Job Summary
Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you will investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments.
Location
UK-based hybrid role with occasional travel to site.
Responsibilities
- Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware and data loss.
- Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post incident activities while ensuring stakeholders remain informed.
- Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments.
- Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes.
- Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operations Technology (OT) environments, working closely with engineering and technology teams.
- Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities.
Qualifications
- Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end to end incident response lifecycle.
- Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact.
- Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish.
- Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques.
- Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non technical audiences while collaborating across multiple teams.
- A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement.
Benefits
- Generous market salary plus a 15% Employee Energy Allowance.
- Comprehensive pension plan.
- Fully funded company healthcare plan.
- 25 day holiday allowance plus public holidays, with the option to purchase up to 5 extra days.
- Flexible benefits including tech treats, eco friendly car leases and travel insurance.