1 to 25 of 77 Incident Response Jobs in the East of England

Senior Manager, Cybersecurity Incident Response

Hiring Organisation
ARM
Location
Cambridge, Cambridgeshire, United Kingdom
Salary
£ 100 K
Overview:Interested in defending a global tech company from the latest cyber threats? Arm is seeking a passionate, experienced Senior Manager of Cybersecurity Incident Response to join our growing Cyber Defence Operations (CDO) team, protecting Arm against current and future cyber-attacks! Situated within Arm’s Enterprise Security … function, this role will lead Arm’s global incident response team across the US, UK and India, including acting as a senior technical and operational leader for major cyber incidents.CDO enables Arm to be successful, delivering scalable and defendable security services that not only provide for the protection ...

Cyber Incident Manager (CIM) - Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland

Hiring Organisation
Tesco
Location
Welwyn Garden City, Hertfordshire, United Kingdom
Salary
£ 70 K
About the role: As a Cyber Incident Manager at Tesco, you will lead the coordinated response to cyber incidents, protecting the integrity of the retail ecosystem that serves millions of customers every day. Acting as a central orchestrator, you will ensure swift, structured, and effective incident resolution … minimising operational disruption and customer impact. This role is critical to maintaining trust in Tesco’s digital platforms by driving proactive, intelligence-led response and embedding continuous improvement across the cyber defence lifecycle. You will operate at the intersection of technology, business impact, and customer outcomes, championing innovation ...

SOC - Cyber Threat Operations Specialist

Hiring Organisation
Certain Advantage
Location
Stevenage, Hertfordshire, United Kingdom
Employment Type
Full-Time
Salary
£85.00 per hour
ongoing and long-term thereafter) IR35 status: Inside IR35 (Umbrella) Cyber Threat Operations Specialist Job Description: An opportunity has arisen in the Active Defence Incident Response Team within Digital Excellence (DEX) for a Cyber Threat Operations specialist. Supporting the Active Defence & Incident Response Manger in assisting … cyber security environment and provide robust threat hunting, detection Engineering and analysis within a high performing team environment. Responsibilities: To support the Active Defence Incident Response Manager in assisting Information Management UK meet the challenges and demands of countering the Cyber Threat. Support for the operational functions ...

Security Manager - SOC - Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland

Hiring Organisation
Tesco
Location
Welwyn Garden City, Hertfordshire, United Kingdom
Salary
£ 80 K
deliver a modern, customer-first cyber defence capability. This role reports to the SOC Manager and forms a key role within our Investigation & Incident Response management team.What is in it for you: We’re all about the little helps. That’s why we make sure our Tesco colleague … effectively scoped, implemented, and embedded without compromising operational performance.· Drive Operational Excellence: Ensure the SOC operates at high performance, maintaining strong detection and response capability, service reliability, and measurable outcomes aligned to business risk.· Enable Innovation: Champion the adoption of Applied AI and automation to optimise SOC workflows, reduce ...

SOC Analyst - Active SC required

Location
Essex, England, United Kingdom
defence/aerospace client on a short term contract. The successful candidate will have proven experience using IBM QRadar SIEM in a monitoring and incident response capacity. Key Responsibilities: Monitor and analyse security events using IBM QRadar SIEM Investigate and respond to security incidents across various platforms Manage … full incident lifecycle, from identification to resolution Conduct threat detection and analysis, along with threat hunting activities Perform detailed log analysis across multiple security platforms Produce incident reports and post-incident reviews Collaborate with team members to ensure robust security controls Investigate non-standard Cyber requests ...

IT Infrastructure & Cyber Security Engineer – 3rd Line, Cloud & AI

Hiring Organisation
Recruitment Revolution
Location
Colchester, Essex, United Kingdom
Salary
£ 55 K
EnablementYour Background/Skills: 3rd Line Engineering, IT Infrastructure, Cyber Security, Azure, Google Workspace, Networking, CrowdStrike, Cisco, VMware vSphere, Windows Server, Jamf, Intune, Incident Response, Cyber Essentials, AI ToolingWho We AreBulk is on an incredible journey, with a mission to evolve from a manufacturing-led retailer into … security aspects of AI integration and take a leading role in our Cyber Essentials project next year.You'll also oversee infrastructure, security tooling, incident response, budgeting and contracting, while becoming a Tier 3 escalation point for complex issues that need deeper technical expertise.And we're not expecting ...

Senior Incident Responder (DFIR) - Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland

Hiring Organisation
Tesco
Location
Welwyn Garden City, Hertfordshire, United Kingdom
Salary
£ 70 K
About the role: Our Digital Forensics and Incident Response (DFIR) team lead the technical investigation and response to security incidents at Tesco. As part of this team, you’ll work alongside our security operations, threat intelligence, and security engineering teams to protect, detect, and respond to security … help improve and automate the team’s technical workflows, working alongside other teams to help drive innovation across our prevention, automation, detection and response capabilities. Your status as a senior incident responder means you’ll serve as a role model for engineers and analysts across Security Operations.What ...

SOC Shift Lead

Hiring Organisation
Searchability NS&D
Location
Hemel Hempstead, England, United Kingdom
busy Security Operations Centre while remaining hands-on with technical investigations. You will act as the senior escalation point during your shift, leading incident response, mentoring analysts and ensuring high standards across investigations. You will also: Lead Major Incident investigations and technical response activities Analyse advanced … Lead Strong experience leading complex cyber security investigations Commercial experience with Microsoft Sentinel and Splunk Enterprise Security Excellent understanding of MITRE ATT and CK, incident response and threat-informed defence Strong networking knowledge including TCP/IP, DNS, HTTP/S, SMTP, LDAP and VPN technologies Experience analysing ...

Senior Detection and Response Engineer

Hiring Organisation
Jagex
Location
Cambridge, Cambridgeshire, United Kingdom
Salary
£ 80 K
remote work. Applicants should be based within a comfortable commuting distance of our office to attend onsite as required.Are you experienced in detection and incident response, with an engineering mindset and a passion for improving the tools, automation and processes used to investigate threats As a Senior Detection … Response Engineer within our Cyber Security team, you’ll play a key role in strengthening Jagex’s detection and incident response capability across our studio and gaming environments. You’ll take ownership of escalated security investigations, going beyond routine alert handling to understand what happened, determine impact ...

Cyber Security Analyst

Hiring Organisation
Carter Jonas
Location
Peterborough, Cambridgeshire, United Kingdom
Salary
£ 60 K
team in Peterborough to help protect Carter Jonas’s systems, data, and information assets. The role combines hands-on security operations with vulnerability management, incident response, cyber risk, governance, assurance and continual improvement of the organisation’s security posture. The post holder will work with IT, Compliance … logs and events across key platforms including SIEM, EDR/XDR, Microsoft Defender, Microsoft Sentinel, email security, cloud security and network monitoring tools.Support timely incident response, containment, remediation, recovery and post-incident review activity with internal teams and third-party providers.Maintain the vulnerability management programme, including scanning ...

Senior Detection and Response Engineer

Location
Cambridge, England, United Kingdom
work. Applicants should be based within a comfortable commuting distance of our office to attend onsite as required. Are you experienced in detection and incident response, with an engineering mindset and a passion for improving the tools, automation and processes used to investigate threats? As a Senior Detection … Response Engineer within our Cyber Security team, you’ll play a key role in strengthening Jagex’s detection and incident response capability across our studio and gaming environments. You’ll take ownership of escalated security investigations, going beyond routine alert handling to understand what happened, determine impact ...

EU Resilience Lead

Hiring Organisation
Booz Allen Hamilton
Location
Cambridge, Cambridgeshire, United Kingdom
Salary
£ 70 K
building recovery capabilities for critical services.You Have:8+ years of experience leading or advising on enterprise technology, resilience, cybersecurity, infrastructure, disaster recovery, business continuity, incident response, or crisis management disciplines for large, complex European or global organizationsExperience with advising executive stakeholders and leading senior-level advising or delivery … current capabilities, and developing practical improvement roadmaps that help clients harden infrastructure, improve alignment to NIST CSF categories, strengthen recovery and continuity strategies, test response capabilities, and mature program governance over timeExperience in a consulting or corporate advisory role, including with a top-tier consulting company, specialized cybersecurity ...

AI Security Consultant

Hiring Organisation
PA Consulting
Location
Pimlico, Hertfordshire, UK
Employment Type
Full-time
supporting secure AI adoption, reviewing LLM-based applications, advising on SOC automation, developing AI security guardrails, and helping organisations use AI to enhance detection, response, reporting and risk management. The right candidate will combine strong cyber security fundamentals with curiosity and practical knowledge of AI security. You should … business risk. Support the design and implementation of security controls across areas such as access management, data protection, logging and monitoring, vulnerability management, incident response and third-party risk. Help clients interpret security requirements, assess control maturity and develop actionable improvement roadmaps. Translate technical findings into clear, business ...

Senior / 3rd Line IT Engineer - Infrastructure & Cyber Security

Hiring Organisation
Recruitment Revolution
Location
Colchester, Essex, South East, United Kingdom
Employment Type
Permanent
Enablement Your Background/Skills: 3rd Line Engineering, IT Infrastructure, Cyber Security, Azure, Google Workspace, Networking, CrowdStrike, Cisco, VMware vSphere, Windows Server, Jamf, Intune, Incident Response, Cyber Essentials, AI Tooling Who We Are BulkTM is on an incredible journey, with a mission to evolve from a manufacturing … security aspects of AI integration and take a leading role in our Cyber Essentials project next year. You'll also oversee infrastructure, security tooling, incident response, budgeting and contracting, while becoming a Tier 3 escalation point for complex issues that need deeper technical expertise. ...

Senior / 3rd Line IT Engineer - Infrastructure & Cyber Security

Hiring Organisation
RecruitmentRevolution.com
Location
CO4, Mile End, Essex, United Kingdom
Employment Type
Permanent
Enablement Your Background/Skills: 3rd Line Engineering, IT Infrastructure, Cyber Security, Azure, Google Workspace, Networking, CrowdStrike, Cisco, VMware vSphere, Windows Server, Jamf, Intune, Incident Response, Cyber Essentials, AI Tooling Who We Are Bulk™ is on an incredible journey, with a mission to evolve from a manufacturing … security aspects of AI integration and take a leading role in our Cyber Essentials project next year. You'll also oversee infrastructure, security tooling, incident response, budgeting and contracting, while becoming a Tier 3 escalation point for complex issues that need deeper technical expertise. ...

Senior / 3rd Line IT Engineer - Infrastructure & Cyber Security

Hiring Organisation
RecruitmentRevolution.com
Location
Colchester, Essex, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Permanent Your Background/Skills: 3rd Line Engineering, IT Infrastructure, Cyber Security, Azure, Google Workspace, Networking, CrowdStrike, Cisco, VMware vSphere, Windows Server, Jamf, Intune, Incident Response, Cyber Essentials, AI Tooling The Opportunity As our ISenior/3rd Line IT Engineer, you'll take ownership of Bulk's infrastructure … security aspects of AI integration and take a leading role in our Cyber Essentials project next year. You'll also oversee infrastructure, security tooling, incident response, budgeting and contracting, while becoming a Tier 3 escalation point for complex issues that need deeper technical expertise. ...

Principal AI Platform Engineer

Location
Cambridge, England, United Kingdom
runtime platforms that make AI services reliable, secure, observable and supportable at Arm scale. You will work across Kubernetes, cloud, identity, secrets, networking, telemetry, incident management and automation to provide the production foundation for Arm's AI platform. Participate in production support and our paid on-call rota … high impact incident response. Production AI runtime platforms: Build/deploy and operate the infrastructure for centrally hosted AI platform services, including MCP server infrastructure, model gateway services and supporting control-plane components. Design runtime patterns for isolation, scalability, secure execution, capacity management and cost-aware operation. Automate provisioning ...

SOC Shift Lead

Hiring Organisation
Searchability NS&D
Location
Watford, Hertfordshire, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £80,000 per annum
busy Security Operations Centre while remaining hands-on with technical investigations. You will act as the senior escalation point during your shift, leading incident response, mentoring analysts and ensuring high standards across investigations. You will also: Lead Major Incident investigations and technical response activities Analyse advanced … Lead Strong experience leading complex cyber security investigations Commercial experience with Microsoft Sentinel and Splunk Enterprise Security Excellent understanding of MITRE ATT and CK, incident response and threat-informed defence Strong networking knowledge including TCP/IP, DNS, HTTP/S, SMTP, LDAP and VPN technologies Experience analysing ...

SENIOR INFORMATION ASSURANCE ENGINEER

Hiring Organisation
Leidos Innovations UK Limited
Location
Huntingdon, Cambridgeshire, East Anglia, United Kingdom
Employment Type
Permanent
Salary
£75,000
with experience developing assurance artefacts such as SyOPs, RMADs, Security Impact Assessments, risk assessments, and accreditation evidence. Experience leading assurance initiatives, audits, control assessments, incident response activity, and vulnerability management using tools such as Nessus, Trivy, Tenable, or similar platforms. Ability to brief and influence senior stakeholders, mentor … Security Impact Assessments, Security Management Plans, risk assessments, and governance documentation. Drive maturity of assurance processes, tooling, reporting, and governance across multiple programmes. Lead incident response capability development, including response plans, playbooks, testing, exercising, and Tabletop Exercises (TTXs). Manage vulnerability, risk, audit, control assessment, and compliance ...

Cyber Security Analyst - Training Course

Hiring Organisation
Netcom Training
Location
Watford, Hertfordshire, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
Training's government-funded Cyber security course is your route into one of tech's fastest-growing fields. Learn threat intelligence, security testing and incident response in an interactive online format and earn a nationally recognised NCFE Level 3 Certificate in Cyber Security Practices. Course details Duration … learn Applying cyber security principles and risk assessment Gathering threat intelligence, including open source intelligence (OSINT) Carrying out security testing and identifying vulnerabilities Planning incident response and writing post-incident reports Potential roles this training could lead to Information Security Analyst Incident Responder Analyst Junior Forensic ...

Cyber Security Analyst - Training Course

Hiring Organisation
Netcom Training
Location
Watford, Hertfordshire, United Kingdom
Employment Type
Permanent, Contract, Temporary, Part Time, Apprenticeship
Training's government-funded Cyber security course is your route into one of tech's fastest-growing fields. Learn threat intelligence, security testing and incident response in an interactive online format and earn a nationally recognised NCFE Level 3 Certificate in Cyber Security Practices. Course details Duration … learn Applying cyber security principles and risk assessment Gathering threat intelligence, including open source intelligence (OSINT) Carrying out security testing and identifying vulnerabilities Planning incident response and writing post-incident reports Potential roles this training could lead to Information Security Analyst Incident Responder Analyst Junior Forensic ...

SC Cleared SOC Analyst: QRadar & Incident Response (Remote)

Location
Essex, England, United Kingdom
defence/aerospace client on a 3-month contract in the UK. The role focuses on monitoring security events with IBM QRadar SIEM, incident response, and threat detection, with remote work and occasional site visits. You will investigate incidents across platforms, manage the incident lifecycle, perform … analysis, and contribute to post-incident reviews, working to MITRE ATT&CK and NIST frameworks. #J-18808-Ljbffr ...

Senior Detection and Response Engineer

Location
Cambridge, England, United Kingdom
queries and monitoring logic across cloud, endpoint, network and application environments. Develop tooling and automation to improve security telemetry, alert enrichment, investigation workflows and response times. Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections. Create … continuously improve incident runbooks, playbooks and detection processes based on findings from real-world investigations. Work with the external SOC and internal engineering teams to strengthen monitoring coverage, investigate escalations and continuously improve detection and response capability. Participate in an on-call rotation. Requirements Hands-on experience investigating ...

Cyber Security Lead

Hiring Organisation
SSA Digital Recruitment
Location
Bedford, Bedfordshire, United Kingdom
Employment Type
Permanent
Salary
£60000 - £72000/annum
security remediation, coordinating penetration testing and ensuring identified vulnerabilities and security issues are addressed effectively. You'll also manage information security risk assessments, support incident response, supplier and third-party security assurance, Business Continuity and Disaster Recovery, while helping embed a strong security culture across the organisation. … Cloud & Identity Security: Microsoft 365, Azure Security, Identity & Access Management (IAM) and access controls. Security Operations: vulnerability management, patch management, penetration testing, remediation and incident response. Information Security: ISO 27001, ISMS, security audits, Cyber Essentials, security policies, governance, risk and compliance. You don't necessarily need to already hold ...

SOC Analyst

Location
Harlow, England, United Kingdom
Requirements: 2-3+ years' SOC experience Strong hands-on experience with IBM QRadar SIEM Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations … Technical Exposure: IBM QRadar Microsoft Defender/EDR Microsoft Sentinel (desirable) Microsoft Entra ID/Azure AD Email threat response Incident Experience: Phishing & Business Email Compromise Malware & Ransomware Account Compromise Privilege Escalation Insider Threats DLP & Data Exfiltration Alerts Suspicious Authentication Activity Knowledge of: MITRE ATT&CK, Cyber Kill ...