126 to 150 of 1,718 Incident Response Jobs in the UK

SOC Shift Lead

Hiring Organisation
Searchability NS&D
Location
Hemel Hempstead, England, United Kingdom
busy Security Operations Centre while remaining hands-on with technical investigations. You will act as the senior escalation point during your shift, leading incident response, mentoring analysts and ensuring high standards across investigations. You will also: Lead Major Incident investigations and technical response activities Analyse advanced … Lead Strong experience leading complex cyber security investigations Commercial experience with Microsoft Sentinel and Splunk Enterprise Security Excellent understanding of MITRE ATT and CK, incident response and threat-informed defence Strong networking knowledge including TCP/IP, DNS, HTTP/S, SMTP, LDAP and VPN technologies Experience analysing ...

SecOps Engineer

Location
Manchester, England, United Kingdom
infrastructure, identity platforms, cloud services, and business systems. Configure, maintain, and optimise security technologies to safeguard hybrid environments, enabling proactive threat detection and resilient incident response through close collaboration with infrastructure, operations, and cloud teams. Coordinate vulnerability management activities across endpoints, servers, cloud services, and network infrastructure, including … high-risk vulnerabilities Contribute to the evolution of automated security operations and threat detection workflows, using scripting and orchestration tools to enhance efficiency and response capabilities over time, in collaboration with infrastructure and operations teams. Maintain and enforce information security policies, procedures, and standards in alignment with regulatory frameworks ...

Information Security Analyst - SecOps Response

Location
Southampton, England, United Kingdom
asking that you attend the office a minimum of 1 day per week. About the Role We’re seeking a passionate and skilled Incident Responder to join our growing Security Operations team, and proactively defend Starling’s customers, assets, and systems against emerging threats. This role will be supporting …/7 operational capabilities (On-call rota). Reporting to the Information Security Lead - SecOps Response, the analyst’s main responsibilities include: Conducting incident response activities to investigate and contain cyber security incidents Developing and maintaining incident response and readiness processes Analyse logs from ...

Sr. Analyst, Falcon Complete (Remote, GBR)

Hiring Organisation
CrowdStrike
Location
United Kingdom
Employment Type
Permanent
Salary
GBP Annual
opportunity to rapidly accelerate your skills? Do you crave new and innovative work that actually matters to your customer? Do you have an Incident Response or Information Security background that you're not fully utilizing? Are you capable of leading teams and interacting well with customers … learn from and mentor on a daily basis? What You'll Do: Conduct monitoring and perform in-depth analysis of security alerts. Exercise incident handling processes across Windows, Mac, and Linux platforms. Perform malware analysis. Perform remote remediation of malware or malicious activity. Develop and improve processes for incident ...

Cyber Defence Senior Director

Hiring Organisation
Boston Consulting Group
Location
London, UK
Cybersecurity Operations capability across the firm's full technology environment. Building on the strengths of the existing teams, you will bring security operations and incident response capabilities together into a more connected end-to-end service that improves visibility, reduces exposure, and strengthens BCG's ability to detect … clear direction for the continued evolution of the capability. Set the strategy, priorities, and performance expectations for global Cybersecurity Operations. Bring monitoring, detection, response, recovery, vulnerability management, and offensive security into a cohesive service. Develop an integrated, end-to-end Security Operations Center capability with clear ownership, handoffs ...

Senior SOC Analyst - DV Clearance

Hiring Organisation
Salt Search
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £100,000 per annum
security cyber defence team supporting critical national infrastructure and sensitive government programmes. This role requires a proactive security professional with strong monitoring, analysis, and incident triage capabilities within a Security Operations Centre environment. SOC Analyst - Key Responsibilities Monitor and analyse security alerts from SIEM and security tooling platforms Perform … triage and investigation of security events and potential incidents Conduct threat hunting and identify indicators of compromise Escalate and coordinate incident response activities where required Analyse endpoint, network, and cloud security telemetry Develop and improve detection rules and use cases Produce detailed investigation and incident reports Collaborate ...

Security Architect - SC Cleared

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
£545 - £590 per day
solutions into operational security environments. Ensure operational teams have the controls, monitoring capabilities, and processes required to manage secure services. Collaborate with Security Operations, Incident Response, Engineering, and Platform teams to maintain secure systems. Drive continuous improvement within security monitoring and incident response capabilities. Stakeholder Engagement … supporting government departments, public sector organisations, or Critical National Infrastructure programmes. Knowledge of: Zero Trust Architecture Secure by Design Principles DevSecOps Methodologies Security Operations & Incident Response Identity & Access Management (IAM) Data Protection & Privacy Controls Enterprise Security Architecture Frameworks Familiarity with: NCSC Cloud Security Principles ISO 27001 NIST Cybersecurity ...

EMEA CSOC Lead

Location
Cheltenham, England, United Kingdom
lead a team of highly capable cyber threat analysts protecting Northrop Grumman UK and EMEA operations, while remaining directly involved in threat hunting, incident response, digital forensics and cyber defence activities. Working as part of a global cybersecurity organisation, you will collaborate closely with colleagues across … direction, coaching and day-to-day operational oversight. Manage security operations across the EMEA region, ensuring effective execution of cyber monitoring, triage, investigation and response activities. Serve as Incident Response Lead for major cyber security events, coordinating technical investigations, containment and remediation activities. Lead advanced threat hunting ...

Senior Security Operations Analyst

Location
Leeds, England, United Kingdom
timely and proactive escalation of potential events/items of interest. The role will include access control, application and development, risk management, operational security, incident response, business continuity, operational and physical security of systems, as well as ongoing user training and reporting requirements. Primary responsibilities include: Monitor, investigate … with Detection and Automation team to support development of detection alerts, security automation and recommendations for tuning of rules to reduce false positives Support incident investigation, containment, eradication, and recovery activities while maintaining accurate documentation, and contributing to the continuous improvement of detection capabilities, playbooks, and operational processes Respond ...

Senior Cyber Detection and Response Engineer

Location
Greater London, England, United Kingdom
Senior Cyber Detection and Response Engineer (London, UK) Summary of Position As a critical technology provider to around 100 of the world's leading financial institutions, Pirum’s security posture is a commercial asset as much as a risk management function. Our customers conduct rigorous third-party security assessments … protect our systems and data directly affects our ability to win and retain business. We are looking for a Senior Detection and Response Engineer to lead Pirum's detection and response capability, enabling us to detect, investigate and contain threats at machine speed across our AWS, on-premises ...

Tech Lead - SOC Responder

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent, Work From Home
with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world class incident response functions to detect, protect, respond, and sustain operations within cyberspace. This role operates at a Tier 3 level , with the expectation that … operational activities, Technology escalation support, Security Solution assessment, existing Service maturing and Build activities assist Analyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach Establishing and governing the security incident response processes, investigations and security operational processes Maintenance and enhancement ...

Security Operations Specialist

Location
Greater London, England, United Kingdom
with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world class incident response functions to detect, protect, respond, and sustain operations within cyberspace. This role operates at a Tier 3 level , with the expectation that … operational activities, Technology escalation support, Security Solution assessment, existing Service maturing and Build activities assist Analyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach Establishing and governing the security incident response processes, investigations and security operational processes Maintenance and enhancement ...

SOC Team Lead

Location
Greater London, England, United Kingdom
your unique needs. We help organisations improve processes such as threat management by building an identity management programme, and establishing prevention, detection and response capabilities to cyber-attacks. The SOC Team Lead drives performance and operational excellence acrossShared Service’s Cyber Services function. Acting as both a technical escalation … point and line manager, they support the team in threat analysis, incident response, and security assurance activities. They foster a proactive culture of cyber hygiene and continuous improvement while collaborating across departments to strengthenShared Service's security posture. The Team Leader also deputises for theService DeskManager during high ...

Staff Software Engineer

Location
Uddingston, Scotland, United Kingdom
technical challenges, setting technical direction and helping teams deliver scalable, reliable systems that support business growth? Are you as comfortable reviewing architecture and leading incident response as you are writing production code? If you bring a blend of technical excellence, leadership and a builder mentality, DFYNE might … deployment quality controls. Lead technical problem-solving across critical business systems. Own and influence architecture and technical design decisions across multiple platforms Lead incident response activity, ensure corrective actions address root causes over individual failures. Pair with engineers across critical systems to reduce single points of failure. Mentor ...

Junior AWS Security Incident Response Engineer

Location
Manchester, England, United Kingdom
Amazon AWS Security Incident Response is seeking a Security Engineer I to join a fast-paced team responsible for threat detection and incident response across customer environments. The role emphasizes learning, collaboration, and communicating complex security concepts to non-technical audiences. You will monitor networks ...

Cyber Security Architect & Engineering Lead

Location
Greater London, England, United Kingdom
establish practical controls for Microsoft 365 Copilot, AI agents, custom AI applications and related technologies. Provide senior technical oversight across security monitoring, detection engineering, incident response and recovery capability. Lead or support the response to complex or high-severity security incidents, working with internal teams, external … security, API security and secure software development. Experience of security architecture review, threat modelling, technical standards, reference architecture and control design. Practical experience across incident response, detection engineering, threat hunting, vulnerability or exposure management and security automation. Ability to automate security and assurance processes using tools such ...

Platform Engineer

Location
Greater London, England, United Kingdom
About incident.io incident.io is the leading AI incident response platform, built to help teams dramatically reduce incident response time and improve reliability. We bring together on‐call, incident response, AI SRE, and status pages in a single platform, giving teams everything they need ...

Incident Response Engineer, UK Security Operations, Hampshire

Location
United Kingdom
Incident Response Engineer, UK Security Operations, Hampshire Google London, UK Mid Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area. X Must be a British citizen to meet compliance and security clearance requirements. Office location will … more programming languages. Active, or the ability to obtain, a Developed Vetting (DV) UK security clearance. Preferred qualifications: Security+ or similar Cyber Security/Incident Response related certifications. Experience responding to security incidents on Kubernetes. Experience analyzing, triaging, and remediating common information security incidents. Understanding of common attacker ...

Principal Product Cybersecurity Assurance

Location
Greater London, England, United Kingdom
Review and provide guidance on security risk assessments, risk mitigation plans, mitigation gap analysis, and security management documentation in support of system cybersecurity certification. Incident Response & Lifecycle Security Establish and maintain a Product Security Incident Response (PSIR) process, encompassing coordinated vulnerability disclosure, patch deployment pipelines … post-field incident analysis. Define and oversee security monitoring requirements for deployed fleets, ensuring field data feeds back into risk files and security artefacts in line with post-market surveillance obligations. Commercial & Bid Support Support the production of work package descriptions and cost estimates for product bids, services ...

Senior Detection and Response Engineer

Location
United Kingdom
work. Applicants should be based within a comfortable commuting distance of our office to attend onsite as required. Are you experienced in detection and incident response, with an engineering mindset and a passion for improving the tools, automation and processes used to investigate threats? As a Senior Detection … Response Engineer within our Cyber Security team, you’ll play a key role in strengthening Jagex’s detection and incident response capability across our studio and gaming environments. You’ll take ownership of escalated security investigations, going beyond routine alert handling to understand what happened, determine impact ...

EU Resilience Lead

Location
Cambridgeshire and Peterborough, England, United Kingdom
capabilities for critical services. You Have: 8+ years of experience leading or advising on enterprise technology, resilience, cybersecurity, infrastructure, disa ster recovery, business continuity, incident response, or crisis management disciplines for large, complex European or global organizations Experience with advising executive stakeholders and leading senior-level advising … capabilities, and develop ing practical improvement roadmaps that help clients harden infrastructure, improve alignment to NIST CSF categories, strengthen recovery and continuity strategies, test response capabilities, and mature program governance over time Experience in a consult ing or corporate advisory role, including with a top-tier consulting company ...

Cyber Incident Response Lead – Hybrid, 5% Bonus

Location
Greater London, England, United Kingdom
Sizewell C Limited is seeking an experienced Cyber Incident Response Lead to develop, manage, and coordinate the organisation’s cyber incident response capability within a highly regulated and safety-critical environment. You will lead preparation, detection, response, recovery, and lessons learned activities for cyber security ...

Senior Cloud Incident Response Specialist

Location
United Kingdom
Google Cloud's Mandiant is seeking a Senior Incident Response Security Consultant (Mid) to lead advanced incident response engagements across cloud and on-prem environments. You will perform forensic analysis, threat hunting, and malware triage, guiding clients through investigations and containment with clear executive communication. Role ...

Security and Compliance Manager

Location
Greater London, England, United Kingdom
Management: Lead regular vulnerability scanning and penetration testing schedules; prioritise and oversee the remediation of technical weaknesses across all retail systems and POS terminals. Incident Response & Forensics: Act as the technical lead for all security incidents, managing the end-to-end response, from initial detection and containment … deep-dive forensic analysis and post-incident reporting. Identity & Access Management (IAM): Establish and enforce rigorous access controls and Multi-Factor Authentication (MFA) protocols to ensure only authorised personnel can access high-value client and financial data. Secure Software Development: Partner with the Digital/E-commerce teams ...

Information Security Manager - Fintech - Hybrid

Location
City Of London, England, United Kingdom
Information Security Manager owns the company’s information security governance, risk and compliance programme, including the ISMS, client security assurance, security policy framework, incident governance, supplier security assurance, and security reporting. The role works closely with Technology, Product, Operations, Legal and senior leadership to ensure the company’s products … security input into privacy compliance activities and works with the DPO on UK GDPR and EU GDPR obligations, DPIAs, data protection by design and incident response. The role is not the statutory DPO unless separately appointed. The role reports to the COO and ultimately to the WDX Board. Responsibilities ...