101 to 125 of 1,764 Incident Response Jobs in the UK

Senior Cyber Threat Intelligence Analyst

Location
Portsmouth, England, United Kingdom
could impact Babcock's people, information, systems, programmes and customers. You will transform complex threat data into actionable intelligence that supports proactive cyber defence, incident response, vulnerability management and risk reduction activities across the organisation. Day-to-day, you'll work closely with Security Operations, Incident Response … threat intelligence to support proactive cyber defence activities. Analysing threat actor activity, malware campaigns, phishing threats and emerging cyber risks. Collaborating with Security Operations, Incident Response and Security Assurance teams to improve cyber resilience. Creating high-quality intelligence assessments and reports that support business decision-making. Monitoring ...

Senior Cloud Security Engineer, GCP

Location
Greater London, England, United Kingdom
growing environments Perform security assessments, audits, threat modelling and architecture design reviews Identify and triage risks and vulnerabilities, and design corrective security controls Lead incident response, including investigation and remediation of security breaches Support security awareness and training programs Advocate the DevSecOps mindset across technology teams Collaborate with … Ability to identify security gaps and create risk‐minimising solutions Proactive approach to staying updated with security threats and vulnerabilities Thorough understanding of the incident response process Desirable: network security, TCP/IP, BGP, VPNs, firewalls, WAFs, IDS/IPS and hybrid GCP/on‐premise connectivity Desirable ...

IS Applications Lead

Location
West of England, England, United Kingdom
capability/controls, with ongoing maturity assessments Conduct security due diligence assessments on any new/changed IS services impacting the business Conduct Cyber Incident Response testing in collaboration with team Support cyber incident response/investigations Oversee service provisioning and hosting of internal LoB apps …/release management Maintain apps (including SAP) build/support documentation (including Service Catalogue), drawing on outsourced providers Provide Master Data Management Handle major incident response (Apps, including SAP) Manage outsourced Apps support contract performance/resources, directing and supervising as required Act as the "glue" to connect ...

Cyber Incident Responder - OT Technology

Location
West Midlands, England, United Kingdom
from the ground up. This is a foundational role within a well-established Security Operations function, offering genuine ownership over strategy, tooling, governance and incident response for OT/IoT environments. You'll work cross-functionally with Threat Intelligence, Incident Response, Vulnerability Management, GRC and Security … Architecture, as well as engineering and site teams, to embed proportionate, pragmatic security controls across operational environments — while also playing a key role in incident response when OT/IoT-related incidents occur. Key Responsibilities Build and develop the organisation's OT/IoT security capability from ...

Senior / 3rd Line IT Engineer - Infrastructure & Cyber Security

Hiring Organisation
Appcast
Location
Colchester, Essex, UK
EnablementYour Background/Skills: 3rd Line Engineering, IT Infrastructure, Cyber Security, Azure, Google Workspace, Networking, CrowdStrike, Cisco, VMware vSphere, Windows Server, Jamf, Intune, Incident Response, Cyber Essentials, AI ToolingWho We AreBulk is on an incredible journey, with a mission to evolve from a manufacturing-led retailer into … security aspects of AI integration and take a leading role in our Cyber Essentials project next year.You'll also oversee infrastructure, security tooling, incident response, budgeting and contracting, while becoming a Tier 3 escalation point for complex issues that need deeper technical expertise.And we're not expecting ...

Principal Software Engineer-AI

Location
Greater London, England, United Kingdom
agentic runtime, auth, data retrieval, eval tooling) Experience running AI systems in production at scale, including observability, cost and capacity planning, regression detection, and incident response for AI-powered applications Experience operating production distributed systems on AWS/Azure, with a strong grasp of reliability, observability, and incident response at scale Deep knowledge of cloud-native technologies, serverless applications, event-driven architectures, data and inference pipelines, relational, NoSQL, and vector databases, and modern software architecture patterns Proven track record of owning multi-year technical strategy and architectural roadmaps, guiding teams from AI prototype through production deployment ...

Head of Information Security

Location
Greater London, England, United Kingdom
across core infrastructure Serve as the technical security authority in customer procurement reviews, vendor risk assessments, and defense customer evaluations Build and manage internal incident response capabilities, continuous monitoring, vulnerability management, and employee security awareness programs Requirements Ambitious, technical security leader Experience suitable for a Senior Security Manager … penetration testing, red teaming, and threat modeling Experience with customer procurement reviews, vendor risk assessments (DDQs), and defense customer evaluations Experience building and managing incident response, continuous monitoring, vulnerability management, and employee security awareness programs Core Competencies Demonstrates expertise in Zero-Trust security frameworks, compliance standards such ...

Engagement Manager

Location
City Of London, England, United Kingdom
with prominent global insurance carriers, leading law firms, and Fortune 1000 businesses. The Engagement Manager oversees complex client engagements related to cybersecurity, digital forensics, incident response, and post-breach remediation. This leadership role focuses on managing the entire client lifecycle, from initial engagement and strategy development to project … suite" executives, legal counsel, and boards of directors. Strategic advisory: Provide expert guidance on cyber resilience, digital risk identification, risk mitigation strategies, and incident response planning. Help clients navigate complex technical, legal, and regulatory landscapes. Project oversight: Supervise digital forensics and incident response teams, ensuring that ...

Senior Cyber Threat Detection and Response Analyst

Hiring Organisation
Appcast
Location
Todmorden, West Yorkshire, UK
Title: Senior Cyber Threat Detection and Response AnalystLocation: Any of our main UK locations + Hybrid Working ArrangementsCompensation: Competitive + BenefitsRole Type: Full time/PermanentRole ID: SF75113At Babcock we’re working to create a safe and secure world, together, and if you join us, you can play your … part as a Senior Cyber Threat Detection and Response Analyst at any of our main UK locations.The roleAs a Senior Cyber Threat Detection and Response Analyst, you’ll be a technical leader within our Cyber Security Operations capability, driving advanced threat detection, cyber defence, incident response ...

Senior Cyber Threat Detection and Response Analyst

Location
Portsmouth, England, United Kingdom
Title: Senior Cyber Threat Detection and Response Analyst Location: Any of our main UK locations+ Hybrid Working Arrangements Compensation: Competitive + Benefits Role Type: Full time/Permanent Role ID: SF75113 At Babcock we’re working to create a safe and secure world, together, and if you join … play your part as a Senior Cyber Threat Detection and Response Analyst at any of our main UK locations. The role As a Senior Cyber Threat Detection and Response Analyst, you’ll be a technical leader within our Cyber Security Operations capability, driving advanced threat detection, cyber defence ...

SOC Level 2 Security Analyst

Hiring Organisation
Appcast
Location
Birmingham, UK
detection, investigation, and management of security alerts and incidents escalated from SOC Analyst (L1) teams. The position focuses on in‐depth analysis, incident validation, tactical response coordination, and continuous improvement of security monitoring and response capabilities. Operating within a 24/7 Security Operations Centre … with internal IT and security teams as well as customers to contain and remediate security incidents. The role contributes directly to improving detection quality, response efficiency, and the overall effectiveness of SOC operations. What you'll be doing: You will investigate security alerts and events escalated from Level ...

Cyber Operations Analyst - Internal Applicants Only

Location
Greater London, England, United Kingdom
traditional relationship and service-led banking powered by modern technology. Job Purpose Support the Bank's operational cyber security capability through cyber security monitoring, incident response coordination, vulnerability management, supplier assurance and operational reporting activities. To place the interests of customers at the centre of all activities … Conduct Rules. Job Description Key Responsibilities: Support the day-to-day oversight of outsourced cyber security services, including Managed Detection and Response (MDR), Security Operations Centre (SOC) and threat monitoring providers. Coordinate cyber security alerts, incidents and escalations, ensuring actions, decisions and outcomes are appropriately recorded and tracked. ...

Product Engineer, Cloud Security (Multiple Levels)

Location
Belfast City District, Northern Ireland, United Kingdom
implementation through deployment and production support and are accountable for the reliability, adoption, and effectiveness of cloud security controls, including their role in incident detection, response, and recovery. Key Responsibilities: Design, build, andoperatecloud‐nativesecurity controls as software products across cloud infrastructure, data platforms, and application services Engineer andmaintaincloud …/CD pipelines, and shared enterprise services Integrate cloud security controls with SIEM and security tooling to generatehigh‐qualitysignals for detection, investigation, and incident response Support incident handling and response by engineering detection logic, automation, and response mechanisms that improve containment and recovery Apply modern ...

SOC Shift Lead

Hiring Organisation
Anson Mccade
Location
South West London, London, United Kingdom
Employment Type
Permanent
Salary
£85,000
incidents while leading, mentoring and developing SOC Analysts on shift. Youll act as a key escalation point for complex and high-severity incidents, supporting incident containment, remediation and recovery while providing leadership across the SOC. What youll be doing Leading the SOC team during your assigned shift and handling … escalations Investigating and responding to medium and high-severity security incidents Supporting incident containment, remediation and recovery Mentoring, teaching and upskilling junior SOC Analysts Supporting threat hunting, detection improvement and incident response activities What were looking for 6+ years experience across SOC, Incident Response ...

SOC Shift Lead

Location
Hillingdon, West London, United Kingdom
incidents while leading, mentoring and developing SOC Analysts on shift. Youll act as a key escalation point for complex and high-severity incidents, supporting incident containment, remediation and recovery while providing leadership across the SOC. What youll be doing Leading the SOC team during your assigned shift and handling … escalations Investigating and responding to medium and high-severity security incidents Supporting incident containment, remediation and recovery Mentoring, teaching and upskilling junior SOC Analysts Supporting threat hunting, detection improvement and incident response activities What were looking for 6+ years experience across SOC, Incident Response ...

Senior Executive, Operational Resilience

Location
Greater London, England, United Kingdom
track findings and actions to closure Test and validate impact tolerances, analyze results and produce remediation plans Develop, test and refine Business Continuity Management, Incident and Crisis Management, and Incident Response Plans Coordinate scenario testing, stress testing and crisis simulations Monitor regulatory developments and translate requirements into … operations, IT and business stakeholders Deliver operational resilience awareness training and communications Maintain IBS and impact tolerance records, test reports, BCM/crisis/incident plans, third-party assessments, MI packs, audit evidence, incident registers and training records Requirements 4+ years of experience in managing business continuity ...

Senior SOC Analyst (24/7 Shift) - Public Sector

Location
Hursley, England, United Kingdom
skills and technical expertise to drive innovation and adoption of new technology. Your role and responsibilities As a Technical Consultant specialising in Threat Detection, Response & Intelligence, you will support and lead the monitoring, detection, and initial response to cyber security threats within a 24×7 SOC consulting environment. … will play a key role in maintaining operational excellence on shift, supporting incident investigation, and ensuring consistent delivery of high-quality security operations across client environments. Working across SIEM platforms, security tooling, and incident response workflows, you will help ensure threats are identified, triaged, and escalated effectively ...

Information Security & Assurance Officer

Location
Ipswich, England, United Kingdom
robust Information Security Management System (ISMS) aligned to ISO/IEC 27001. You will act as the central authority for information security governance, incident management and continuous improvement across the organisation. What You'll Be Doing Governance & Compliance: Implement and enforce client ISMP requirements across GSA, including security assurance … core IT controls, including identity and access management, MFA, endpoint protection, logging, monitoring and baseline security configuration across office and operational locations. SOC Integration & Incident Management: Oversee security monitoring, log availability, alerting and incident response processes, ensuring effective integration with the client SOC and any managed security ...

Security Operations Manager

Location
Greater London, England, United Kingdom
their business. Job Description This is a hands-on leadership role. You need to be technical, in the detail, and able to lead an incident bridge. You will run a global function and own Security Operations end to end: the SOC, incident response, detection engineering and threat … intelligence, along with the people and platforms behind them. THE CHALLENGE: Own incident response. Preparation, triage, containment, eradication, and the post-incident reviews that make the next incident smaller. You will lead major incidents personally and set the standard for what good looks like. Build ...

Vice President, Threat and Vulnerability Management Team Lead

Location
City Of London, England, United Kingdom
associated post-deployment check-outs.* Triage vulnerabilities into “Fix, Acknowledge, and Investigate” categories using industry-aligned risk rating methodologies.* Use ServiceNow Application Vulnerability Response (AVR) and Vulnerability Response (VR) modules to manage and report on vulnerabilities and violations across the estate, integrating with dashboards and workflows for visibility … scanning, penetration testing, and security awareness training.* Proficiency in using vulnerability scanning tools (e.g. Tenable, Qualys, Rapid7, Veracode, JFrog Xray), threat intelligence platforms, and incident response tools.* Prior experience implementing automated solutions for vulnerability scanning, threat detection, and incident response, with a focus on continuous process ...

Cyber Response & Recovery Manager (Reactive DFIR) – German Speaking

Location
Greater London, England, United Kingdom
Role This hands-on position sits within a cyber advisory practice, focusing on reactive digital forensics and incident response. Day to day, the role involves managing medium to large incident response cases, supporting clients in building internal IR capabilities, contributing to runbooks and playbooks, and developing internal … tooling, processes, and team training when not engaged on active cases. Skills & Experience Candidates require a strong technical background in digital forensics and incident response, with proven incident management experience. The role demands eligibility for SC or DV security clearance. Opportunities exist to obtain recognised security certifications ...

Information Security Consultant

Location
United Kingdom
parts of their security programme they cannot resource internally — from regulatory compliance and risk management through to board-level reporting and incident readiness. As an Information Security Consultant you will act as the vCISO lead on a portfolio of client engagements. You will be the security voice … controlled engagement documentation in the shared client collaboration space. Supply chain and third‐party assurance Conduct vendor and supplier due diligence, including questionnaire design, response review and risk identification. Support clients with inbound third‐party due diligence requests, compliance questionnaires and cyber insurance proposal forms, including evidence gathering. Training ...

Director, MTA Engineering

Location
Greater London, England, United Kingdom
eager to master them quickly.Our AI leadership extends beyond how we build to what we build. Our Mihra AI agent delivers 7x faster threat response for customers, and we're recognized as "Agents of Change" in Human Risk Management. Engineers here work at the intersection of cutting-edge … succession planning for key leadership and senior technical roles.* **Drive Engineering Excellence:** Set and maintain high standards across your squads: testing, observability, release governance, incident response, and secure development practices. Hold the organisation accountable for operational excellence on a zero-downtime, globally distributed platform — including post-incident ...

Senior Platform Engineer

Location
Greater London, England, United Kingdom
systems. Improve developer experience through automation, self-serve tooling and infrastructure-as-code practices that increase engineering velocity. Own and evolve our observability, incident response and reliability practices to minimise downtime and improve system performance. Partner closely with product and engineering teams to support new services, migrations … distributed systems fundamentals. Experience improving CI/CD pipelines and deployment automation in fast-moving engineering teams. Comfortable debugging production issues and participating in incident response in high-availability environments. Clear communication skills and the ability to work closely with software engineers across multiple teams. You get excited ...

Head of Security Operations

Location
Greater London, England, United Kingdom
culture, development and training for the organisation. Maintain a clear division of ownership with the VP InfoSec, with regular collaboration expected across both domains. Incident Response & Resilience: Own incident response and crisis management when customer-facing infrastructure is affected. Run post-incident reviews … engineering leadership without relying on formal authority. Experience working alongside a peer GRC/Infosec function with clearly defined but collaborative boundaries. Experience owning incident response and resilience programmes at scale. Nice to Have Experience securing AI-native, GPU-accelerated or HPC infrastructure specifically. Background in telecom, hyperscale ...