Skip to main content
AfterDuty

Security Analyst, Incident Response (GSOC London)

RBC · London, Greater London

Type
Full-time
Posted
10 days ago

Overview

Job Description What is the opportunity? You will be a key member of the RBC Global Security Incident Response team as an experienced Security Analyst. This is a key role within the Global Security Operations Centre (GSOC).

About this role

Job Description

What is the opportunity?

You will be a key member of the RBC Global Security Incident Response team as an experienced Security Analyst. This is a key role within the Global Security Operations Centre (GSOC).

You will be providing technical expertise and leadership support to the proactive and reactive responses to cyber threats targeting RBC's global environment.

You will report to the Senior Manager, Incident Response and work with a team of 4-6 technical specialists. You will act as the focal point of contact for GSOC management with regards to security incidents. You will provide support to local and extended team members with critical incidents impacting RBC users, systems, infrastructure, and resources.

Should you be shortlisted, do please let us know if you have any specific requirements for the interview.

This is a permanent, full-time role and requires 4 days in our London Fenchurch office.

What will you do?

Global accountability to respond to critical security incidents/events providing accurate and timely reporting to Global Cyber Security Leadership.

Provide 7/24/365 support for security incidents impacting mission critical business and IT infrastructure, including supporting global incident management and response, remediation and reporting.

Support and maintain communication with Computer Security Incident Response Team (CSIRT) extended team members ensuring timely communication to all stakeholders regarding incident response activities.

Provide post mortem reporting for leadership detailing security vulnerabilities, technology gaps, shortcomings or miscellaneous security issues.

Responsible for working with threat intelligence, Security Operations Centre and extended teams to ensure global compliance to RBC standards with respect to security incidents and related findings.

Responsible for driving to resolution security incidents in a timely and effective manner.

Work collaboratively with Cybersecurity Command Centre technical analysts, specialists and management to detail and report on the status and resolution of critical incidents.

Execute incident response actions and engage with business/technical stakeholders.

What do you need to succeed?

Must-have

Bachelor’s degree in computer sciences and/or IT related disciplines and Certifications in information security preferred (one or more of the following; CISSP, GCIA, GCIH, GREM, CEH).

Demonstrated experience performing investigation activities for security related events in a complex Incident Management or Security Operations Center environment.

Thorough understanding of Security Information and Incident Management methodologies.

Proven experience in a SOC environment.

Exposure to malware and sandbox analysis.

Robust computer networking & OS knowledge.

Nice-to-have

Experience with SOAR platforms.

Familiarity with threat hunting techniques and scenarios.

Knowledge in detection engineering.

Understanding of current threat landscape and threat actor TTPs.

Experience with scripting languages (PowerShell, python, regex, bash, etc.)

Industry recognized certifications from ISC2, SANS, ISACA, etc.

What is in it for you?

We thrive on the challenge to be our best - progressive thinking to keep growing and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

Help to develop the ethos and environment of a new team.

Leaders who will support your development through coaching and managing opportunities

Have the opportunities to work with the best in the field

Ability to make a difference and lasting impact

Work in a dynamic, collaborative, progressive, and high-performing team

Agency Notice

RBC Group does not accept agency resumés. Please do not forward resumés to our employees, nor any other company location. RBC Group only pay fees to agencies where they have entered into a prior agreement to do so and in any event do not pay fees related to unsolicited resumés. Please contact the Recruitment function for additional details.

Job Skills

Business Perspective, Critical Thinking, Decision Making, Detail-Oriented, Forensic Computing, Group Problem Solving, Information Security Operation Center (ISOC), IT Incident Management, Security Information and Event Management (SIEM), Threat Management

Additional Job Details

Address

10 FENCHURCH AVENUE:LONDON City

London Country

United Kingdom Work hours/week

35 Employment Type

Full time Platform

TECHNOLOGY AND OPERATIONS Job Type

Regular Pay Type

Salaried Posted Date

2026-07-15 Application Deadline

2026-08-12 Note:* Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

Our Employment Opportunities

At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.

Join our Talent Community

Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.

Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com.

RBC is presently inviting candidates to apply for this existing vacancy. Applying to this posting allows you to express your interest in this current career opportunity at RBC. Qualified applicants may be contacted to review their resume in more detail.

About cyber security & digital forensics roles for ex-police

Cyber security, digital forensics and incident-response roles. DMIs, cybercrime investigators and digital forensics officers bring evidential discipline and investigative judgement that DFIR and security teams struggle to hire.

See all cyber security & digital forensics jobs in London

Why this fits a police background — match score 90/100

  • Intelligence & OSINT
  • Incident command & response
  • Investigative casework
  • Working to legislation & regulation
  • Security operations

What cyber security & digital forensics roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Digital forensics analyst£32,000–£45,000
DFIR consultant£45,000–£65,000
Senior forensics / IR specialist£60,000–£80,000
Threat-intelligence specialist£55,000–£80,000
Full cyber security & digital forensics salary guide →

More cyber security & digital forensics jobs for ex-police

  • Cyber Security Consultant

    Searchability · London

    Contract

    £570 a dayEstimated

    Cyber Security Consultant – Preston, Birmingham or London, UK •    Up to £570 per day, Inside IR35, •    Hybrid working with 2 days onsite •    Active SC clearance required •    3-month contract duration ABOUT THE CLIENT: Our client is a well-established technology consultancy delivering critical…

    Posted 4 days ago

  • Information Security Engineer

    Freshfields · London

    Full-time

    Role summary/purpose of job We are seeking a passionate Security Specialist with hands-on experience in working with all aspects of Azure, M365, and preferably Google Cloud Platforms (GCP).

    Posted 4 days ago

  • Cybersecurity Analyst

    Visa · London

    Full-time

    About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid.

    Posted 4 days ago

  • Data Privacy Officer

    Pipedrive · London

    Full-time

    We believe it takes great people to create a great product. That’s why our team lives our company values, and we hire based on them, too. Since 2010, Pipedrive has been on a mission to support sales and marketing teams with easy-to-use, powerful tools that make everyday work faster and…

    Posted 4 days ago