1 to 25 of 1,764 Incident Response Jobs in the UK

Senior / Lead Incident Response Engineer

Location
Greater London, England, United Kingdom
Title: Senior/Lead Incident Response Engineer Type: Permanent Location: London – Hybrid The Opportunity We are working with a leading, technology-driven financial services organisation to appoint two Senior/Lead Incident Response Engineers on a permanent basis. These are senior-level positions within a highly … sophisticated cybersecurity environment, suited to candidates who have built their careers in cybersecurity engineering and have subsequently developed deep expertise in incident response and major incident management. The organisation is looking for individuals who have already operated through large-scale, high-impact and business-critical cyber incidents ...

Cyber Response & Recovery Manager (Reactive DFIR) - German Speaking

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice. Your specific … focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands-on incident response role and an opportunity to join a high performing team that works with a wide ...

Cyber Defense Incident Responder - Associate Director

Location
Greater London, England, United Kingdom
responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

Location
Greater London, England, United Kingdom
Senior Manager, Global Cyber Security Incident Response (Global CSIRT) Location: London About the role KPMG International sets strategy, supports collaboration and protects the reputation of a global network of independent professional services firms. Within Global Digital, the Global Information Security Group provides trusted security services that support KPMG … digital transformation and help protect the network and its clients from cyber threats. The Global Cyber Security Incident Response Team forms part of Information Security Services and works alongside the Global Security Operations Centre to detect, investigate and support the remediation of potential threats. In this senior operational ...

Senior Incident Response Consultant 2

Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

Incident Response Lead

Hiring Organisation
Morson Edge
Location
Glasgow, Lanarkshire, Scotland, United Kingdom
Employment Type
Contract, Work From Home
Incident Response Lead Scottish Power HQ, Glasgow Flexible & Hybrid working pattern Negotiable rate, Inside IR35, PAYE and UMB options available Help us create a better future, quicker SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations … deliver a cyber resilient business and the Incident Response Lead is essential in achieving our goals. This role will be integrated into an active and ambitious global cyber security function, contributing to SPEN's cyber security purpose of delivering cyber resilient OT and IT, to enable a safe ...

Cyber Defense Incident Responder

Location
Greater London, England, United Kingdom
responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Head of Cyber Defence & Incident Response London - United Kingdom - Full Time

Location
Greater London, England, United Kingdom
Head of Cyber Defence & Incident Response At Quadient, we support businesses of all sizes in their digital transformation and growth journey, unlocking operational efficiency with reliable, secure, and sustainable automation processes. Our success in delivering innovation and business growth is inspired by the connections our diverse teams create … business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection ...

Senior Incident Response Consultant, Rapid Response

Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

SOC and Incident Response Lead

Location
City Of London, England, United Kingdom
need any adjustments throughout the process in whatever way works best for you. Job Description The Role As an experienced SOC and Incident Response Lead at ASOS, you will provide hands-on technical leadership across security monitoring, detection, engineering, incident response, and threat-led investigations. … will lead the SOC and Incident Response team, ensure security incidents are investigated and resolved effectively, and maintain a strong operating relationship with our external MSSP. The ideal candidate will combine deep technical expertise with proven experience leading analysts, improving operational capability, managing stakeholders, and making sound decisions ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection … response and recovery. Reports directly to the CISO and leads cyber defence operations (including the MSSP) and cybersecurity incident response across the organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology. A key focus is optimising security tooling (e.g., SIEM ...

Associate/Senior Associate - Data & Cyber

Location
West of England, England, United Kingdom
Data & Cyber team advises a wide range of clients across a variety of industry sectors on cyber incidents, regulatory response, technology and data-related claims, and cyber/technology insurance coverage. We are recognised for combining deep cyber incident response capability with a strong understanding … insurance market, enabling us to support clients across the lifecycle of a cyber event and its downstream exposures: from immediate breach response and crisis management, through policy notification and coverage strategy, to regulatory engagement and dispute resolution. The role Based in Bristol, the Associate (1-4 years ...

Regional CERT Manager

Location
Kingston, England, United Kingdom
planet. That’s why our purpose is ‘to make sustainable living commonplace’ Role Overview The Regional CERT Manager is responsible for leading cyber incident response operations across the region, ensuring effective detection, containment, investigation, remediation, and recovery from security incidents. This role combines strategic leadership with hands … technical expertise to drive operational excellence, strengthen security capabilities, and enhance organisational cyber resilience. Key Responsibilities Lead regional Cyber Emergency Response Team (CERT) operations, providing both strategic direction and technical guidance for complex cyber security incidents. Own and continuously improve the end‐to‐end Incident Management lifecycle, ensuring ...

SOC Analyst - SC Cleared

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£545 - £590 per day + Inside IR35
environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams. You will … cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions. Key Responsibilities Security Monitoring & Incident Response Monitor and triage security alerts generated through SIEM and security tooling. Investigate and respond ...

DFIR Managing Consultant

Location
Manchester, England, United Kingdom
Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Role Purpose: To manage and service NCC Group clients within the Incident Response space. The Managing Consultant plays a critical role within the DFIR team of experienced consultants, delivering high‐quality incident response and proactive services to clients. The role involves leading and contributing to detailed technical analysis, managing incident response activities, and ensuring effective communication and coordination throughout an engagement. With a strong focus on technically supporting clients during live incidents, the Managing Consultant is also expected to contribute ...

Cyber Incident Operations Lead

Hiring Organisation
Appcast
Location
Glasgow, UK
Cyber Incident Operations LeadSalary: 59-74K (plus up to 15% bonus, 15% pension and private healthcare)Location: Glasgow (hybrid, 2-3 days in the office)Permanent, Full time**Due to the nature of the role, the successful candidate will need to be able to obtain NSV SC clearance … years before being eligible to meet the Minimum Residency Criteria**Help us create a better future, quickerWe are looking for an experienced Incident Response Lead to play a critical role in strengthening and evolving SPR’s cyber defence capability across complex IT and Operational Technology (OT) environments. Working ...

Security analyst - Sector security

Location
Manchester, England, United Kingdom
users across universities, colleges and research organisations. Combining cutting-edge security technologies, threat intelligence and specialist expertise, we provide 24/7 protection, rapid incident response and advanced threat detection to help our members stay secure and resilient. Security Centre brings together Cyber Security Incident Response (CSIRT), Digital Forensics and Incident Response (DFIR), SIEM Analysts and Network Defensive Services specialists. Working at the forefront of cyber defence, we identify and respond to threats, support organisations through cyber incidents, conduct threat hunting activities and continuously evolve our capabilities to stay ahead of emerging risks. ...

Security analyst - Sector security

Location
Oxford, England, United Kingdom
users across universities, colleges and research organisations. Combining cutting-edge security technologies, threat intelligence and specialist expertise, we provide 24/7 protection, rapid incident response and advanced threat detection to help our members stay secure and resilient. Security Centre brings together Cyber Security Incident Response (CSIRT), Digital Forensics and Incident Response (DFIR), SIEM Analysts and Network Defensive Services specialists. Working at the forefront of cyber defence, we identify and respond to threats, support organisations through cyber incidents, conduct threat hunting activities and continuously evolve our capabilities to stay ahead of emerging risks. ...

Security analyst - Sector security

Location
West of England, England, United Kingdom
users across universities, colleges and research organisations. Combining cutting-edge security technologies, threat intelligence and specialist expertise, we provide 24/7 protection, rapid incident response and advanced threat detection to help our members stay secure and resilient. Security Centre brings together Cyber Security Incident Response (CSIRT), Digital Forensics and Incident Response (DFIR), SIEM Analysts and Network Defensive Services specialists. Working at the forefront of cyber defence, we identify and respond to threats, support organisations through cyber incidents, conduct threat hunting activities and continuously evolve our capabilities to stay ahead of emerging risks. ...

Incident Response Specialist

Hiring Organisation
Adecco
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Full-Time
Salary
£700.00 per day
take your cyber security expertise to the next level? Our client, a leader in the energy sector, is on the lookout for an Incident Response Specialist to join their dynamic cyber security team. Role: Incident Response Specialist Duration: 6 Months (ext. options) Location: Warwick (Hybrid … mindset, promoting shared responsibility among Security Operations teams. Your contributions will be vital in defending against an ever-evolving threat landscape. Key Responsibilities Include: Incident Response: Triage and manage high-priority incidents while ensuring appropriate responses are executed. Produce clear incident summaries quickly and adapt your communication ...

Incident Response Specialist

Hiring Organisation
Adecco
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Contract
Contract Rate
£700/day
take your cyber security expertise to the next level? Our client, a leader in the energy sector, is on the lookout for an Incident Response Specialist to join their dynamic cyber security team. Role: Incident Response Specialist Duration: 6 Months (ext. options) Location: Warwick (Hybrid … mindset, promoting shared responsibility among Security Operations teams. Your contributions will be vital in defending against an ever-evolving threat landscape. Key Responsibilities Include: Incident Response: Triage and manage high-priority incidents while ensuring appropriate responses are executed. Produce clear incident summaries quickly and adapt your communication ...

Lead Security Operations Center Analyst (f/m/d)

Location
Reading, England, United Kingdom
overseeing workload prioritisation, SOC reporting, and the successful delivery of projects associated with SOC tooling, automation, compliance, and operational maturity. This role encompasses reactive incident response, proactive detection engineering, threat hunting, vulnerability management, and operational leadership. You will also contribute to strategic initiatives including penetration testing coordination, security … logs, API configurations and traffic, container environments, network data, application and infrastructure architecture, as well as data center hosting environments to support threat detection, incident investigation, and root cause analysis. Manage complex cybersecurity incidents end to end, including containment, eradication, recovery, and post-incident analysis, while coordinating closely ...

Senior SOC Analyst - Incident Response

Location
Greater London, England, United Kingdom
enable GHD to deliver for clients and communities around the world. As cyber threats become more sophisticated and connected environments grow in complexity, effective incident response depends on more than technology alone. At GHD, we combine disciplined investigation, practical judgement and close collaboration to understand threats quickly, contain … enable GHD to deliver for clients and communities around the world. As cyber threats become more sophisticated and connected environments grow in complexity, effective incident response depends on more than technology alone. At GHD, we combine disciplined investigation, practical judgement and close collaboration to understand threats quickly, contain ...

Senior SOC Analyst - Incident Response

Location
North East, England, United Kingdom
enable GHD to deliver for clients and communities around the world. As cyber threats become more sophisticated and connected environments grow in complexity, effective incident response depends on more than technology alone. At GHD, we combine disciplined investigation, practical judgement and close collaboration to understand threats quickly, contain … enable GHD to deliver for clients and communities around the world. As cyber threats become more sophisticated and connected environments grow in complexity, effective incident response depends on more than technology alone. At GHD, we combine disciplined investigation, practical judgement and close collaboration to understand threats quickly, contain ...

Threat Response Technology and Capabilities Product Owner

Hiring Organisation
Appcast
Location
Ringwood, Hampshire, UK
networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential.Title and SummaryThreat Response Technology and Capabilities Product OwnerOverviewThe Corporate Security Threat and Response Management product ownership team is looking for a Lead Security Engineer to help drive … ideal candidate is passionate about the modern security tools, capabilities, and strategies.As a Product Owner, you will be defining, owning, and driving the incident response technology and capability strategy across global Security Operations. This role sets the vision for response tooling, automation, AI augmentation, and digital evidence ...