Amach

Open

Senior Cyber Incident Response Analyst

Location
Ankara, Ankara, Turkey
Posted
Jul 27, 2026
Last seen
Aug 7, 2026

About the role

About us:

Amach is an industry-leading technology driven company with headquarters located in Dublin and remote teams in UK and Europe.

Our blended teams of local and nearshore talent are optimised to deliver high quality and collaborative solutions.

Founded in 2013, Amach was created to solve a specific problem in aviation: too much complexity, too little usable intelligence. We help airlines modernise their operating model using cloud, data and Al-delivered by teams with deep aviation domain expertise.

Our goal is to maximize airlines' operational efficiency by optimizing resource use, reduce costs and increase customer experience and satisfaction.

The Senior Cyber Incident Response Analyst is a senior technical specialist within the Cyber Defence function, responsible for leading hands-on incident response activities and managing the SOC. You will drive effective services including 24x7 monitoring, rapid incident response, and ongoing improvement of detection and response processes through automation, testing and strong operational governance.

Reporting into the Head of Cyber Defence, this role will work cross‑functionally with teams across Cyber Defence, Cyber Engineering and IT, supporting ongoing maturity of cyber monitoring coverage and incident management playbooks for timely detection and response processes.

Required Experience:

Essential Qualifications / Experience

  • 10+ years cybersecurity and/or IT experience, with at least 6 years in SOC or Incident Response roles
  • Proven experience in direct involvement in cyber incidents, fulfilling investigation, digital forensics, event triaging and response responsibilities
  • Experience working with outsourced SOC security services
  • Relevant Cyber qualifications e.g. CISM, GIAC, OSCP, CEH, or similar

Essential Competencies / Skills

  • Strong crisis management, communication and cross‑functional collaboration skills.
  • Proactive and independent thinker, willing to challenge ways of working
  • Hands‑on proficiency with Cyber Defence technologies (e.g., SIEM, Threat Intelligence, SOAR, EDR platforms such as CrowdStrike, ZeroFox, Splunk or equivalent).
  • Demonstrated ability to develop and mature incident management capabilities, improving operational processes and playbooks, and development of detection use cases.
  • Ability to translate threat intelligence, control testing and incident learnings into measurable improvements in detections, controls and response automation.

Key responsibilities & duties include:

  • Support the execution of the Cyber Incident Management strategy defined by the Head of Cyber Defence
  • Act as the technical escalation for the customer's SOC
  • Senior member of the Incident Response team during cyber events, co-ordinating with the outsourced SOC and internal Cyber and IT teams on response, forensics and investigation activities and remediations.
  • Participate in analysis exercises with the SOC, identifying recurring root causes to incidents and champion remediations and improvements
  • Partner with Vulnerability Management and Offensive Security teams, to continually optimise monitoring and cyber use case colorations.
  • Lead improvements to monitor, detect and respond to threats in real time, leveraging SIEM, EDR, SOAR and automation to deliver at scale.
  • Ensure Cyber Defence evidence, reporting and assurance are fit for purpose (incident records integrity, audit trails, lessons learned and continuous improvement actions).
  • Part of on-call rota, as point of escalation in the event of a major cyber event
  • Partner with the outsourced SOC and Threat Management services, with daily, weekly and monthly operational cadences, to ensure full visibility of the current incident landscape, and holding them accountable for service KPIs and SLAs
  • Lead the development and maintenance of incident response playbooks
  • Support the Head of Cyber Defence to deliver regular incident testing to enhance readiness with technology and operational teams

Desirable skills

  • Familiarity with MITRE ATT&CK framework and modern attacker techniques.
  • Experience managing IR KPIs such as MTTD/MTTR, detection coverage and first-time remediation
  • Scripting and developing skills for integrating cyber tools, and automating playbook responses.
  • Familiarity with regulatory and incident reporting obligations and evidence requirements (e.g., NIS2, GDPR, aviation regulations such as IAA/EASA Part‑IS).

What’s in it for you:

  • An opportunity to join a fast-growing company
  • Options for career advancement <li data-leveltext="" data-font="Symbol" data-listid="1" d