Cyber Security Incident Response Analyst

  • Centrica plc
  • Windsor, Berkshire
  • 14/07/2026
Full time Information Technology Telecommunications Cyber Security

Job Description

Job Summary

Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you will investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments.

Location

UK-based hybrid role with occasional travel to site.

Responsibilities
  • Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware and data loss.
  • Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post incident activities while ensuring stakeholders remain informed.
  • Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments.
  • Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes.
  • Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operations Technology (OT) environments, working closely with engineering and technology teams.
  • Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities.
Qualifications
  • Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end to end incident response lifecycle.
  • Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact.
  • Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish.
  • Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques.
  • Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non technical audiences while collaborating across multiple teams.
  • A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement.
Benefits
  • Generous market salary plus a 15% Employee Energy Allowance.
  • Comprehensive pension plan.
  • Fully funded company healthcare plan.
  • 25 day holiday allowance plus public holidays, with the option to purchase up to 5 extra days.
  • Flexible benefits including tech treats, eco friendly car leases and travel insurance.