Citi's Cloud IncidentResponse (Cloud IR) team seeks a Senior Vice President of Microsoft 365 (M365) and Azure IncidentResponse to lead and oversee the organization's incidentresponse operations within the M365 environment. You will work closely with stakeholders to ensure effective … security incidentresponse with an aim to safeguard the integrity of Citi's Microsoft 365 services. Your role is critical in ensuring a proactive and coordinated approach in responding to cloud security incidents and managing security risks within the M365 suite. You will align incidentresponse … the evolution of cloud security practices, and guide the organization through critical security challenges within the M365 ecosystem. Responsibilities: Own and lead Citi's response to security incidents in our M365 and Azure platforms Build and sustain a high-performing security operations team skilled in managing M365 incidents Collaborate More ❯
contain, escalate, investigate, and coordinate mitigation of security events relative to anomalies detected and escalated by the Cyber Fusion Center according to Experian's IncidentResponse Plan. As an individual contributor, this team member will join a new, growing team of specialized, advanced responders to support escalations of … complex and prioritized matters from Experian's existing 24x7 security monitoring and response functions, responsible for responding to and analyzing security incidents involving threats targeting Experian information assets. You will work with end-users, technical support teams, and management to ensure remediation and recovery from these threats. You will … report to the Senior Manager, Global Incident Response. You'll have the opportunity to: Conduct advanced incidentresponse activities to investigate and contain complex or larger-scale cybersecurity matters. Orchestrate workstreams across teams (Forensics and Cyber Threat Hunting) and explain the CFC's overall understanding of the More ❯
City of London, London, United Kingdom Hybrid / WFH Options
Ashdown Group
IncidentResponse Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £100,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an IncidentResponse Manager within its cyber threat … point once a month for weekends) - Deliver on information security projects - Ensuring services provided meet the business requirements To be considered suitable for this IncidentResponse Manager role you will need the following skills and experience: - Experience in a technical cyber/incidentresponse role - Previous … team management experience - Good understanding of incidentresponse frameworks and methodologies (ICERF) - Good understanding of threats, vulnerabilities and processes - Familiarity with incidentresponse tools and measures - Relevant industry certifications would be seen as advantageous (CISSP, OSCP, OSCE etc. More ❯
A leading Commerce firm is looking for an IncidentResponse Lead to join their Cyber Defence team. This crucial role will support the team in enhancing its detection capabilities and modernising the incidentresponse (IR) process across the organisation. The IncidentResponse Lead will … be responsible for managing the entire IR lifecycle, from initial triage through to remediation. Key Responsibilities: Manage end-to-end incidentresponse (IR) processes, ensuring swift and effective resolution of security incidents. Develop and maintain incidentresponse playbooks and runbooks. Analyse incident reports and provide … actionable insights. Engage with and manage stakeholders throughout the incident lifecycle. Lead the threat-hunting process, using frameworks like MITRE ATT&CK to proactively identify potential threats. Ideal Candidate: Extensive experience in all aspects of IncidentResponse, with hands-on involvement in P1 and P2 incidents (mainly More ❯
firm, including the central operations of finance, information technology, marketing, risk, legal, operations and human resources. What You'll Do As a Cyber Security IncidentResponse Manager at BCG, you will be a key member of our Cyber Security IncidentResponse Team (CSIRT), responsible for identifying … analyzing, and mitigating cyber threats. This role requires a proactive approach to threat hunting, cyber threat intelligence, and incidentresponse, ensuring the protection of BCG’s global network. You will work closely with the Security Operations Center (SOC), Security Information and Event Management (SIEM), and Managed Security Service … Provider (MSSP) to enhance detection and response capabilities. Your expertise will contribute to strengthening our security posture and minimizing business risks associated with cyber threats. * Act as a Tier 3 Incident Responder, supporting complex investigations into cyber security incidents. * Conduct proactive threat hunting to detect and neutralize emerging More ❯
firm, including the central operations of finance, information technology, marketing, risk, legal, operations and human resources. What You'll Do As a Cyber Security IncidentResponse Manager at BCG, you will be a key member of our Cyber Security IncidentResponse Team (CSIRT), responsible for identifying … analyzing, and mitigating cyber threats. This role requires a proactive approach to threat hunting, cyber threat intelligence, and incidentresponse, ensuring the protection of BCG’s global network. You will work closely with the Security Operations Center (SOC), Security Information and Event Management (SIEM), and Managed Security Service … Provider (MSSP) to enhance detection and response capabilities. Your expertise will contribute to strengthening our security posture and minimizing business risks associated with cyber threats. * Act as a Tier 3 Incident Responder, supporting complex investigations into cyber security incidents. * Conduct proactive threat hunting to detect and neutralize emerging More ❯
IT Service Providers and business stakeholders across the company to implement and optimise cyber security operations capabilities. Responsibilities Accountable for managing the Cyber Security Response team and the quality of third party services and deliverables, reviewing performance, and driving continuous improvement. Take the lead management responsibility for all cyber … security event monitoring and incidentresponse services received from all partner organisations with particular focus on the company’s Manage Security Service relationship (MSS). Proactively manage the search for cyber threats that may go undetected in our environment that have evaded our automated security tools and defences. … Accountable for Cyber Security incidentresponse management including the establishment, maintenance and improvement of cyber security incidentresponse plans, procedures, and playbooks. Manage post-incident activity to include scheduling and chairing Post Incident Reviews (PIR), the documentation of Root Cause Analysis (RCA) for security More ❯
Cyber Security IncidentResponse Lead We are working with a company that is looking for an experienced CSIRT specialist with a strong track record in high-stakes cyber incidentresponse and digital forensics to take ownership of the IR process and help drive automation across the … CSIRT team. What You’ll Be Doing: Lead end-to-end cyber incidentresponse investigations, including breach analysis, e-Discovery, and network forensics. Design, build, and maintain forensic infrastructure and incidentresponse tooling. Take ownership of cyber investigations and coordinate response efforts across teams. Run … and support cyber tabletop exercises, resilience drills, and war-gaming sessions. Monitor and analyse security alerts, coordinating swift response and resolution. Perform detailed forensic reviews and support third-party security assessments. Present incident progress, reporting clearly to senior stakeholders, and escalating when necessary. Maintain real-time dashboards and More ❯
Cyber Security IncidentResponse Lead We are working with a company that is looking for an experienced CSIRT specialist with a strong track record in high-stakes cyber incidentresponse and digital forensics to take ownership of the IR process and help drive automation across the … CSIRT team. What You’ll Be Doing: Lead end-to-end cyber incidentresponse investigations, including breach analysis, e-Discovery, and network forensics. Design, build, and maintain forensic infrastructure and incidentresponse tooling. Take ownership of cyber investigations and coordinate response efforts across teams. Run … and support cyber tabletop exercises, resilience drills, and war-gaming sessions. Monitor and analyse security alerts, coordinating swift response and resolution. Perform detailed forensic reviews and support third-party security assessments. Present incident progress, reporting clearly to senior stakeholders, and escalating when necessary. Maintain real-time dashboards and More ❯
Security IncidentResponse Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £100,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an IncidentResponse Manager within its cyber … point once a month for weekends) - Deliver on information security projects - Ensuring services provided meet the business requirements To be considered suitable for this IncidentResponse Manager role you will need the following skills and experience: - Experience in a technical cyber/incidentresponse role - Previous … team management experience - Good understanding of incidentresponse frameworks and methodologies (ICERF) - Good understanding of threats, vulnerabilities and processes - Familiarity with incidentresponse tools and measures - Relevant industry certifications would be seen as advantageous (CISSP, OSCP, OSCE etc. More ❯
London, Broad Street, United Kingdom Hybrid / WFH Options
Ashdown Group
Security IncidentResponse Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £100,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an IncidentResponse Manager within its cyber … point once a month for weekends) - Deliver on information security projects - Ensuring services provided meet the business requirements To be considered suitable for this IncidentResponse Manager role you will need the following skills and experience: - Experience in a technical cyber/incidentresponse role - Previous … team management experience - Good understanding of incidentresponse frameworks and methodologies (ICERF) - Good understanding of threats, vulnerabilities and processes - Familiarity with incidentresponse tools and measures - Relevant industry certifications would be seen as advantageous (CISSP, OSCP, OSCE etc. More ❯
Security Engineer, IncidentResponse , AWS Corporate Security Job ID: Amazon Corporate Services Pty Ltd AWS is looking for a passionate Security Engineer, IncidentResponse who can lead the response to security issues across the largest cloud provider in the world. You must thrive in high … pressure situations, and think like both an attacker and defender, while working through the entire incidentresponse lifecycle. You'll be working in a global team environment where clear and accurate communication, documentation, and collaboration on security issues is critical. In this role you'll be conducting security … monitoring and response activities for the Amazon internal network. We value broad and deep technical knowledge, specifically in the fields of operating system security, network security, cryptography, software security, malware analysis, forensics, security operations, incidentresponse, detection and hunting, and emergent security intelligence. We don't expect More ❯
to protecting our organization from evolving threats. We are looking for a skilled and passionate Senior Security Engineer to focus on Threat Detection and Response in a dynamic, hybrid cloud environment. This is a unique opportunity to lead and enhance our capabilities in detecting, investigating, and responding to security … Security Operations Team collaborates closely with cross-functional teams across the Information Security organization and external partners. We lead key initiatives, including security monitoring, incidentresponse, vulnerability management, and threat intelligence, all aimed at strengthening our security posture and ensuring resilience against emerging threats. About the role & what … you'll do: As a Senior Security Engineer specializing in Threat Detection and Response, you will be at the forefront of our security efforts, leading incidentresponse investigations, driving incidents to resolution, and implementing improvements based on lessons learned. Additionally, you will develop and automate detection and More ❯
our expanding teams. As an Information Security Engineer with a focus on development and automation, you will serve as the engineering backbone of the IncidentResponse team. Your expertise in development and automation will play a critical role in enhancing security operations and incidentresponse capabilities. … and implement automated processes for containment and remediation of affected assets, IOCs, and TTPs. Design and maintain automated workflows for efficient and effective security incident response. Collaborate with cross-functional teams to automate security-related tasks and processes, enhancing overall efficiency and accuracy. Leverage automation frameworks and scripting languages … to streamline security operations and improve incident handling capabilities. Produce detailed incident reports and security recommendations using automated reporting and analysis tools. Hold stakeholders accountable for implementing automated remediation actions and monitor their effectiveness. Provide training and guidance on leveraging automation tools for streamlined incidentresponseMore ❯
Security Engineer, AWS SOC IncidentResponse Job ID: Amazon Data Services UK Limited The Amazon Web Services Security Operations Center AWS-SOC Team manages security issues across the globe. The team is looking for a highly motivated, technically inclined individual to work as a Security Engineer. A successful … fine-tune detection rules and correlation logic to improve threat detection capabilities. Conduct in-depth investigations of security incidents, perform forensic analysis, and coordinate incidentresponse activities. Maintain and optimize security information and event management systems and other security tools used in the SOC. Collaborate with other teams … to enhance threat intelligence, improve incidentresponse procedures, and provide regular reports on security posture. A day in the life As a Security Engineer in Detections, your day revolves around safeguarding our digital assets. This position supports other AWS Security Engineers with security engineering, security operations and incidentMore ❯
You will need to login before you can apply for a job. Security Engineer, AWS SOC IncidentResponse Sector: Technology Role: Professional Contract Type: Permanent Hours: Full Time DESCRIPTION The Amazon Web Services Security Operations Center AWS-SOC Team manages security issues across the globe. The team is … fine-tune detection rules and correlation logic to improve threat detection capabilities. Conduct in-depth investigations of security incidents, perform forensic analysis, and coordinate incidentresponse activities. Maintain and optimize security information and event management systems and other security tools used in the SOC. Collaborate with other teams … to enhance threat intelligence, improve incidentresponse procedures, and provide regular reports on security posture. A day in the life As a Security Engineer in Detections, your day revolves around safeguarding our digital assets. This position supports other AWS Security Engineers with security engineering, security operations and incidentMore ❯
of cybersecurity within the organisation. You'll help build and implement the SOC within IT operations, conduct daily operations of the internal SOC including incident monitoring, analysis, and response, implement SOC procedures and best practice to ensure efficient and effective incidentresponse, and support major incidentresponse efforts and lead on incidentresponse efforts including containment, investigation, analysis, and reporting of security incidents. Your profile Experience as a SOC Analyst in an enterprise scale organisation; managing security operations incidents and events Hands-on knowledge and experience of security operations and incidentresponse planning; Cellebrite, Magnet Domain Tools Knowledge of cybersecurity principles and frameworks; ISO27001, NIST, GDPR etc. Knowledge and experience with MS Sentinel, Cisco Meraki, MS Defender, Endpoint protection Knowledge and experience with SIEM, IDS/IPS, firewalls, endpoint protection systems, and vulnerability management Knowledge and experience analysing and More ❯
Windsor, Berkshire, South East, United Kingdom Hybrid / WFH Options
Centrica
Join Centrica's IT Security Team as a Cyber Security IncidentResponse Manager! ?? Are you ready to drive the UK's energy transformation? Centrica is looking for a skilled Cyber Security IncidentResponse Manager to join our IT Security team. You'll handle cyber incident … investigations, e-Discovery, network forensics, and cyber breach inquiries. Location: Hybrid working with occasional travel to Windsor. Key Accountabilities: Carry out forensic analysis and incidentresponse investigations Build and manage forensic and incident infrastructure. Lead cyber forensic investigations. Support weekly security operations calls. Oversee resilience planning and … and remediate vulnerabilities. Analyse security reports and manage alerts. Stay updated on security policies and regulations. Experience Required: Expert in Security Operations and Security Incident Response. Expert in cyber incident investigations, e-Discovery, network forensics, and cyber breach inquiries Proficiency in SIEM, SEM, and log monitoring. Scripting/ More ❯
Bradford, West Yorkshire, Yorkshire, United Kingdom
Vanquis Bank Limited
will proactively identify, analyse, respond, and mitigate cyber threats that pose risks to Vanquis Banking Groups cybersecurity posture. This involves monitoring security events, conducting incidentresponse activities, enhancing our threat detection capabilities, and ensuring compliance with policy, standards, and regulation. Your contributions will directly impact our ability to … participate the delivery of services provided by the Cyber Intelligence Centre including by not limited to Cyber Threat Intelligence, Security Posture Management, Cyber Security IncidentResponse, Threat Hunting, Penetration Testing & Red Team Testing, and Cyber Risk Mitigation. Incorporate threat intelligence into CIC activities. Collaborate and assist with the … investigation and resolution of complex security incidents. Support the delivery of retrospective improvements based on incident analysis, RCAs and PIRs. Engage with third-party security partners to enhance and mature services. Maintain centralised processes across all VBG product lines, promoting synergy and efficiency. Stay updated on the latest cyber More ❯
leadership and capabilities. We’re looking for a Level 3 SOC Analyst to join our client's team, offering expertise in security analysis and incidentresponse to help drive the success of their Cyber Security Operations Center (CSOC). In this role, you will investigate and validate potential … mentor and uplift analyst skills and act as a key escalation point. The role will involve collaborating with global security teams, including CERT and Incident Management, to enhance overall security capabilities. Key Responsibilities: Advanced IncidentResponse: Handle escalated security incidents that L1 and L2 analysts cannot resolve … Security Reporting and Advisories: Contribute to or lead the delivery of cyber security reports and advisories to key stakeholders. Residual Risk Assessment: Deliver post-incident analysis, technical lessons learned, and reporting to assess residual risk. Advanced SIEM Tuning: Refine and tune SIEM tools to reduce false positives and detect More ❯
Cambridge, Cambridgeshire, United Kingdom Hybrid / WFH Options
Arm Limited
Role Overview: Utilising knowledge of security operations, incidentresponse, and detection engineering, you will be responsible for the delivery of SIEM detections and security automations. The successful candidate will be proficient in automation and orchestration tools (e.g., SOAR platforms, scripting languages like Python, PowerShell) and have experience with … APIs, and Case Management tools for data enrichment. Responsibilities: Build security automations, logging, and SIEM detections to improve the CDO's efficiency, scalability, and incidentresponse capabilities. Design, implement, and maintain automated workflows and playbooks to streamline CDO operations, including incidentresponse, threat hunting, cyber threat … intelligence and vulnerability management. Collaborate with CDO analysts to identify repetitive tasks and automate them to improve operational efficiency. Collaborate with Threat Intelligence, IncidentResponse, and Attack Surface Management to build and tune robust SIEM detections for both proactive and reactive response actions. Continuously evaluate automation solutions More ❯
Automation & Detection Engineer for a 6-month contract to start ASAP, based in Cambridge ( Hybrid), Inside IR35 Role Overview: Utilising knowledge of security operations, incidentresponse, and detection engineering, you will be responsible for the delivery of Microsoft SIEM detections and security automations. The successful candidate will be … of log sources into Microsoft Sentinel SIEM. Build security automations, logging, and SIEM detections to improve the Cyber Defence Operation’s efficiency, scalability, and incidentresponse capabilities. Design, implement, and maintain automated workflows and playbooks to streamline CDO operations, including incidentresponse, threat hunting, cyber threat … and vulnerability management. Collaborate with Cyber Defence Operation analysts to identify repetitive tasks and automate them to improve operational efficiency. Collaborate with Threat Intelligence, IncidentResponse, and Attack Surface Management to build and tune robust SIEM detections for both proactive and reactive response actions. Continuously evaluate automation More ❯
Automation & Detection Engineer for a 6-month contract to start ASAP, based in Cambridge ( Hybrid), Inside IR35 Role Overview: Utilising knowledge of security operations, incidentresponse, and detection engineering, you will be responsible for the delivery of Microsoft SIEM detections and security automations. The successful candidate will be … of log sources into Microsoft Sentinel SIEM. Build security automations, logging, and SIEM detections to improve the Cyber Defence Operation’s efficiency, scalability, and incidentresponse capabilities. Design, implement, and maintain automated workflows and playbooks to streamline CDO operations, including incidentresponse, threat hunting, cyber threat … and vulnerability management. Collaborate with Cyber Defence Operation analysts to identify repetitive tasks and automate them to improve operational efficiency. Collaborate with Threat Intelligence, IncidentResponse, and Attack Surface Management to build and tune robust SIEM detections for both proactive and reactive response actions. Continuously evaluate automation More ❯
Loughton, Essex, South East, United Kingdom Hybrid / WFH Options
Profile 29
business strategy, gap analysis and implementation, for securing their Azure-based infrastructure, integrating security automation, ensuring PCI DSS compliance, vulnerability and penetration testing and incident response. This role will focus on developing and maintaining secure, scalable Azure DevOps pipelines and Infrastructure as Code (IaC) using Terraform. Their ideal candidate … Leverage Azure Security Centre, Microsoft Defender for Cloud, and Microsoft Sentinel for advanced security monitoring. Threat Detection & SOAR Automation: Oversee Security Orchestration, Automation, and Response (SOAR) solutions including SOC Prime. Network & Application Security: Manage Web Application Firewalls (WAF) and Intrusion Prevention Systems (IPS). Vulnerability & Penetration Testing: Review Penetration … PCI DSS Compliance: Conduct security audits, risk assessments, and ensure regulatory compliance. DNS Security: Implement and monitor DNS security solutions to prevent cyber threats. IncidentResponse: Formulating and documenting a solid process utilising a 3rd party support partner Security Monitoring & Logging: Develop SIEM solutions, logging strategies, and real More ❯
Employment Type: Contract, Work From Home
Rate: From £500 to £700 per day (direct contract with the client)
Loughton, Essex, South East, United Kingdom Hybrid / WFH Options
Profile 29
business strategy, gap analysis and implementation, for securing their Azure-based infrastructure, integrating security automation, ensuring PCI DSS compliance, vulnerability and penetration testing and incident response. This role will focus on developing and maintaining secure, scalable Azure DevOps pipelines and Infrastructure as Code (IaC) using Terraform. Their ideal candidate … Leverage Azure Security Centre, Microsoft Defender for Cloud, and Microsoft Sentinel for advanced security monitoring. Threat Detection & SOAR Automation: Oversee Security Orchestration, Automation, and Response (SOAR) solutions including SOC Prime. Network & Application Security: Manage Web Application Firewalls (WAF) and Intrusion Prevention Systems (IPS). Vulnerability & Penetration Testing: Review Penetration … PCI DSS Compliance: Conduct security audits, risk assessments, and ensure regulatory compliance. DNS Security: Implement and monitor DNS security solutions to prevent cyber threats. IncidentResponse: Formulating and documenting a solid process utilising a 3rd party support partner Security Monitoring & Logging: Develop SIEM solutions, logging strategies, and real More ❯