OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
23/07/2026
Full time
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
23/07/2026
Full time
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
23/07/2026
Full time
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
23/07/2026
Full time
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
23/07/2026
Full time
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
23/07/2026
Full time
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
Job Summary Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you will investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments. Location UK-based hybrid role with occasional travel to site. Responsibilities Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware and data loss. Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post incident activities while ensuring stakeholders remain informed. Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments. Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes. Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operations Technology (OT) environments, working closely with engineering and technology teams. Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities. Qualifications Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end to end incident response lifecycle. Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact. Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish. Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques. Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non technical audiences while collaborating across multiple teams. A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement. Benefits Generous market salary plus a 15% Employee Energy Allowance. Comprehensive pension plan. Fully funded company healthcare plan. 25 day holiday allowance plus public holidays, with the option to purchase up to 5 extra days. Flexible benefits including tech treats, eco friendly car leases and travel insurance.
14/07/2026
Full time
Job Summary Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you will investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments. Location UK-based hybrid role with occasional travel to site. Responsibilities Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware and data loss. Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post incident activities while ensuring stakeholders remain informed. Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments. Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes. Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operations Technology (OT) environments, working closely with engineering and technology teams. Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities. Qualifications Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end to end incident response lifecycle. Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact. Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish. Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques. Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non technical audiences while collaborating across multiple teams. A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement. Benefits Generous market salary plus a 15% Employee Energy Allowance. Comprehensive pension plan. Fully funded company healthcare plan. 25 day holiday allowance plus public holidays, with the option to purchase up to 5 extra days. Flexible benefits including tech treats, eco friendly car leases and travel insurance.
Cyber Security Incident Response AnalystApplylocations: Windsortime type: Full timeposted on: Posted Todaytime left to apply: End Date: July 25, 2026 (14 days left to apply)job requisition id: R Join us, be part of more. We're so much more than an energy company. We're a family of brands revolutionising how we power the planet. We're energisers. One team of 21,000 colleagues that's energising a greener, fairer future by creating an energy system that doesn't rely on fossil fuels, whilst living our powerful commitment to igniting positive change in our communities. Here, you can find more purpose, more passion, and more potential. That's why working here is . We do energy differently - we do it all. We make it, store it, move it, sell it, and mend it. An opportunity to play your part - Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you'll investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments. Working alongside a team of security experts, you'll play a key role in protecting our business, driving continuous improvement, and helping us stay one step ahead of emerging threats in a fast-paced and ever-evolving cyber landscape. Location : UK-based hybrid role, Occasional travel to site. Day to day Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware, data loss and complex security events. Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post-incident activities while ensuring stakeholders remain informed and aligned. Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments. Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes. Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operational Technology (OT) environments, working closely with engineering and technology teams. Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities, helping Centrica stay one step ahead of emerging cyber threats. What are the must haves Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end-to-end incident response lifecycle. Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact. Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish. Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques. Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non-technical audiences while collaborating across multiple teams. A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement, helping us strengthen our cyber defences and stay ahead of emerging threats. What's in it for you? Enjoy a generous market salary, along with fantastic growth opportunities and a vibrant work environment! Power up your pay with a 15% Employee Energy Allowance, surpassing the government's price cap! Secure your future with our comprehensive pension plan, designed for peace of mind. Elevate your health with our fully-funded company healthcare plan, prioritizing your well-being. Recharge with a generous 25-day holiday allowance, plus public holidays, and even purchase up to 5 extra days for extended relaxation! Experience unparalleled work-life balance with an exceptional selection of flexible benefits, from tech treats and eco-friendly car leases to travel insurance for your adventures! Why should you apply? We're not a perfect place - but we're a people place. Our priority is supporting all of the different realities our people face. Life is about so much more than work. We get it. That's why we've designed our total rewards to give you the flexibility to choose what you need, when you need it, making sure that you and your family are supported not only financially, but physically and emotionally too. Visit the link below to discover why we're a great place to work and what being part of more means for you. you're full of energy, fired up about sustainability, and ready to craft not only a better tomorrow, but a better you, then come and find your purpose in a team where your voice matters, your growth is non-negotiable, and your ambitions are our priority.Help us, help you. We would love for you to share any information about yourself throughout our recruitment process so that we can better understand you and help shape your journey.
14/07/2026
Full time
Cyber Security Incident Response AnalystApplylocations: Windsortime type: Full timeposted on: Posted Todaytime left to apply: End Date: July 25, 2026 (14 days left to apply)job requisition id: R Join us, be part of more. We're so much more than an energy company. We're a family of brands revolutionising how we power the planet. We're energisers. One team of 21,000 colleagues that's energising a greener, fairer future by creating an energy system that doesn't rely on fossil fuels, whilst living our powerful commitment to igniting positive change in our communities. Here, you can find more purpose, more passion, and more potential. That's why working here is . We do energy differently - we do it all. We make it, store it, move it, sell it, and mend it. An opportunity to play your part - Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you'll investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments. Working alongside a team of security experts, you'll play a key role in protecting our business, driving continuous improvement, and helping us stay one step ahead of emerging threats in a fast-paced and ever-evolving cyber landscape. Location : UK-based hybrid role, Occasional travel to site. Day to day Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware, data loss and complex security events. Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post-incident activities while ensuring stakeholders remain informed and aligned. Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments. Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes. Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operational Technology (OT) environments, working closely with engineering and technology teams. Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities, helping Centrica stay one step ahead of emerging cyber threats. What are the must haves Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end-to-end incident response lifecycle. Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact. Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish. Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques. Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non-technical audiences while collaborating across multiple teams. A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement, helping us strengthen our cyber defences and stay ahead of emerging threats. What's in it for you? Enjoy a generous market salary, along with fantastic growth opportunities and a vibrant work environment! Power up your pay with a 15% Employee Energy Allowance, surpassing the government's price cap! Secure your future with our comprehensive pension plan, designed for peace of mind. Elevate your health with our fully-funded company healthcare plan, prioritizing your well-being. Recharge with a generous 25-day holiday allowance, plus public holidays, and even purchase up to 5 extra days for extended relaxation! Experience unparalleled work-life balance with an exceptional selection of flexible benefits, from tech treats and eco-friendly car leases to travel insurance for your adventures! Why should you apply? We're not a perfect place - but we're a people place. Our priority is supporting all of the different realities our people face. Life is about so much more than work. We get it. That's why we've designed our total rewards to give you the flexibility to choose what you need, when you need it, making sure that you and your family are supported not only financially, but physically and emotionally too. Visit the link below to discover why we're a great place to work and what being part of more means for you. you're full of energy, fired up about sustainability, and ready to craft not only a better tomorrow, but a better you, then come and find your purpose in a team where your voice matters, your growth is non-negotiable, and your ambitions are our priority.Help us, help you. We would love for you to share any information about yourself throughout our recruitment process so that we can better understand you and help shape your journey.