1,101 to 1,125 of 2,368 Incident Response Jobs in the UK

Cyber Resilience Specialist

Hiring Organisation
Hays Specialist Recruitment Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£600.00 per day
recruit a Cyber Resilience Specialist to support a high-profile Operational Resilience programme.This role will focus on linking cyber threats, vulnerabilities, security controls and response scenarios to business service impacts and Operational Resilience outcomes. The successful candidate will work closely with security, technology operations, risk teams and service owners … tolerance assessments and resilience planning. Provide clear recommendations and actionable improvements to strengthen resilience capabilities. Essential Skills & Experience Experience in Cyber Resilience, Cybersecurity Operations, Incident Response, Threat Management or Vulnerability Management. Strong understanding of security controls, SOC operations, detection, response and recovery processes. Experience translating technical cyber ...

Senior Consultant - Cyber Security

Hiring Organisation
CyPro
Location
City of London, London, United Kingdom
risks, defining appropriate remedial actions. Leading operational delivery for client certification audits, e.g. ISO 27001, CE+ and SOC2. Supporting our Security Operations Centre during incident response, ensuring effective threat mitigation. Raising cyber security awareness through our entertaining bulletin, blogs, phishing simulations and tabletop exercises. Co-ordinating penetration tests … improve client security. Leading the response to third-party due diligence questionnaires and assessing new vendors. Ensuring you continue to make yourself marketable and credible to clients and prospects by maintaining professional accreditations. A Senior Consultant would be expected to have at least 2 professional accreditations such as CompTIA+ ...

platform engineer

Location
Greater London, England, United Kingdom
resilient system design with sensible APIs, failure handling, rate limiting, retries, idempotency, and safe change management; Improve reliability and observability through metrics, dashboards, alerting, incident follow-ups, and operational improvements; Partner with Applied AI Engineers and product teams to understand platform needs and help them build AI-powered features … with reliability and observability requirements; Experience designing and delivering shared platform or infrastructure components used by multiple teams; Strong production ownership, including monitoring, alerting, incident response, debugging, and post-incident learning; Knowledge of distributed systems fundamentals, including asynchronous workflows, idempotency, consistency trade-offs, and designing for failure ...

Information Security Analyst

Location
Greater London, England, United Kingdom
network infrastructure into a coherent detection stack Write, test, and maintain detection rules that reduce noise and measure coverage against real attacker behaviour Lead incident response from detection through containment, eradication, and post-mortem; own the IR runbooks and keep them tested through tabletop exercises Perform forensic analysis … initial access, persistence, privilege escalation, exfiltration) and can map an investigation to it Comfortable scripting in Python or similar to automate enrichment, triage, and response Strong ownership mindset: sees things through end-to-end with little guidance Desirable Deep familiarity with an EDR platform (CrowdStrike, SentinelOne, Defender ...

Cyber SOC Lead

Location
Glasgow, Scotland, United Kingdom
support skills, careers and economic development across Scotland. You'll drive the evolution of our Security Operations Centre, lead a team of analysts, shape incident response capabilities, and help define cyber security strategy across the partnership. Working with technologies including Microsoft Sentinel, Defender, Entra ID, Purview, Intune … Manage and coordinate major cyber incidents and investigations. Work closely with our managed SOC provider to enhance security capabilities. Improve threat detection, monitoring and response processes. Influence cyber security strategy and risk management across the partnership. Lead cyber exercises, continuous improvement initiatives and service innovation. Translate technical risks into ...

Product Manager

Location
Greater London, England, United Kingdom
identify trends in team velocity, providing early warnings and performance feedback to the Product Lead, elevate concerns with capacity and velocity where necessary. Incident Response & Escalation: Monitor and oversee incident management, proactively driving engineering teams to elevate and follow through with stakeholder informing when necessary Voice ...

Product Manager

Location
Greater London, England, United Kingdom
identify trends in team velocity, providing early warnings and performance feedback to the Product Lead, escalating concerns with capacity and velocity where necessary. Incident Response & Escalation: Monitor and oversee incident management, proactively driving engineering teams to escalation and follow through with stakeholder informing when necessary. Voice ...

VP of Security & Infrastructure

Hiring Organisation
Flo Health
Location
London, United Kingdom
Salary
> £ 150 K
Oversee the management life cycle of code, third party and platform vulnerabilities, ensuring remediation paths are transparent, risk-based, and tracked to closure.Security Operations & Incident Response: Oversee detection engineering, continuous threat monitoring, and serve as the accountable executive for major incident escalations.2. Platform & Infrastructure EngineeringCloud & Developer Infrastructure ...

VP of Security & Infrastructure

Location
Greater London, England, United Kingdom
management life cycle of code, third party and platform vulnerabilities, ensuring remediation paths are transparent, risk-based, and tracked to closure. Security Operations & Incident Response: Oversee detection engineering, continuous threat monitoring, and serve as the accountable executive for major incident escalations. 2. Platform & Infrastructure Engineering Cloud & Developer ...

Security Engineer

Location
Belfast City District, Northern Ireland, United Kingdom
engineers, with a clear path toward technical or team leadership as the U.K. presence scales. Responsibilities Assist in fine-tuning Upwind's detection and response mechanisms. Support proactive reviews of customer environments to identify risks, exposed attack surfaces, and recommend improvements. Lead and conduct in-depth security investigations, including … best practices in cloud security. Contribute to the development and training of AI-driven detection models, leveraging machine learning to improve investigation accuracy and response efficiency. Requirements Based in Belfast, NI. This is a hybrid, in-office, 3 days per week role; visa sponsorship is not available. You must ...

Director, Security Engineering & Operations

Hiring Organisation
Cognism
Location
London, United Kingdom
Salary
£ 100 K
security posture that is embedded in strong security foundations, helping us stay ahead of the threat landscape rather than reacting to it.Detection, Response & SOC PartnershipOwn the strategic relationship with our 24/7 outsourced SOC holding them to a high standard on threat hunting, threat intelligence utilisation, and automated … response, not just SLA compliance.Ensure Cognism has a holistic, well-maintained SIEM that reflects how we operate and improves continuously as the threat landscape evolves.Build the internal team into a trusted escalation layer, with clear incident response playbooks, rehearsed escalation paths, and a feedback loop that sharpens ...

Software Engineering Tech Lead (SRE + AI)

Hiring Organisation
CISCO Systems
Location
London, United Kingdom
Salary
£ 80 K
teams monitor, diagnose, and auto-remediate global SaaS infrastructure.Whatyou'lldo Technical Leadership & Architecture: Define the technical roadmap and architecture for AI-assisted observability, automated incident response, and self-healing cloud infrastructure.Agentic Workflows & Tooling: Design and build production-grade AI agents, MCP tool integrations, and deterministic evaluation pipelines … quality guardrails.Reliability & Scalability Engineering: Partner with application and infrastructure teams to define SLIs/SLOs, handle error budgets, and lead deep-dive post-incident reviews (PIRs).Mentorship & Collaboration: Mentor senior and mid-level engineers, establish engineering best practices, and drive alignment across global development and operations teams.You’ll manage ...

Data Governance & AI Consultant

Location
West of England, England, United Kingdom
evaluation (appropriate metrics and acceptance thresholds; robustness, fairness, privacy, and safety testing; secure red-teaming where applicable). Operational governance (monitoring KPIs, drift detection, incident response, change control, and regular re-evaluation & re-training with realistic datasets). Author clear artefacts: governance frameworks, operating procedures, evaluation plans, model … interviews with stakeholders, capturing requirements and converting them into actionable designs and backlogs. Support benefits tracking (e.g., DQ uplift, lineage coverage, model performance stability, incident reduction). Methods, tools & assurance Apply and tailor customer playbooks for data governance and AI assurance (policy templates, DQ standards, risk & control libraries, evaluation ...

Software Engineering Tech Lead (SRE + AI)

Location
Greater London, England, United Kingdom
auto-remediate global SaaS infrastructure. What you'll do Technical Leadership & Architecture: Define the technical roadmap and architecture for AI-assisted observability, automated incident response, and self-healing cloud infrastructure. Agentic Workflows & Tooling: Design and build production-grade AI agents, MCP tool integrations, and deterministic evaluation pipelines … quality guardrails. Reliability & Scalability Engineering: Partner with application and infrastructure teams to define SLIs/SLOs, handle error budgets, and lead deep‐dive post‐incident reviews (PIRs). Mentorship & Collaboration: Mentor senior and mid-level engineers, establish engineering best practices, and drive alignment across global development and operations teams. ...

Infrastructure Software Engineer, Apps Platform

Location
Greater London, England, United Kingdom
skills and the ability to navigate performance/security tradeoffs in production systems Comfort with ambiguity, and the ability to context-switch between reactive incident work and proactive product development Nice to haves: Experience as a founder or early engineer at an infrastructure-focused startup, owning a product … tenant or untrusted environments (e.g., FaaS, CI sandboxes, remote notebooks) Open-source contributions to systems or developer-tools projects History of on-call/incident response for production systems ***PLEASE NOTE:Our policy requires a 90-day waiting period before reconsidering candidates for the same role. This allows ...

SecOps Engineer

Hiring Organisation
Context Recruitment Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £75,000 per annum
base articles in line with best practices Automate security tasks and toolchains using scripting (PowerShell, Batch, etc.) Collaborate with external SOC teams Prepare post-incident reports and root cause analyses Manage end-user device (EUD) security via MS Intune, Sophos and NinjaOne Schedule and assess vulnerability scans on critical … driven changes Produce weekly security operations reports Manage Cisco Umbrella web filtering and SSL inspection policies Requirements: Previous hands-on experience in SecOps or Incident Response Recognised Security certifications such as Security+, CEH, or Microsoft security certifications Strong knowledge of Microsoft Windows OS security and hardening Working PowerShell ...

Senior Full Stack Engineer – Industrial Sustainability Reporting Platform

Hiring Organisation
IFS
Location
London, United Kingdom
Salary
£ 80 K
make sound engineering trade-offs around scalability, maintainability, performance, and product impactOwn reliability and operational excellence, including telemetry, SLOs, error budgets, on-call rotations, incident response, and continuous service improvementChampion DevOps practices, including CI/CD, deployment automation, monitoring, and application-level operationsCollaborate with Platform Engineers as part … programming languagesExperience designing and building scalable APIs, services, and cloud-native applicationsStrong understanding of DevOps practices, including CI/CD, deployment, monitoring, automation, and incident responseExperience delivering secure, observable, high-quality production softwareStrong focus on code quality, automated testing, documentation, performance, and maintainabilityAbility to lead technical design discussions ...

SIEM Engineer

Location
Reading, England, United Kingdom
data transformations Design and optimise KQL queries; build and tune analytic rules and detection logic Develop Logic Apps/SOAR workflows to automate response Implement CI/CD pipelines (Azure DevOps/Git) for SIEM content deployment Automate deployment/config across environments; tune detections to reduce false positives … logic design and tuning Logic Apps, Playbooks and SOAR automation Azure DevOps/Git CI/CD pipeline implementation Strong grounding in security monitoring, incident response and threat hunting Strong troubleshooting and root cause analysis skills Desirable SANS SEC503 – Network Monitoring and Threat Detection Candidates must hold active ...

Devops Engineer

Location
Greater London, England, United Kingdom
environment Proactively identify risks, bottlenecks, and failure patterns before they impact users Define and track appropriate SLIs/SLOs for critical services Conduct post‐incident reviews and drive lasting improvements Supporting AI‐Augmented Development A large proportion of the solutions you will support are built rapidly using structured … scale Actively use AI tools (e.g. Claude, Copilot, or similar) to accelerate your own work: writing scripts, diagnosing issues, generating runbooks, reviewing configurations Diagnosis & Incident Response Take ownership of vague or ambiguous production issues (e.g. “it’s running slow”, “the server keeps falling over”) and drive them through ...

IT Delivery Manager - Technology Operations

Hiring Organisation
Red King Resourcing
Location
London, West End, United Kingdom
Employment Type
Contract
Contract Rate
£500 - £550/day Dep on skills / exp - INSIDE IR35
technology services across a multi-site organisation. The chosen Candidate will be responsible for TechBar and desktop support, hardware and software asset management, major incident response and the performance of third-party technology support providers. This is a key operational leadership role, combining service delivery, supplier management … standards, monitoring performance and leading regular service reviews. Own hardware and software asset management, including lifecycle, stock, deployment and licence compliance. Lead the technology response to P1 and P2 major incidents, coordinating resources, communications and resolution. Drive post-incident reviews, root-cause analysis and continuous improvement. ...

IT Delivery Manager - Technology Operations

Hiring Organisation
Red King Resourcing
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£500.00 - £550.00 per day
technology services across a multi-site organisation. The chosen Candidate will be responsible for TechBar and desktop support, hardware and software asset management, major incident response and the performance of third-party technology support providers. This is a key operational leadership role, combining service delivery, supplier management … standards, monitoring performance and leading regular service reviews. Own hardware and software asset management, including lifecycle, stock, deployment and licence compliance. Lead the technology response to P1 and P2 major incidents, coordinating resources, communications and resolution. Drive post-incident reviews, root-cause analysis and continuous improvement. ...

Product Security Engineer

Location
Greater London, England, United Kingdom
RESPONSIBILITIES Security Engineering & Operations Design, build, and operate Watcher’s core security controls: identity and access management, infrastructure and cloud security, endpoint management, and incident response. Build paved roads that make the secure path the default, easy path Establish and advocate for security practices across Apollo, and build … between hands‐on security work and strategic product thinking within the same week. Strong written communication, this role produces security questionnaire responses, whitepapers, and incident communications that need to be clear and precise. Nice‐to‐haves Strong understanding of enterprise security buyer concerns , ideally from having been a security ...

Senior Full Stack Engineer - Agentic Industrial Emissions Platform (React and Go)

Hiring Organisation
IFS
Location
London, United Kingdom
Salary
£ 80 K
sound engineering trade-offs around scalability, maintainability, performance, and product impact. Own reliability and operational excellence, including telemetry, SLOs, error budgets, on-call rotations, incident response, and continuous service improvement. Champion DevOps practices, including CI/CD, deployment automation, monitoring, and application-level operations. Collaborate with Platform Engineers … Experience designing and building scalable APIs, services, and cloud-native applications. Strong understanding of DevOps practices, including CI/CD, deployment, monitoring, automation, and incident response. Experience delivering secure, observable, high-quality production software. Strong focus on code quality, automated testing, documentation, performance, and maintainability. Ability to lead technical ...

Senior Infrastructure Engineer (Linux & Cloud Automation)

Hiring Organisation
Adria Solutions
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
automation Manage Azure Key Vault, secrets, and certificate lifecycle processes Implement infrastructure changes and contribute to CAB processes Resolve technical escalations and support major incident response Participate in a shared on-call rota What We're Looking For Strong experience in infrastructure engineering, cloud operations, or managed services …/or ARM templates Azure DevOps and CI/CD pipeline experience Scripting and automation experience using Bash and/or PowerShell Strong troubleshooting, incident management, and problem-solving skills Why Join? Work with modern cloud, automation, and DevOps technologies Play a key role in driving Infrastructure-as-Code ...

Senior Platform Engineer

Hiring Organisation
Leonardo DRS
Location
Yeovil, Somerset, UK
Employment Type
Full-time
maintenanceOperational support of platform services (e.g. PAM, PKI, cross-domain solutions) in live environmentsPlatform administration including patching, upgrades, configuration, and account managementMonitoring, alerting, and incident response for platform servicesIncident and problem management, including troubleshooting and root cause analysisNetworking concepts (TCP/IP, DNS, DHCP, firewalls)Automation and scripting … services, or cross-domain/secure transfer solutionsUse of monitoring and alerting tools (e.g. SIEM, infrastructure monitoring platforms)ITIL-aligned service management practices (incident, problem, change)Automation of operational activities (scripts, scheduled jobs, runbooks)Experience working in high-availability or 24/7 service environmentsIntegration with enterprise services (Active ...