Now hiring

Incident Response Senior Analyst - Dublin (Dublin, L, IE) @ CRH Jobs

Dublin, Leinster, IEOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><span style="font-size:10.0pt"><span style="font-family:Arial, Helvetica, sans-serif"><span id="cke_bm_1317S" style="display:none"> </span><img class="decoded" src="https://rmkcdn.successfactors.com/c53088e5/2b7a0e54-4d2d-4ff0-b700-b.jpg"></span></span></p> <p> </p> <p><span style="font-size:10.0pt"><span style="font-family:Arial, Helvetica, sans-serif"><span style="color:black"><strong>Country:</strong> <span style="font-family:Arial, Helvetica, sans-serif"><span style="color:black"><span style="font-family:Arial, Helvetica, sans-serif"><span style="color:black"><span style="font-family:Arial, Helvetica, sans-serif"><span style="color:black"><span style="font-family:Arial, Helvetica, sans-serif"><span style="color:black"><span style="font-family:Arial, Helvetica, sans-serif"><span style="color:black"><span style="font-family:Arial, Helvetica, sans-serif"><span style="color:black"><span style="font-family:Arial, Helvetica, sans-serif"><span style="color:black">Ireland</span></span></span></span></span></span></span></span></span></span></span></span></span></span> </span></span><br></span><span style="font-size:10.0pt"><span style="font-family:Arial, Helvetica, sans-serif"><span style="color:black"><strong>Req ID:</strong> <span contenteditable="false">525808</span></span></span></span><br><span style="font-size:10.0pt"><span style="font-family:Arial, Helvetica, sans-serif"><strong>Job Type</strong>: <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif">Full Time</span></span></span></span></span></span></span></span></span></span></span></span></span></span></span> </span></span><br><span style="font-size:10.0pt"><span style="font-family:Arial, Helvetica, sans-serif"><strong>Workplace Type</strong>: <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif">Hybrid</span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span><br><span style="font-size:10.0pt"><span style="font-family:Arial, Helvetica, sans-serif"><strong>Seniority Level</strong>: <span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif"><span style="font-family:Arial, Helvetica, sans-serif">Associate</span></span></span></span></span></span></span></span></span></span></span></span></span></span></span> </span></span></p> <p style="text-align:justify"> </p> <p style="text-align:justify"><span style="text-decoration:underline"><strong><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">About CRH</span></strong></span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"> </span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">CRH is the leading provider of building materials critical to modernizing infrastructure. <span>With our team </span>of 83,000 people across 4,000 locations, our unmatched scale, connected portfolio, and deep local relationships make us the partner of choice for transportation, water, and reindustrialization projects, shaping communities for a better tomorrow. CRH (NYSE: CRH) is a member of the S&amp;P 500 Index. For more information, visit <a href="https://www.crh.com">www.crh.com</a>.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"> </span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Without you noticing our products, we are everywhere you live, work, and relax.</span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"> </span><br><span style="font-family:arial, helvetica, sans-serif;font-size:10.0pt">Our project portfolio includes some of the most sustainable and cutting-edge building projects around the world. Think of the asphalt on the Silverstone Grand Prix Circuit, the Paris Metro Rail project, but also the Louis Vuitton Museum in Paris, parts of the Burj Khalifa, and the Kennedy Space Centre.</span></p> <p style="text-align:justify"> </p><p><strong>Role Overview</strong></p> <p>We are seeking an experienced Senior Cybersecurity Incident Response Analyst to act as a key escalation point from the Security Operations Centers (SOC). In this role, you will lead the investigation, containment, and resolution of complex, high-impact security incidents, working closely with incident response leadership and cross-functional teams. You will provide clear, data-driven insights and communications to support timely decision-making.</p> <p> </p> <p>Outside of incident response, you will strengthen security posture through threat hunting and detection engineering, leveraging lessons learned and threat intelligence to enhance SOC capabilities. This is a hands-on role suited to a technically strong professional with sound judgment and a collaborative approach in a global environment.</p> <p> </p> <p>This role operates within a global function and requires flexibility for out-of-hours support. While work-life balance is supported, regular presence in a CRH office is expected, particularly for onboarding, sensitive activities, and team collaboration.</p> <p> </p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif"><strong>Key Responsibilities</strong></span></p> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif"><strong>Incident Response:</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Work with a team of responders, the incident response manager and cybersecurity leadership as needed and collaborate with infrastructure, IT, vulnerability, threat intelligence, and application security teams</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Serve as a point of contact to respond and investigate suspected and confirmed cybersecurity incidents, which may include off-hours or on a scheduled rotation</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Examine incidents that may be related to ransomware, host compromise, account compromise, phishing, anomalous user behavior, third parties and data leakage</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Collect and analyze information from multiple event sources and internal and external sources</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Document and communicate incident details from initial investigation through closure and post-mortem including to validate, document, prioritize, recommend and complete root cause analysis</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Support process improvement of monitoring and response metrics including mean time to respond, key performance indicators (KPIs), and service-level objectives (SLOs) for security events and incidents</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Liaise with security operations to improve monitoring and response workflows</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Perform incident analysis and trend reporting for host, network, identity, and third-party events</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Regularly participate in IR tabletop exercises designed to test, identify gaps, improve skills, enhance communication, and engage with key stakeholders</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Refine and maintain playbooks, policies, procedures, and guidelines to ensure they align with industry best practices</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Remain current with emerging threats and share knowledge with colleagues to improve incident response</span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif"><strong> </strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif"><strong>Threat Hunting:</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Identify misconfigurations, vulnerabilities, missing, or improperly applied security controls</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Conduct research of current and emerging threats facing the business and industry sector to identify associated indicators of compromise, tactics, techniques, and procedures</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Review events to support threat hunting based on anomalies and possible true-positive incidents</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Review reports from tabletops, vulnerability, and penetration testing assessments to proactively identify weaknesses</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Actively hunt for exposures and identify incidents warranting action to disrupt and remediate threats</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Actively participate in threat hunting exercises to hone and strengthen skills across the team</span></li> </ul> <p><span style="font-family:arial, helvetica, sans-serif"><strong> </strong></span></p> <p><span style="font-family:arial, helvetica, sans-serif"><strong>Detection Engineering Activities:</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Build or modify scripts for detection engineering and threat hunting</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Take observables (e.g., IOCs, TTPs, etc.) and use these to create searches or detections for signs of observables on internal systems</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Proactively identify and define the lifetime value of observables / detections</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Test detections to identify and tune out false positives</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Provide detection logic to Security Engineering team for deployment to production</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Support Security Operations and Engineering efforts to refine detection logic as required</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Be familiar with prompting, AI agents, copilots and MCP solutions to analyze events across data sources</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Perform other duties as assigned</span></li> </ul> <p> </p> <p><span style="font-family:arial, helvetica, sans-serif"><strong>Education &amp; Experience</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">5–8 years’ experience in cybersecurity, with a focus on incident response or SOC operations</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Proven experience leading major incident investigations and response</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Strong background in threat hunting and detection engineering</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Hands-on expertise with SIEM, EDR, IDS/IPS, and forensic tools</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Experience across cloud environments (AWS/Azure) and identity systems (AD/Azure AD)</span></li> <li style="font-family:arial, helvetica, sans-serif"><span style="font-family:arial, helvetica, sans-serif">Relevant certifications (e.g., GCIH, GCFA, CISSP) desirable</span></li> </ul> <p> </p><p><br><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif"><strong>What CRH Offers You</strong></span></p> <ul> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">A culture that values opportunity for growth, development, and internal promotion</span></p> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Highly competitive salary package</span></p> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Comprehensive secondary benefits</span></p> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Significant contribution to your pension plan</span></p> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Health and wellness programs, including an on-site gym and fitness classes</span></p> </li> <li style="font-family:arial, helvetica, sans-serif;font-size:10.0pt"> <p><span style="font-size:10.0pt;font-family:arial, helvetica, sans-serif">Excellent opportunities to develop and progress with a global organization</span></p> </li> </ul> <p><br><span style="font-size:10.0px;font-family:arial, helvetica, sans-serif"><strong>Connect your future to CRH </strong></span></p> <p><span style="font-size:10.0px;font-family:arial, helvetica, sans-serif">We are curious to learn more about you. At CRH, we believe our mutual differences contribute to the healthy, productive, and enjoyable workspace we create. Please introduce yourself and send us your application. <span style="font-size:10.0px;font-family:arial, helvetica, sans-serif">Following a positive review of your application, you will be invited to an introductory call with one of our Recruiters.</span></span></p> <p> </p> <p><span style="font-size:10.0px;font-family:arial, helvetica, sans-serif">Is this role not for you, but do you know someone who would love to join the team? Please let us know!</span></p> <p> </p> <p><span style="font-size:10.0px;font-family:arial, helvetica, sans-serif">CRH finds it important that vacancies are shared to individuals that may find them interesting and/or could be suitable for the role</span></p> <p> </p> <p><span style="font-size:10.0px;font-family:arial, helvetica, sans-serif">Please contact our recruitment team at [email protected]. </span></p> <p> </p> <p><span style="font-size:10.0px;font-family:arial, helvetica, sans-serif"><em>CRH is an equal opportunity employer. We are committed to creating an inclusive work environment for all employees and actively encourage applications from all sectors of the community. </em></span></p> <p> </p> <p><span style="font-size:10.0px;font-family:arial, helvetica, sans-serif"><em>Benefits/perks listed above may vary depending on the nature of the employment with CRH and the country where you work.</em></span></p> <p> </p> <p><span style="font-size:10.0px;font-family:arial, helvetica, sans-serif"><em><strong>Please note that we cannot accept any applications submitted through email for GDPR purposes. Candidates must apply through our job portal.</strong></em></span></p> <p> </p> <p><span style="font-size:10.0px;font-family:arial, helvetica, sans-serif"><em><strong>We do not accept candidate introductions for this position from recruitment agencies, unless you have been instructed to do so by our recruitment team.</strong></em></span></p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores