1 to 25 of 59 Incident Response Jobs in Manchester

Cyber Response & Recovery - Manager (Remediation focus)

Hiring Organisation
KPMG
Location
Manchester, UK
Employment Type
Full-time
Cyber Response & Recovery Manager (Remediation)This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the roleThe Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG's Cyber Advisory practice. Your specific focus will … compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience. This ...

Director, Digital Forensics & Incident Response (Global)

Location
Manchester, England, United Kingdom
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group’s global Digital Forensics … Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. ...

Information Security Engineer

Hiring Organisation
Freshfields Bruckhaus Deringer
Location
Manchester, UK
Employment Type
Full-time
Aside from infrastructure, the candidate should have experience and working knowledge of SIEM and vulnerability management platforms. The role will cover elements of cyber incident response, so a background in supporting a wider incident response function is a necessity. Key ResponsibilitiesCloud Security Assessment & Advisory: Assess … Azure IaaS and Google Cloud environments, including infrastructure. Provide recommendations based on industry best practices and emerging security threats. The ability to provide Cyber Incident Responders subject matter expertise in Cloud security when required. Defender & Security Monitoring Advisory: Evaluate and optimise the use of Azure Defender and other security ...

Senior Security Specialist

Hiring Organisation
Reonomy
Location
Manchester, UK
Employment Type
Full-time
security operations, expanding our offensive security capabilities, and improving how we detect and respond to emerging threats. Working across security engineering, threat intelligence, incident response, and cloud security, you will identify opportunities to improve detection, automate processes, mature security technologies, and strengthen our overall security posture. This … Security Operations and technology teams to drive continuous improvement. Work across the full spectrum of modern cybersecurity. From security engineering and cloud security to incident response, threat intelligence, automation, and offensive security, this role offers technical breadth. You will solve complex security challenges, improve detection and response ...

Security Consultant

Hiring Organisation
Version 1
Location
Manchester, UK
Employment Type
Full-time
define pragmatic remediation roadmaps aligned to business priorities. Lead and support security architecture reviews across cloud, applications, infrastructure, IAM, data protection and detection/response domains. Provide expert consulting to customers on security strategy, risk reduction, control design, and security operating model improvements. Challenge weak security assumptions with confidence … guardrails. Partner with engineering, platform, DevOps and operations teams to embed security into delivery pipelines and infrastructure as code practices. Support threat detection, incident response readiness, use-case tuning, and post-incident improvement activities. Contribute to security standards, policies, patterns, reusable accelerators, and client-facing deliverables including ...

Database Platform Manager

Location
Manchester, England, United Kingdom
fleet reliability and SLOs. This role is weighted toward hands-on technical depth. You should be as credible in a design review or an incident bridge as you are in a planning session with senior stakeholders. Key Responsibilities Technical direction The technical roadmap for the estate. We want someone … performance, high availability and disaster recovery, patching, and backup and recovery Senior escalationpointfor complex L3 work: performance and query tuning, replication and failover, major incident response and post-incident review Automation, infrastructure as code and database CI/CD, with everything in GitHub under proper change management ...

Cyber Security Analyst

Hiring Organisation
The Portfolio Group
Location
Manchester, United Kingdom
Employment Type
Permanent
Salary
£50000 - £55000/annum
infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service … with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will ...

Global DFIR Director: Lead Cyber Incident Excellence

Location
Manchester, England, United Kingdom
Group plc seeks a Director, Digital Forensics & Incident Response (Global) to lead the global DFIR capability, setting strategic direction and ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The role requires driving operational excellence, collaborating with NCC Group leaders … expanding security services through incident response opportunities. #J-18808-Ljbffr ...

Cloud Security Engineer - Manchester - National Security West

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£95,000
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Cloud Security Engineer - London - National Security West

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£95,000
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Cloud Security Engineer – London – National Security West

Hiring Organisation
BAE Systems
Location
Manchester, United Kingdom
Employment Type
Full Time
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Product Security Engineer

Location
Manchester, England, United Kingdom
real control rather than a manifest scan, build-pipeline isolation, third-party risk as runtime telemetry. When the next big supply-chain incident lands, we should know within hours whether it touches us. Detect, respond, contain Runtime detection that catches what actually happens, not what a vendor template guesses … might. Incident response codified as automation: containment, rotation, isolation, evidence capture. Forensics tooling that works on our stack. Adversary emulation against our real attack surface. The metric is mean-time-tocontain, not control coverage. Secure the agentic development surface Our engineers ship with AI agents in the loop ...

WAF Security Engineer

Location
Manchester, England, United Kingdom
code approaches Contribute to platform modernisation, service improvements, refactoring, automation and technical-debt reduction Improve monitoring, alerting and telemetry to strengthen platform reliability and incident response Support diagnosis and resolution of major incidents with Security Engineering, Network and Cloud teams Embed secure-by-design patterns and guardrails Produce … including design, implementation, and optimization of security controls. Proficient in Infrastructure as Code, CI/CD pipelines, and automation to enhance platform reliability and incident response. Highest-signal resume keywords Web Application Firewall (WAF) Technologies Infrastructure as Code (IaC) CI/CD Pipelines Application Security Python Scripting Hard Skills ...

Platform Engineer, Azure Infrastructure

Location
Manchester, England, United Kingdom
compliance Collaborate with developers to improve CI/CD pipelines, deployment strategies, and overall developer experience Enhance observability and reliability, refining alerting, monitoring, and incident response Collaborate on cloud optimization projects, improving performance, cost efficiency, and security posture Mentor and guide team members, fostering a culture of technical … compliance Collaborate with developers to improve CI/CD pipelines, deployment strategies, and overall developer experience Enhance observability and reliability, refining alerting, monitoring, and incident response Collaborate on cloud optimization projects, improving performance, cost efficiency, and security posture Mentor and guide team members, fostering a culture of technical ...

Senior SOC Analyst - Manchester

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
Salary
£95,000
/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance … using the Protective Monitoring platform and Internet resources to identify cyber-attacks/security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. ...

SRE Managing Consultant - Cloud Operating Model

Location
Manchester, England, United Kingdom
Model & Ways of Working**: Define and implement SRE ways of working and engagement patterns, aligning reliability practices with existing ITSM/ITIL processes (e.g., incident, problem, release and change) and modern engineering delivery.* **Reliability Measures (SLIs/SLOs) & Error Budgets**: Establish service measures and targets (SLIs/SLOs … Insight:** Shape observability approaches (metrics/logs/traces) and operational monitoring models that make reliability risks visible and actionable, improving operational decision-making.* **Incident Excellence & Continuous Learning:** Design incident analysis and improvement loops, including practical approaches that strengthen incident response and drive learning through post ...

SOC Analysts - L2 and L3 (SC and DV-Cleared)

Hiring Organisation
Pigment Consulting
Location
Manchester, North West, United Kingdom
Employment Type
Contract
Investigation of phishing, malware, credential compromise and suspicious activity. Supporting containment, eradication and recovery. Developing and improving detection rules and playbooks. Producing high-quality incident documentation and reports. Supporting and mentoring Tier 1 analysts. Tier 3 SOC Analyst As a Tier 3 Analyst, you'll provide advanced technical investigation … senior escalation point for complex incidents. Responsibilities include: Leading complex and high-severity security investigations. Advanced threat hunting and incident response. Malware, endpoint, network and forensic investigation. Developing advanced detections and response capabilities. Root-cause analysis and post-incident investigation. Supporting major incident response. Working closely ...

Vice President, Production Services Application Support

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
coverage across on-site and offshore support hours. Use SQL scripting, automation, monitoring, and observability tools to improve operational resilience, service health, reliability, and incident response. To be successful in this role, we're seeking the following: Excellent SQL scripting skills. Strong scripting and automation skills using languages such … Proven skills and track record in AI automation, including the use of intelligent automation capabilities to reduce manual effort, improve operational efficiency, and enhance incident response workflows. Experience applying AI and automation solutions for alert correlation, anomaly detection, predictive monitoring, and service optimisation. Strong understanding of Site Reliability ...

Junior Cyber Security Analyst

Hiring Organisation
The Portfolio Group
Location
Manchester, United Kingdom
Employment Type
Permanent
Salary
£35000/annum
first security stack already in place, it is an exciting time to join the business and learn your craft as we mature our detection, response, and automation capabilities across a global estate. You will work alongside the wider IT team - Infrastructure, Network, Development, DevOps, and Service Desk - gaining … understanding of how security supports the business. The purpose of this role is to build a working knowledge of security operations, protective monitoring, and incident handling by working closely with, and learning from, the wider InfoSec team. Reporting to the Associate Director - Cyber Security, with day-to-day guidance ...

Senior Security Engineer

Location
Manchester, England, United Kingdom
many of these technologies/areas as possible is highly desirable: Security Frameworks (NIST, CIS etc.) PAM Tools and Technologies AWS Security Incident Response Endpoint Security (including mobile devices, Windows and Linux) Job Benefits We have a high-performance culture which is balanced evenly with world-class well ...

Software Engineering Manager

Hiring Organisation
Drive Further
Location
Cheadle, England, United Kingdom
C#, Angular, SQL Server Stay hands-on when needed: design, code, pair, review PRs, unblock the team Drive quality, reliability and security: testing approach, incident response, post-incident improvements Hire, onboard and develop engineers (including onshore/offshore collaboration) What we need from you 8+ years building ...

Service Reliability Engineer - Manchester

Hiring Organisation
Fitch Group
Location
Manchester, United Kingdom
Employment Type
Full Time
driven automation and blameless postmortems. Champion AI‐enabled operations using AWS Bedrock/SageMaker and Model Context Protocol (MCP) for log analysis, anomaly detection, incident triage, and workflow orchestration; establish adoption guardrails. Define and enforce cloud guardrails and security controls (SCPs/IAM boundaries, OPA policies, tagging, centralized logging … core infrastructure fundamentals (networking, storage, DNS) and APM/telemetry tooling. What Would Make You Stand Out: Practical experience with agentic AI for operations—incident triage, runbooks, and change management—with clear guardrails, auditability, and human-in-the-loop controls. Supporting AI/ML workloads at scale: SageMaker endpoints ...

Senior Cloud Engineer, AI Platform SRE

Location
Manchester, England, United Kingdom
prompt and configuration changes, with automated eval and regression checks before promotion. Reliability engineering: Define and track SLOs and SLAs for platform services, run incident response and root cause analysis, and write post-mortems people will read. On-call and runbooks: Take part in the programme … GitLab CI, Argo CD, Jenkins or similar. Observability: Hands‐on with Datadog, Prometheus, Grafana or OpenTelemetry, and opinionated about what's worth alerting on. Incident management: Calm, methodical instincts under pressure, and a habit of fixing the class of problem rather than the instance. AI and ML operations: Experience ...

NMC Cyber Detect Analyst

Hiring Organisation
Police Digital Services
Location
Wigan, Greater Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Services and provides visibility and control of information risks for policing. It supports the 24x7x365 nature of police operations, providing a threat detection and response capability for digital services before, during and after cyber-attacks, enabling stakeholders to understand and proactively manage risk across the technology estate at both … edge technology and a strong set of processes. The NMC Cyber Detect Analysts will work closely with teams across the NMC, typically with the Incident Response Teams to ensure security issues are addressed quickly upon discovery. NMC Cyber Detect Analyst duties involve but are not limited to: Initial ...

Senior Security Engineer (GCP)

Location
Manchester, England, United Kingdom
engagements across the full stack — from greenfield SIEM/SOAR deployments and SOC modernisation programmes to detection engineering, posture management, threat hunting, and incident response uplift. Secure GCP estates with the adoption of CI/CD pipelines, secure landing zones and cloud posture reviews. Expertise when integrating third ...