills and experience:Significant experience in cyber incident response, detection engineering or SOC and CSIRT operationsStrong cloud security expertise across AWS and Azure, including hands-on incident investigationProficiency with SIEM platforms and log analysisExperience with red and purple team exercises and adversary simulationKnowledge of containerised environments and cloud-native infrastructure securityProgramming or scripting experience, preferably in Python, and exposure to automation platformsStrong understanding of modern attack techniques, threat actors and the MITRE ATT&CK frameworkExperience mentoring or leading within a security operations environmentStrong ## Description environments. You will use cloud-native security tooling and multi-SIEM operations, such as Elastic, Azure, AWS, to strengthen detection and response capabilities. You will also participate in purple team and red team exercises, continuously validating and improving the team's effectiveness against advanced adversaries. As a senior member of the team, you will also mentor junior analysts, contribute to automation initiatives and support the on-call escalation rota for out-of-hours response.Key responsibilities of the role include:Investigating and responding to complex security incidents across cloud, hybrid, and on-premise environmentsProactively hunting for threats and developing detection logic across SIEM and cloud security systemsParticipating in red and purple team exercises to test, validate and enhance detection and response capabilitiesDeveloping and maintaining automation workflows using tools such as Tines and PythonCollaborating with engineering teams to improve log ingestion