it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Career Advice
  • Contact us
  • Employers
    • Register as Employer
    • Pricing Plans
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

12 jobs found

Email me jobs like this
Refine Search
Current Search
cyber security analyst csirt incident response
Hybrid CSIRT Engineer: Incident Response & Detection
OVO Group Bristol, Gloucestershire
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
23/07/2026
Full time
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
CSIRT Engineer (Cyber Security Incident Response Team)
OVO Group Bristol, Gloucestershire
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
23/07/2026
Full time
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
CSIRT Engineer (Cyber Security Incident Response Team)
OVO Group
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
23/07/2026
Full time
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
Hybrid CSIRT Engineer: Incident Response & Detection
OVO Group
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
23/07/2026
Full time
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
Hybrid CSIRT Engineer: Incident Response & Detection
OVO Group
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
23/07/2026
Full time
OVO Group in the United Kingdom is seeking a hands on CSIRT Engineer to join the Cyber Defence Operations team. You'll manage the full lifecycle of security alerts, from detection to containment and recovery, supporting Plan Zero by protecting our digital estate. Based hub based hybrid working, you'll work at Bristol or other hubs and attend events; you'll lead junior analysts and develop monitoring logic (SIEM rules), red team activities, and threat hunting to keep our environment secure.
CSIRT Engineer (Cyber Security Incident Response Team)
OVO Group
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
23/07/2026
Full time
CSIRT Engineer (Cyber Security Incident Response Team) Role OVO-View Team: Cyber Defence Operations Location: Hub Based - Hybrid for all Salary banding: £56,000 and £75,000 Experience: Mid-level Working pattern: Full-Time Reporting to: Delivery & Growth Lead Sponsorship: Unfortunately we are unable to offer sponsorship for this role. Top 3 qualities for this role: Adaptability, Passionate, Integrity Where you'll work: Depending on the needs of your business area, we expect hub based people to be in the office at least once a week, and to go to OVO Connection events in-person. You'll be assigned to the closest one of our three hub offices, Bristol, Glasgow, or London; unless your role requires field-based work. Each hub has accessible spaces to park your laptop, is designed to inspire people, help them connect and bring big ideas to life. Everyone belongs at OVO: At OVO, we are on a mission to solve one of humanity's biggest challenges, the climate crisis. And we know it takes all of us to change the world. That's why we need diverse people from all abilities, gender identities, ethnicities, ages, sexual orientations, life experiences and backgrounds to join us. Teamworking for the planet: Everything we do here spins around Plan Zero. So, naturally, the team you'll be joining plays a gigantic role in making that happen. Here's how: The Cyber Defence Operations team is responsible for ensuring the resilience and security of all OVO systems, data, and critical infrastructure. Our vision is to maintain a continuously hardened and observable digital estate, allowing OVO to innovate quickly and securely. Our impact directly supports Plan Zero by protecting the technology that underpins all climate crisis solving initiatives, guaranteeing that our mission to drive a clean energy transition is never disrupted. This role in a nutshell: The purpose of this role is to act as a hands on cybersecurity specialist within the Cyber Defence Operations team, expertly managing the full lifecycle of security threats, from proactive defence hardening and detection engineering to rapid incident response. This position directly relates to Plan Zero by ensuring the stability and trustworthiness of the technology platform that enables millions of customers to transition to net zero carbon living. Your key outcomes will be: Front line of the Security Operations Centre at OVO, handling day to day incidents, with a view of leading several junior analysts in the upcoming months Execute the incident response process for critical security alerts, ensuring swift containment, eradication, and post incident analysis Develop and implement security monitoring and detection logic (e.g., SIEM rules) to reduce the time from compromise to detection (MTTD) Conduct and support proactive security exercises, including penetration tests and red teaming activities, to continuously assess and harden OVO's environment Systems: Google Chronicle, Crowdstrike, Jira, Sublime, Tines You'll be a successful CSIRT Engineer at OVO if you You have a proven track record of navigating high pressure environments and managing the full lifecycle of security alerts Are an Incident Response specialist You effectively lead the transition from detection to containment and recovery with speed and technical precision Apply an offensive mindset You leverage your experience in Penetration Testing or Red Teaming to anticipate adversary tactics and proactively harden defences Invest in technical leadership You scale your impact by mentoring junior and senior analysts, directly contributing to the team's collective growth Drive operational efficiency You collaborate across the team to refine detection logic, automate workflows, and optimise ticket response to maintain a lean, effective operation Let's talk about what's in it for you: We'll pay you between £56,000 and £75,000, depending on your specific skills and experience. We keep our pay ranges broad on purpose to give us, and you, flexibility to match your experience to our zero carbon mission. You'll be eligible for an on target bonus of 15%. We have one OVO bonus plan that focuses on the collective performance of our people to deliver our Plan Zero goal. We also offer plenty of green benefits and progressive policies to help you feel like you belong at OVO and there's flex pay. We'll give you 9% Flex Pay on top of your salary - 4% of this is auto enrolled into your pension, and the remaining 5% is yours to do what you like with. You can use this to buy from our extensive range of flexible benefits, including our green benefits which we've put at the heart of our offering, add to your pension or even take it as cash. For starters, you'll get 34 days of holiday (including bank holidays). For your health: With benefits like a healthcare cash plan or private medical insurance depending on your career level, critical illness cover, life assurance, health assessments, and more. For your wellbeing: With gym membership, travel insurance, workplace ISA, will writing services, dental insurance, and more. For your lifestyle: With extra holiday buying, discount dining, home & tech loans, and supporting your favourite charities with give as you earn donations. For your home: Get up to £400 towards any OVO Energy plan, plus great discounts on solar, smart thermostats and EV chargers. For your commute: Nab a great deal on ultra low emission car leasing, plus our cycle to work scheme and public transport season ticket loans. Want to hear about our full range of flexible benefits and progressive people policies? Our People Team can tell you everything you need to know. For your Belonging: To find better ways to support our people, we need to listen to each other's experiences and find ways to build a truly inclusive and diverse workplace. As part of this, we have 8 Belonging Networks at OVO. Led by our people, for our people - so when you join OVO, you can play a part - big or small - with any of the Networks. It's up to you. Oh, and one last thing We'd be thrilled if you tick off all our boxes, yet we also believe it's just as important we tick off all of yours. And if you think you have most of what we're looking for but not every single thing, go ahead and hit apply. We'd still love to hear from you! If you have any additional requirements, there's a space to let us know on the application form; we want to make the process as easy and comfortable for you as possible.
Hybrid UK Cyber Security Incident Response Analyst
Centrica plc
Centrica plc is seeking a Cyber Security Incident Response Analyst to join the CSIRT. You will lead investigations across cloud, identity, networks and endpoints, coordinating containment and recovery while keeping stakeholders informed. You will perform technical analyses using SIEM/EDR tools, contribute to playbooks, and support forensics to preserve evidence and produce clear, compliant reports for legal and governance teams.
16/07/2026
Full time
Centrica plc is seeking a Cyber Security Incident Response Analyst to join the CSIRT. You will lead investigations across cloud, identity, networks and endpoints, coordinating containment and recovery while keeping stakeholders informed. You will perform technical analyses using SIEM/EDR tools, contribute to playbooks, and support forensics to preserve evidence and produce clear, compliant reports for legal and governance teams.
Cyber Security Incident Response Analyst
Centrica plc Windsor, Berkshire
Job Summary Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you will investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments. Location UK-based hybrid role with occasional travel to site. Responsibilities Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware and data loss. Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post incident activities while ensuring stakeholders remain informed. Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments. Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes. Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operations Technology (OT) environments, working closely with engineering and technology teams. Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities. Qualifications Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end to end incident response lifecycle. Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact. Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish. Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques. Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non technical audiences while collaborating across multiple teams. A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement. Benefits Generous market salary plus a 15% Employee Energy Allowance. Comprehensive pension plan. Fully funded company healthcare plan. 25 day holiday allowance plus public holidays, with the option to purchase up to 5 extra days. Flexible benefits including tech treats, eco friendly car leases and travel insurance.
14/07/2026
Full time
Job Summary Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you will investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments. Location UK-based hybrid role with occasional travel to site. Responsibilities Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware and data loss. Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post incident activities while ensuring stakeholders remain informed. Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments. Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes. Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operations Technology (OT) environments, working closely with engineering and technology teams. Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities. Qualifications Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end to end incident response lifecycle. Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact. Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish. Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques. Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non technical audiences while collaborating across multiple teams. A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement. Benefits Generous market salary plus a 15% Employee Energy Allowance. Comprehensive pension plan. Fully funded company healthcare plan. 25 day holiday allowance plus public holidays, with the option to purchase up to 5 extra days. Flexible benefits including tech treats, eco friendly car leases and travel insurance.
Cyber Security Incident Response Analyst
Centrica plc
Cyber Security Incident Response AnalystApplylocations: Windsortime type: Full timeposted on: Posted Todaytime left to apply: End Date: July 25, 2026 (14 days left to apply)job requisition id: R Join us, be part of more. We're so much more than an energy company. We're a family of brands revolutionising how we power the planet. We're energisers. One team of 21,000 colleagues that's energising a greener, fairer future by creating an energy system that doesn't rely on fossil fuels, whilst living our powerful commitment to igniting positive change in our communities. Here, you can find more purpose, more passion, and more potential. That's why working here is . We do energy differently - we do it all. We make it, store it, move it, sell it, and mend it. An opportunity to play your part - Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you'll investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments. Working alongside a team of security experts, you'll play a key role in protecting our business, driving continuous improvement, and helping us stay one step ahead of emerging threats in a fast-paced and ever-evolving cyber landscape. Location : UK-based hybrid role, Occasional travel to site. Day to day Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware, data loss and complex security events. Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post-incident activities while ensuring stakeholders remain informed and aligned. Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments. Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes. Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operational Technology (OT) environments, working closely with engineering and technology teams. Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities, helping Centrica stay one step ahead of emerging cyber threats. What are the must haves Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end-to-end incident response lifecycle. Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact. Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish. Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques. Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non-technical audiences while collaborating across multiple teams. A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement, helping us strengthen our cyber defences and stay ahead of emerging threats. What's in it for you? Enjoy a generous market salary, along with fantastic growth opportunities and a vibrant work environment! Power up your pay with a 15% Employee Energy Allowance, surpassing the government's price cap! Secure your future with our comprehensive pension plan, designed for peace of mind. Elevate your health with our fully-funded company healthcare plan, prioritizing your well-being. Recharge with a generous 25-day holiday allowance, plus public holidays, and even purchase up to 5 extra days for extended relaxation! Experience unparalleled work-life balance with an exceptional selection of flexible benefits, from tech treats and eco-friendly car leases to travel insurance for your adventures! Why should you apply? We're not a perfect place - but we're a people place. Our priority is supporting all of the different realities our people face. Life is about so much more than work. We get it. That's why we've designed our total rewards to give you the flexibility to choose what you need, when you need it, making sure that you and your family are supported not only financially, but physically and emotionally too. Visit the link below to discover why we're a great place to work and what being part of more means for you. you're full of energy, fired up about sustainability, and ready to craft not only a better tomorrow, but a better you, then come and find your purpose in a team where your voice matters, your growth is non-negotiable, and your ambitions are our priority.Help us, help you. We would love for you to share any information about yourself throughout our recruitment process so that we can better understand you and help shape your journey.
14/07/2026
Full time
Cyber Security Incident Response AnalystApplylocations: Windsortime type: Full timeposted on: Posted Todaytime left to apply: End Date: July 25, 2026 (14 days left to apply)job requisition id: R Join us, be part of more. We're so much more than an energy company. We're a family of brands revolutionising how we power the planet. We're energisers. One team of 21,000 colleagues that's energising a greener, fairer future by creating an energy system that doesn't rely on fossil fuels, whilst living our powerful commitment to igniting positive change in our communities. Here, you can find more purpose, more passion, and more potential. That's why working here is . We do energy differently - we do it all. We make it, store it, move it, sell it, and mend it. An opportunity to play your part - Ready to be on the frontline of cyber defence? At Centrica, we're looking for a talented Cyber Security Incident Response Analyst to join our Cyber Security Incident Response Team (CSIRT). In this role, you'll investigate and respond to cyber security incidents across a diverse technology landscape, from cloud platforms and identity services to networks, endpoints and modern engineering environments. Working alongside a team of security experts, you'll play a key role in protecting our business, driving continuous improvement, and helping us stay one step ahead of emerging threats in a fast-paced and ever-evolving cyber landscape. Location : UK-based hybrid role, Occasional travel to site. Day to day Lead and support cyber security incident investigations across Centrica, analysing and responding to threats ranging from phishing and credential compromise to ransomware, data loss and complex security events. Manage incidents throughout the full response lifecycle, coordinating containment, eradication, recovery and post-incident activities while ensuring stakeholders remain informed and aligned. Conduct technical investigations using SIEM, EDR, cloud, identity, email and network security tools to determine scope, impact and root cause across enterprise and cloud environments. Support forensic investigations and evidence handling activities, ensuring robust documentation, evidence preservation and clear reporting for technical, legal and governance purposes. Investigate threats across modern technology platforms, including AWS, Azure, SaaS applications, code repositories, CI/CD pipelines and Operational Technology (OT) environments, working closely with engineering and technology teams. Drive continuous improvement by contributing to incident response playbooks, tabletop exercises, detection enhancements and lessons learned activities, helping Centrica stay one step ahead of emerging cyber threats. What are the must haves Proven experience in Cyber Security Operations, Incident Response, Threat Hunting, Digital Forensics or Cloud Security, with a strong understanding of the end-to-end incident response lifecycle. Strong analytical and investigative skills, with the ability to correlate logs and security data from multiple sources using SIEM, EDR and identity platforms to quickly identify threats and assess impact. Knowledge of forensic principles, evidence handling and defensible investigation practices, ensuring incidents are documented clearly and accurately from start to finish. Good understanding of modern technology environments, including cloud platforms, SaaS applications, identity services, GitHub and code repositories, alongside awareness of evolving cyber threats and attacker techniques. Excellent communication and stakeholder management skills, able to translate technical findings into clear, actionable updates for both technical and non-technical audiences while collaborating across multiple teams. A naturally curious, calm and resilient approach, with sound judgement, strong integrity and a passion for continuous improvement, helping us strengthen our cyber defences and stay ahead of emerging threats. What's in it for you? Enjoy a generous market salary, along with fantastic growth opportunities and a vibrant work environment! Power up your pay with a 15% Employee Energy Allowance, surpassing the government's price cap! Secure your future with our comprehensive pension plan, designed for peace of mind. Elevate your health with our fully-funded company healthcare plan, prioritizing your well-being. Recharge with a generous 25-day holiday allowance, plus public holidays, and even purchase up to 5 extra days for extended relaxation! Experience unparalleled work-life balance with an exceptional selection of flexible benefits, from tech treats and eco-friendly car leases to travel insurance for your adventures! Why should you apply? We're not a perfect place - but we're a people place. Our priority is supporting all of the different realities our people face. Life is about so much more than work. We get it. That's why we've designed our total rewards to give you the flexibility to choose what you need, when you need it, making sure that you and your family are supported not only financially, but physically and emotionally too. Visit the link below to discover why we're a great place to work and what being part of more means for you. you're full of energy, fired up about sustainability, and ready to craft not only a better tomorrow, but a better you, then come and find your purpose in a team where your voice matters, your growth is non-negotiable, and your ambitions are our priority.Help us, help you. We would love for you to share any information about yourself throughout our recruitment process so that we can better understand you and help shape your journey.
MI5
Cyber Security Analyst
MI5 Cheltenham, Gloucestershire
Salary £37,892, including a £2,758 concessionary payment. After 6 to 13 months, you may be eligible for a non pensionable skills payment of £7,247 or £15,757, subject to assessment and reviewed every three years. Flexible working We support flexible working arrangements, such as part time and compressed hours, as well as flexible start and finish times. Because of the role's responsibilities, most work is carried out on site. Opportunities for homeworking may be available but will depend on operational requirements and cannot be guaranteed. About us At GCHQ, we unlock the complex world of data and communications to keep the UK and its citizens safe, both in the real world and online. Working closely with our British Intelligence partners, MI5 and MI6, we protect the UK from threats including serious organised crime, terrorism, and cyber attacks. A role in GCHQ offers varied and fascinating work in a supportive and encouraging environment that puts the emphasis on teamwork. The role As a Cyber Security Analyst within GCHQ's Cyber Security Incident Response Team (CSIRT), you focus on protecting critical systems from a wide range of cyber threats, including malware, insider threats, denial of service attacks, and phishing activity. Your work plays a key role in safeguarding GCHQ's networks and data in a high stakes, security focused environment. Each day starts with a review of alerts and overnight activity, prioritising incidents based on severity and potential impact. Key findings are shared in the daily CSIRT meeting, where the team aligns on ongoing investigations and sets priorities. Attention then turns to analysing high priority alerts, working through logs, network traffic, and endpoint data using tools such as Splunk. Working closely with colleagues across IT and security teams, you'll gather information and mitigate emerging threats. Alongside your core investigative work, responsibilities include monitoring security alarms, creating new detection content, and using threat intelligence to strengthen defences. The role also involves building automations to improve Security Operations Centre (SOC) efficiency, responding to security breaches, and providing specialist support in digital forensics, including assistance with HR casework. Most work sits within team delivery objectives, with scope to take on individual projects, if you want to explore a particular area further. About you You're a problem solver with a natural curiosity about how systems work, how they can be protected, and a genuine enthusiasm for developing your skills. You can demonstrate experience in at least one core cyber security discipline, such as malware analysis, intrusion detection, security monitoring, or incident response, ideally gained within a Security Operations Centre (SOC) environment. A solid understanding of Windows and Linux internals is expected. Broader IT experience is advantageous, including exposure to cloud technologies like AWS or Azure, alongside a motivation to continue developing your technical expertise. Training and development When you join GCHQ, you'll receive an organisational induction along with support from a buddy to help you settle in. Development in this role is a mix of on the job learning and formal training. Skills are developed through experience, working alongside colleagues on real incidents and supported by a range of internal and external training opportunities. As a Cyber Security Analyst, there is access to a mix of internal and external training opportunities, including the chance to work towards security certifications such as Certified Information Systems Security Professional (CISSP) and the Offensive Security Certified Professional (OSCP). There are no overseas travel requirements for this role; however, there may be occasional opportunities to attend conferences both within the UK and internationally. Rewards and benefits You'll receive a starting salary of £37,892 plus other benefits including: 25 days' annual leave, rising to 30 days after 5 years' service, and an additional 10.5 days of public and privilege holidays opportunities to be recognised through our employee performance scheme an interest free season ticket loan a cycle to work scheme facilities such as a gym, restaurant, and on site coffee bars; availability varies by location paid parental and adoption leave Equal opportunities At GCHQ, diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio economic backgrounds. Find out more about our culture, working environment and diversity on our website. We're Disability Confident GCHQ is proud to have achieved Leader status within the Department for Work and Pensions' Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader, we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. This is known as the Offer of an Interview. To secure an interview for this role, candidates must meet the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation Able to demonstrate experience of working as a Cyber Security/Security Operations Centre Analyst Able to demonstrate experience working in at least one of the following fields: malware analysis, intrusion detection, monitoring & incident response There is a wide range of extra support available throughout the recruitment process to enable you to do your best. Please see our website for information on reasonable adjustments we can offer. What to expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order: An initial online application form including pre screening questions to ensure you meet our eligibility criteria Online Situational Judgement Test (SJT) in which you rate the appropriateness of responses to a series of short scenarios Application form, looking at your motivation for the role and the organisation Online test, examining your responses to different situations typical to the role Assessment Centre, including situational role plays, tasking exercise and interview If successful, you will receive a conditional offer of employment Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 to 9 months to process, including vetting, so we advise you to continue any current employment until you have received your final job offer. Before you apply To work at GCHQ, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here. This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here. Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs, and you'll need to declare your previous drug usage at the relevant stage. Before you apply, we recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first or surname or date of birth. This is good practice and will help you to manage your application with us more securely. The role is based in Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in person appointments during the recruitment and vetting process. Full details will be provided with your interview or assessment invitation. Reimbursement is discretionary and will only be made in line with the Candidate Expenses Policy, as amended from time to time. Candidates must book their own travel, using the most economical option, and provide original hard copy receipts for reimbursement. Please note, you should only launch your application from within the UK. If you are based overseas, you should wait until you visit the UK to launch an application. Applying from outside the UK will impact on our ability to progress your application. You should not discuss your application, other than with your partner or a close family member. . click apply for full job details
05/07/2026
Full time
Salary £37,892, including a £2,758 concessionary payment. After 6 to 13 months, you may be eligible for a non pensionable skills payment of £7,247 or £15,757, subject to assessment and reviewed every three years. Flexible working We support flexible working arrangements, such as part time and compressed hours, as well as flexible start and finish times. Because of the role's responsibilities, most work is carried out on site. Opportunities for homeworking may be available but will depend on operational requirements and cannot be guaranteed. About us At GCHQ, we unlock the complex world of data and communications to keep the UK and its citizens safe, both in the real world and online. Working closely with our British Intelligence partners, MI5 and MI6, we protect the UK from threats including serious organised crime, terrorism, and cyber attacks. A role in GCHQ offers varied and fascinating work in a supportive and encouraging environment that puts the emphasis on teamwork. The role As a Cyber Security Analyst within GCHQ's Cyber Security Incident Response Team (CSIRT), you focus on protecting critical systems from a wide range of cyber threats, including malware, insider threats, denial of service attacks, and phishing activity. Your work plays a key role in safeguarding GCHQ's networks and data in a high stakes, security focused environment. Each day starts with a review of alerts and overnight activity, prioritising incidents based on severity and potential impact. Key findings are shared in the daily CSIRT meeting, where the team aligns on ongoing investigations and sets priorities. Attention then turns to analysing high priority alerts, working through logs, network traffic, and endpoint data using tools such as Splunk. Working closely with colleagues across IT and security teams, you'll gather information and mitigate emerging threats. Alongside your core investigative work, responsibilities include monitoring security alarms, creating new detection content, and using threat intelligence to strengthen defences. The role also involves building automations to improve Security Operations Centre (SOC) efficiency, responding to security breaches, and providing specialist support in digital forensics, including assistance with HR casework. Most work sits within team delivery objectives, with scope to take on individual projects, if you want to explore a particular area further. About you You're a problem solver with a natural curiosity about how systems work, how they can be protected, and a genuine enthusiasm for developing your skills. You can demonstrate experience in at least one core cyber security discipline, such as malware analysis, intrusion detection, security monitoring, or incident response, ideally gained within a Security Operations Centre (SOC) environment. A solid understanding of Windows and Linux internals is expected. Broader IT experience is advantageous, including exposure to cloud technologies like AWS or Azure, alongside a motivation to continue developing your technical expertise. Training and development When you join GCHQ, you'll receive an organisational induction along with support from a buddy to help you settle in. Development in this role is a mix of on the job learning and formal training. Skills are developed through experience, working alongside colleagues on real incidents and supported by a range of internal and external training opportunities. As a Cyber Security Analyst, there is access to a mix of internal and external training opportunities, including the chance to work towards security certifications such as Certified Information Systems Security Professional (CISSP) and the Offensive Security Certified Professional (OSCP). There are no overseas travel requirements for this role; however, there may be occasional opportunities to attend conferences both within the UK and internationally. Rewards and benefits You'll receive a starting salary of £37,892 plus other benefits including: 25 days' annual leave, rising to 30 days after 5 years' service, and an additional 10.5 days of public and privilege holidays opportunities to be recognised through our employee performance scheme an interest free season ticket loan a cycle to work scheme facilities such as a gym, restaurant, and on site coffee bars; availability varies by location paid parental and adoption leave Equal opportunities At GCHQ, diversity and inclusion are critical to our mission. To protect the UK, we need a truly diverse workforce that reflects the society we serve. This includes diversity in every sense of the word: those with different backgrounds, ages, ethnicities, gender identities, sexual orientations, ways of thinking and those with disabilities or neurodivergent conditions. We therefore welcome and encourage applications from everyone, including those from groups that are under represented in our workforce such as women, those from an ethnic minority background, people with disabilities and those from low socio economic backgrounds. Find out more about our culture, working environment and diversity on our website. We're Disability Confident GCHQ is proud to have achieved Leader status within the Department for Work and Pensions' Disability Confident scheme. This is aimed at encouraging employers to think differently about disability and take action to improve how they recruit, retain and develop disabled people. As a Disability Confident Leader, we aim to ensure that a fair and proportionate number of disabled applicants who best meet the essential minimum criteria for this position, will be offered an interview, if it is practical for us to do so. This is known as the Offer of an Interview. To secure an interview for this role, candidates must meet the minimum criteria, which will be assessed at the CV sift stage: You'll be required to reach the minimum pass mark for the online Situational Judgement Test (SJT), which assesses criteria important for all roles in our organisation Able to demonstrate experience of working as a Cyber Security/Security Operations Centre Analyst Able to demonstrate experience working in at least one of the following fields: malware analysis, intrusion detection, monitoring & incident response There is a wide range of extra support available throughout the recruitment process to enable you to do your best. Please see our website for information on reasonable adjustments we can offer. What to expect Our recruitment process is fair, transparent, and based on merit. Here is a brief overview of each stage, in order: An initial online application form including pre screening questions to ensure you meet our eligibility criteria Online Situational Judgement Test (SJT) in which you rate the appropriateness of responses to a series of short scenarios Application form, looking at your motivation for the role and the organisation Online test, examining your responses to different situations typical to the role Assessment Centre, including situational role plays, tasking exercise and interview If successful, you will receive a conditional offer of employment Please note, you must successfully pass each stage of the process to progress to the next. Your application may take around 6 to 9 months to process, including vetting, so we advise you to continue any current employment until you have received your final job offer. Before you apply To work at GCHQ, you need to be a British citizen or hold dual British nationality. You can read our full eligibility criteria here. This role requires the highest security clearance, known as Developed Vetting (DV). It's something everyone in the UK Intelligence Community undertakes. You can find out more about the vetting process here. Please note we have a strict drugs policy, so once you start your application, you can't take any recreational drugs, and you'll need to declare your previous drug usage at the relevant stage. Before you apply, we recommend setting up a separate email address for your contact with us, to ensure your personal and application correspondence remain separate. Try to avoid having identifying features in your email address, such as your first or surname or date of birth. This is good practice and will help you to manage your application with us more securely. The role is based in Cheltenham or Manchester, so you'll need to live within a commutable distance. Please consider any financial implications and practicalities before submitting an application, as we do not offer relocation costs. We offer reasonable reimbursement of travel costs for candidates attending in person appointments during the recruitment and vetting process. Full details will be provided with your interview or assessment invitation. Reimbursement is discretionary and will only be made in line with the Candidate Expenses Policy, as amended from time to time. Candidates must book their own travel, using the most economical option, and provide original hard copy receipts for reimbursement. Please note, you should only launch your application from within the UK. If you are based overseas, you should wait until you visit the UK to launch an application. Applying from outside the UK will impact on our ability to progress your application. You should not discuss your application, other than with your partner or a close family member. . click apply for full job details
Senior CSIRT Analyst: Threat Hunter & Incident Response
Alastair LLP
Alastair LLP, located in Greater London, seeks a skilled individual for a cyber security position tackling complex security incidents. The ideal candidate will possess significant experience in cyber incident response and cloud security expertise across AWS and Azure. The role includes responsibilities such as mentoring junior analysts, developing automation workflows, and participating in threat detection. Benefits include competitive compensation, annual leave, and comprehensive healthcare.
01/07/2026
Full time
Alastair LLP, located in Greater London, seeks a skilled individual for a cyber security position tackling complex security incidents. The ideal candidate will possess significant experience in cyber incident response and cloud security expertise across AWS and Azure. The role includes responsibilities such as mentoring junior analysts, developing automation workflows, and participating in threat detection. Benefits include competitive compensation, annual leave, and comprehensive healthcare.
Morson Human Resources Limited
Senior SOC Incident Response Lead Threat Hunting & IR
Morson Human Resources Limited
Morson Human Resources Limited is looking for an Incident Response (CSIRT) / SOC Level 3 Analyst based in Crawley. This 6-month contract role focuses on investigating and responding to high-severity cyber security incidents, and enhancing response playbooks and SOC procedures. The ideal candidate will have strong SOC and cyber defense expertise, a proactive mindset, and experience managing incidents. Onsite work will be required for 2-3 days a week.
01/07/2026
Full time
Morson Human Resources Limited is looking for an Incident Response (CSIRT) / SOC Level 3 Analyst based in Crawley. This 6-month contract role focuses on investigating and responding to high-severity cyber security incidents, and enhancing response playbooks and SOC procedures. The ideal candidate will have strong SOC and cyber defense expertise, a proactive mindset, and experience managing incidents. Onsite work will be required for 2-3 days a week.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board