Cyber Investigations and Response Lead
The Cybersecurity Investigations & Response (CIR) team within AC3 (Aon's Global Cybersecurity Operations) is responsible for leading and coordinating incident response, conducting in-depth investigations, and continuously improving how Aon detects, responds to, and recovers from cyber events.
This role can be virtual near one of our US office locations.
Aon is in the business of better decisions
At Aon, we shape decisions for the better to protect and enrich the lives of people around the world.
As an organization, we are united through trust as one inclusive team, and we are passionate about helping our colleagues and clients succeed.
What the day will look like
This role focuses on deep investigation, coordination, and response leadership-ensuring incidents are executed according to defined processes, evidence is preserved, risks are clearly understood, and lessons learned to drive measurable improvements across Aon's cybersecurity program.
Incident Response & Investigations
-
Lead or support end-to-end investigations for security incidents, from initial triage through containment, eradication, and recovery.
-
Perform detailed analysis of alerts, logs, and telemetry across multiple domains (SIEM, endpoint, identity, network, cloud, email, and third-party sources) to determine scope, root cause, and business impact.
-
Partner closely with AC3 Threat Detection & Response (TDR) teams to validate true positives, refine investigative hypotheses, and improve the quality and reliability of detection signals.
-
Develop clear incident timelines, findings, and technical assessments, ensuring accurate and complete case documentation.
-
Maintain high-quality incident records and evidence within Aon's case management and response tooling.
Crisis & Stakeholder Coordination
-
Support crisis execution during major or high-severity incidents, collaborating with GEOC, Legal, Risk, Audit, Communications, and business leadership as required.
-
Translate technical findings into clear, risk-based insights for both technical and non-technical audiences.
-
Follow and reinforce consistent escalation and communication patterns-ensuring the right stakeholders are informed at the right time with the right level of detail.
-
Contribute to calm, structured, and disciplined response execution during high-pressure events.
Playbooks, Procedures & Readiness
-
Help develop, maintain, and improve incident response runbooks, playbooks, and standard operating procedures for common and high-impact scenarios (e.g., ransomware, BEC, insider threat, data ex-filtration, cloud compromise).
-
Participate in, and help design, tabletop exercises and simulations to test technical response and crisis readiness.
-
Support audit, regulatory, and internal assurance activities by clearly documenting response processes, decisions, and evidence of execution.
Continuous Improvement & Threat-Informed Defense
-
Lead or contribute to lessons-learned activities following incidents and near misses; track improvement actions through to completion.
-
Partner with vulnerability management, identity, infrastructure, cloud, and application security teams to ensure investigation insights drive real risk reduction.
-
Identify detection and visibility gaps and work with TDR to enhance telemetry, tune detections, and improve signal-to-noise ratios across AC3.
-
Strengthen Aon's threat-informed defense by feeding investigative insights back into controls, detections, and processes.
Collaboration & Global Alignment
-
Operate within a follow-the-sun global model, coordinating with CIR and TDR peers across North America, EMEA, and APAC.
-
Support alignment of tools, telemetry, processes, and reporting across regions to enable consistent, scalable operations.
-
Contribute to a culture of collaboration, shared ownership, and continuous improvement across AC3 and Global Cybersecurity Solutions.
How this opportunity is different
As a CIR Analyst, you will play a critical role in investigating and responding to security incidents across Aon's North America region. You will work closely with TDR, Global Security Operations, IT, Legal, Risk, Audit, and business stakeholders to ensure incidents are handled effectively and consistently.
Skills and experience that will lead to successRequired
-
Professional experience in cybersecurity operations, incident response, digital forensics, threat hunting, or a closely related discipline.
-
Strong understanding of core security domains, including: Network security; Endpoint security; Identity and access management; Cloud security fundamentals; Common attack techniques (MITRE ATT&CK familiarity preferred);
-
Hands-on experience with multiple security technologies, such as: SIEM platforms (log analysis, investigation, correlation); EDR/EPP tools; Network security tools (firewalls, proxies, IDS/IPS); Email security and identity platforms; Cloud security and logging solutions
-
Demonstrated ability to analyze telemetry, develop investigative hypotheses, and methodically work incidents through to resolution.
-
Strong written and verbal communication skills, including the ability to produce clear technical documentation and concise executive-level summaries.
-
Familiarity with structured incident response frameworks (e.g., NIST, SANS, ISO) is preferred.
Preferred
-
Experience in a large, complex, or global enterprise environment.
-
Prior work experience in a SOC, DFIR function, or Cyber Incident Response Team.
-
Familiarity with automation or scripting (e.g., Python, PowerShell, KQL, or SOAR platforms) to accelerate investigations and response.
-
Experience working with SOAR or case management platforms in an operational environment.
-
Relevant industry certifications (e.g., GCIA, GCFA, GNFA, GCIH, CISSP, CISM) are a plus but not required.
Education: Bachelor's degree or equivalent years of industry experience.
How we support our colleagues
In addition to our comprehensive benefits package, we encourage an inclusive workforce. Plus, our agile environment allows you to manage your wellbeing and work/life balance, ensuring you can be your best self at Aon. Furthermore, all colleagues enjoy two "Global Wellbeing Days" each year, encouraging you to take time to focus on yourself. We offer a variety of working style solutions for our colleagues as well.
Our continuous learning culture inspires and equips you to learn, share and grow, helping you achieve your fullest potential. As a result, at Aon, you are more connected, more relevant, and more valued.
Aon values an innovative and inclusive workplace where all colleagues feel empowered to be their authentic selves. Aon is proud to be an equal opportunity workplace.
Aon provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, creed, sex, sexual orientation, gender identity, national origin, age, disability, veteran, marital, domestic partner status, or other legally protected status. People with criminal histories are encouraged to apply.
We are committed to providing equal employment opportunities and fostering an inclusive workplace. If you require accommodations during the application or interview process, please let us know. You can request accommodations by emailing us at [email protected] or your recruiter. We will work with you to meet your needs and ensure a fair and equitable experience.
For positions in San Francisco and Los Angeles, we will consider for employment qualified applicants with arrest and conviction record in accordance with local Fair Chance ordinances.
Aon is not accepting unsolicited resumes from search firms for this position. If you are a search firm, you will not be compensated in any way for your submission of a candidate, even if Aon hires that candidate.
Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to this job at any time.
Pay Transparency Laws:
The salary range for this position (intended for U.S. applicants) is $150,000 - $175,000 USD annually. The actual salary will vary based on applicant's education, experience, skills, and abilities, as well as internal equity and alignment with market data. The salary may also be adjusted based on applicant's geographic location.
This position is eligible to participate in one of Aon's annual incentive plans to receive an annual discretionary bonus in addition to base salary. The amount of any bonus varies and is subject to the terms and conditions of the applicable incentive plan.
Aon offers a comprehensive package of benefits for full-time and regular part-time colleagues, including, but not limited to: a 401(k) savings plan with employer contributions; an employee stock purchase plan; consideration for long-term incentive awards at Aon's discretion; medical, dental and vision insurance, various types of leaves of absence, paid time off, including 12 paid holidays throughout the calendar year, 15 days of paid vacation per year, paid sick leave as provided under state and local paid sick leave laws, short-term disability and optional long-term disability, health savings account, health care and dependent care reimbursement accounts, employee and dependent life insurance and supplemental life and AD&D insurance; optional personal insurance policies, adoption assistance, tuition assistance, commuter benefits, and an employee assistance program that includes free counseling sessions. Eligibility for benefits is governed by the applicable plan documents and policies.
#LI-RB1 #LI-VIRTUAL 2026-99204The Cybersecurity Investigations & Response (CIR) team within AC3 (Aon's Global Cybersecurity Operations) is responsible for leading and coordinating incident response, conducting in-depth investigations, and continuously improving how Aon detects, responds to, and recovers from cyber events.
This role can be virtual near one of our US office locations.
Aon is in the business of better decisions
At Aon, we shape decisions for the better to protect and enrich the lives of people around the world.
As an organization, we are united through trust as one inclusive team, and we are passionate about helping our colleagues and clients succeed.
What the day will look like
This role focuses on deep investigation, coordination, and response leadership-ensuring incidents are executed according to defined processes, evidence is preserved, risks are clearly understood, and lessons learned to drive measurable improvements across Aon's cybersecurity program.
Incident Response & Investigations
-
Lead or support end-to-end investigations for security incidents, from initial triage through containment, eradication, and recovery.
-
Perform detailed analysis of alerts, logs, and telemetry across multiple domains (SIEM, endpoint, identity, network, cloud, email, and third-party sources) to determine scope, root cause, and business impact.
-
Partner closely with AC3 Threat Detection & Response (TDR) teams to validate true positives, refine investigative hypotheses, and improve the quality and reliability of detection signals.
-
Develop clear incident timelines, findings, and technical assessments, ensuring accurate and complete case documentation.
-
Maintain high-quality incident records and evidence within Aon's case management and response tooling.
Crisis & Stakeholder Coordination
-
Support crisis execution during major or high-severity incidents, collaborating with GEOC, Legal, Risk, Audit, Communications, and business leadership as required.
-
Translate technical findings into clear, risk-based insights for both technical and non-technical audiences.
-
Follow and reinforce consistent escalation and communication patterns-ensuring the right stakeholders are informed at the right time with the right level of detail.
-
Contribute to calm, structured, and disciplined response execution during high-pressure events.
Playbooks, Procedures & Readiness
-
Help develop, maintain, and improve incident response runbooks, playbooks, and standard operating procedures for common and high-impact scenarios (e.g., ransomware, BEC, insider threat, data ex-filtration, cloud compromise).
-
Participate in, and help design, tabletop exercises and simulations to test technical response and crisis readiness.
-
Support audit, regulatory, and internal assurance activities by clearly documenting response processes, decisions, and evidence of execution.
Continuous Improvement & Threat-Informed Defense
-
Lead or contribute to lessons-learned activities following incidents and near misses; track improvement actions through to completion.
-
Partner with vulnerability management, identity, infrastructure, cloud, and application security teams to ensure investigation insights drive real risk reduction.
-
Identify detection and visibility gaps and work with TDR to enhance telemetry, tune detections, and improve signal-to-noise ratios across AC3.
-
Strengthen Aon's threat-informed defense by feeding investigative insights back into controls, detections, and processes.
Collaboration & Global Alignment
-
Operate within a follow-the-sun global model, coordinating with CIR and TDR peers across North America, EMEA, and APAC.
-
Support alignment of tools, telemetry, processes, and reporting across regions to enable consistent, scalable operations.
-
Contribute to a culture of collaboration, shared ownership, and continuous improvement across AC3 and Global Cybersecurity Solutions.
How this opportunity is different
As a CIR Analyst, you will play a critical role in investigating and responding to security incidents across Aon's North America region. You will work closely with TDR, Global Security Operations, IT, Legal, Risk, Audit, and business stakeholders to ensure incidents are handled effectively and consistently.
Skills and experience that will lead to successRequired
-
Professional experience in cybersecurity operations, incident response, digital forensics, threat hunting, or a closely related discipline.
-
Strong understanding of core security domains, including: Network security; Endpoint security; Identity and access management; Cloud security fundamentals; Common attack techniques (MITRE ATT&CK familiarity preferred);
-
Hands-on experience with multiple security technologies, such as: SIEM platforms (log analysis, investigation, correlation); EDR/EPP tools; Network security tools (firewalls, proxies, IDS/IPS); Email security and identity platforms; Cloud security and logging solutions
-
Demonstrated ability to analyze telemetry, develop investigative hypotheses, and methodically work incidents through to resolution.
-
Strong written and verbal communication skills, including the ability to produce clear technical documentation and concise executive-level summaries.
-
Familiarity with structured incident response frameworks (e.g., NIST, SANS, ISO) is preferred.
Preferred
-
Experience in a large, complex, or global enterprise environment.
-
Prior work experience in a SOC, DFIR function, or Cyber Incident Response Team.
-
Familiarity with automation or scripting (e.g., Python, PowerShell, KQL, or SOAR platforms) to accelerate investigations and response.
-
Experience working with SOAR or case management platforms in an operational environment.
-
Relevant industry certifications (e.g., GCIA, GCFA, GNFA, GCIH, CISSP, CISM) are a plus but not required.
Education: Bachelor's degree or equivalent years of industry experience.
How we support our colleagues
In addition to our comprehensive benefits package, we encourage an inclusive workforce. Plus, our agile environment allows you to manage your wellbeing and work/life balance, ensuring you can be your best self at Aon. Furthermore, all colleagues enjoy two "Global Wellbeing Days" each year, encouraging you to take time to focus on yourself. We offer a variety of working style solutions for our colleagues as well.
Our continuous learning culture inspires and equips you to learn, share and grow, helping you achieve your fullest potential. As a result, at Aon, you are more connected, more relevant, and more valued.
Aon values an innovative and inclusive workplace where all colleagues feel empowered to be their authentic selves. Aon is proud to be an equal opportunity workplace.
Aon provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, creed, sex, sexual orientation, gender identity, national origin, age, disability, veteran, marital, domestic partner status, or other legally protected status. People with criminal histories are encouraged to apply.
We are committed to providing equal employment opportunities and fostering an inclusive workplace. If you require accommodations during the application or interview process, please let us know. You can request accommodations by emailing us at [email protected] or your recruiter. We will work with you to meet your needs and ensure a fair and equitable experience.
For positions in San Francisco and Los Angeles, we will consider for employment qualified applicants with arrest and conviction record in accordance with local Fair Chance ordinances.
Aon is not accepting unsolicited resumes from search firms for this position. If you are a search firm, you will not be compensated in any way for your submission of a candidate, even if Aon hires that candidate.
Nothing in this job description restricts management's right to assign or reassign duties and responsibilities to this job at any time.
Pay Transparency Laws:
The salary range for this position (intended for U.S. applicants) is $150,000 - $175,000 USD annually. The actual salary will vary based on applicant's education, experience, skills, and abilities, as well as internal equity and alignment with market data. The salary may also be adjusted based on applicant's geographic location.
This position is eligible to participate in one of Aon's annual incentive plans to receive an annual discretionary bonus in addition to base salary. The amount of any bonus varies and is subject to the terms and conditions of the applicable incentive plan.
Aon offers a comprehensive package of benefits for full-time and regular part-time colleagues, including, but not limited to: a 401(k) savings plan with employer contributions; an employee stock purchase plan; consideration for long-term incentive awards at Aon's discretion; medical, dental and vision insurance, various types of leaves of absence, paid time off, including 12 paid holidays throughout the calendar year, 15 days of paid vacation per year, paid sick leave as provided under state and local paid sick leave laws, short-term disability and optional long-term disability, health savings account, health care and dependent care reimbursement accounts, employee and dependent life insurance and supplemental life and AD&D insurance; optional personal insurance policies, adoption assistance, tuition assistance, commuter benefits, and an employee assistance program that includes free counseling sessions. Eligibility for benefits is governed by the applicable plan documents and policies.
#LI-RB1 #LI-VIRTUALRecommended Jobs
Chemical Operator
What you´ll do Operates machines and production equipment safely in accordance with instructions Sets up or adjusts equipment according to manufacturing specifications Monitors the quality o…
Software Developer
Kforce has a client in Chicago, IL that is seeking a Software Developer. This is high touch position with a notable amount of collaboration across product teams and stakeholders to define requirements…
ServiceNow Solution Architect (Senior Manager)
Mon, 01/19/2026 - 04:10 Huron helps its clients drive growth, enhance performance and sustain leadership in the markets they serve. We collaborate with education organizations to develop strategies an…
Account Executive
Redstone Payment Solutions – Outside Sales Representative (Sales Partner) Family-owned Merchant Services leader delivering industry-low processing rates and white-glove service. We’re not here to…
Easter Photo Set Staff-St Claire Square
Love the Holidays? Want to work alongside the Easter Bunny? We’ve got a job for you! VIP Holiday Photos needs your help to make children's dreams come true this coming Easter season: March -April. …
Head of Sales - AVP - Healthcare Provider
Role: AVP, Business Development - Healthcare (Remote) Description Reveal HealthTech is a dedicated healthcare-focused technology services company - helping our clients with a range of AI and produ…
Class A Experienced OTR Driver for Landstar RXO Job
Class A Experienced OTR Driver for Landstar RXO Job About our company, we're a full service logistics company providing services throughout the US and Canada. Our company partners with Fortune 500 co…
Account Executive - Employee Benefits
At Gallagher Benefit Services, you’re a trusted partner to organizations navigating some of their most important people decisions. We help clients build better workplaces, where people feel supp…
Route Service Manager - UniFirst
Route Service Manager UniFirst seeking a Route Service Manager to join our team! The Route Service Manager will recruit and lead a team of Route Service Supervisors and Route Service Representati…
Office Manager
Office Manager Transdevis hiring an Office Manager. TheOffice Manager performs administrative tasks in maintaining the collecting, gathering, processing and reporting of all financial information …