151 to 175 of 1,718 Incident Response Jobs in the UK

Assistant Manager – Information Security

Location
Greater London, England, United Kingdom
oversight to cyber security operations and liaise with specialist technical teams. Coordinate threat intelligence and vulnerability management, remediation SLAs and external providers. Support incident response, crisis management, operational resilience, business continuity and IT disaster recovery, including AWS cloud environments. Support the Data Protection Officer with UK GDPR governance … GDPR, and awareness of FCA/PRA and payment scheme expectations. Sound understanding of the cyber threat landscape, threat intelligence, vulnerability management and incident/breach management, with the ability to interpret events and drive effective remediation. Working knowledge with security technologies and controls, including perimeter/edge security ...

DevSecOps Engineer

Location
Greater London, England, United Kingdom
systems are protected from vulnerabilities, misconfigurations, and emerging threats. You’ll champion secure‐by‐design principles, automate security controls, and maintain strong monitoring and incident response practices. The role requires close collaboration with Developers, Cloud Engineers, Product Managers, and external suppliers. You will also contribute to the continuous … activities with engineering teams. Perform regular reviews of Terraform modules, container images, Helm charts, and AKS configurations to identify misconfigurations and risks. Monitoring, Detection & Incident Response Work with monitoring tooling (e.g., Datadog or Azure Monitor) to detect anomalous or suspicious activity. Maintain alerting rules, dashboards, and security signals ...

Sr. Manager, Site Reliability

Location
Manchester, England, United Kingdom
Tier-1 customer-facing services, in partnership with Product and Engineering. Establish error budget policy and the enforcement mechanism when budgets burn. Design the incident command structure: severity rubric, declaration criteria, war-room protocol, stakeholder communication cadence, and the postmortem template. Train the first cohort of incident commanders … already in use) over net-new procurement. Define the instrumentation standards all new services must meet. Partner with the VP to migrate the interim incident response RACI — currently held by matrixed individuals across IT, Engineering, Support, and Enterprise Security — into a durable SRE-owned model. Establish ...

AI Security Consultant

Location
Greater London, England, United Kingdom
supporting secure AI adoption, reviewing LLM-based applications, advising on SOC automation, developing AI security guardrails, and helping organisations use AI to enhance detection, response, reporting and risk management. The right candidate will combine strong cyber security fundamentals with curiosity and practical knowledge of AI security. You should … business risk. Support the design and implementation of security controls across areas such as access management, data protection, logging and monitoring, vulnerability management, incident response and third-party risk. Help clients interpret security requirements, assess control maturity and develop actionable improvement roadmaps. Translate technical findings into clear, business ...

Senior Security Operations Engineer New London

Location
Greater London, England, United Kingdom
business and our customers. In the short to medium term, your focus will be on improving operational security capability - enhancing detection and response, incident management, vulnerability management and cloud security operations. As these capabilities mature, you’ll increasingly focus on security engineering and architecture; designing scalable security services … this role you will: Manage, build and mature our Security Operations capability (short to medium term) Own and continuously improve security monitoring, detection and incident response capabilities across our cloud, endpoint and SaaS environment. Build, tune, and maintain high-quality detections, reducing alert fatigue while increasing confidence that ...

3rd Line Security Analyst

Hiring Organisation
Xact Placements Limited
Location
Reading, Berkshire, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
take ownership of the engineering, administration, health and continuous improvement of the security platforms, detection content and automation that underpin threat monitoring, detection and incident response across my client’s internal and managed customer environments. They will act as the final internal escalation point for complex and high … live incidents. Key Responsibilities Lead the end-to-end management of complex and high-severity security incidents, including investigation, containment, eradication, recovery and post-incident review. Conduct digital forensic investigations across cloud, identity, endpoint and network platforms, and carry out malware analysis and threat validation. Design, implement and optimise ...

Senior SOC Analyst – Incident Response Leader

Location
England, United Kingdom
seeking a Senior SOC Analyst - Incident Response to lead complex security incidents in a large enterprise. You will own investigations end to end, coordinate multiple IT teams and apply structured incident response methodology using Microsoft Sentinel and Defender XDR. You will mentor junior analysts, develop playbooks ...

Senior Security Operations Engineer

Location
Bournemouth, England, United Kingdom
week. We are happy to discuss flexible working! Top 3 skills needed for this role: Highly experienced Cyber Security Operations expertise Advanced security incident response capability Proven security tooling and threat management knowledge What this role is all about: We're looking for a Senior Security Operations Engineer … strong relationships with internal stakeholders, vendors and technology partners to support effective security operations You'll develop and maintain security documentation, operational procedures and incident response playbooks Support penetration testing activities and coordinate the remediation of identified findings Contribute to the ongoing enhancement of monitoring, detection and response ...

AMBG - Cloud Security & Exposure Management Architect

Location
Greater London, England, United Kingdom
Assess the resiliency posture of customer environments from both technical and operational perspectives. Evaluate disaster recovery (DR) plans, business continuity (BC) strategies, and Major Incident Response Plans (MIRPs). Conduct in-depth analysis of cloud infrastructure, application dependencies, observability, and failover capabilities. Review and enhance incident response … availability zones, backup, recovery, and monitoring services. Familiarity with cloud-native resiliency patterns and site reliability engineering (SRE) practices. Experience designing and assessing Major Incident Response Plans (MIRPs). Experience in business continuity planning and operational resilience. Strong communication and documentation skills across technical and business stakeholders. Together ...

Lead Security Analyst

Location
United Kingdom
engagement, setting the technical direction for the SOC and owning the quality of what the team produces—from detection engineering to threat-hunting to incident response. This isn’t a role where you disappear into a ticket queue. You’ll shape the threat‐landscape narrative for your engagement, drive … collection plan, produce timely and rigorous intelligence products, and build feedback loops that keep the cycle honest and improving. Establish and lead security incident response practice — build playbooks, define the severity model, run exercises, and lead the team’s response to significant incidents; run blameless post‐mortems ...

Incident Response Manager — Hybrid/Remote

Location
United Kingdom
Arctic Wolf is seeking a Manager, Incident Response to lead and mature the practice by combining strategic leadership with advanced technical incident response expertise. This role guides a hybrid/remote team through complex investigations, ransomware engagements, and large-scale recovery, while maintaining high standards ...

Senior SOC Incident Response Lead

Location
Greater London, England, United Kingdom
seeking a Senior SOC Analyst - Incident Response to lead complex, high-severity incidents across a large enterprise environment. You will own investigations end-to-end, coordinate technical teams during live incidents and apply robust incident response methodology. This role emphasizes hands-on containment, evidence preservation ...

SVP, Global Head of Platform Operations

Location
Greater London, England, United Kingdom
more automated while raising reliability for customers who cannot tolerate downtime. You will own the end-to-end deployment pipeline, production observability and incident management, and the SLO/SLI framework that defines what "good" looks like for every customer-facing service. You will build the leadership layer underneath … Management. Key partners : CTPO, Engineering leadership, SVP Infrastructure, CISO/Security, Product, Customer Support and line-of-business heads. Primary Focus Reliability, Deployment, and Incident Management. The SVP defines and enforces SLOs/SLIs, owns the CI/CD pipeline, leads automated deployment strategy, drives P1/P2 incident ...

Senior Weekend Incident Response Consultant - Remote UK

Location
United Kingdom
Google Inc. is seeking a Senior Incident Response Consultant for the Mandiant Weekend team to lead complex client engagements across cloud, endpoint, and network sources. The role requires 5+ years in investigative forensics, end-to-end incident response, and strong communication skills to explain findings ...

Senior Platform Engineer, Foundations

Location
Greater London, England, United Kingdom
other cloud environments using infrastructure as code and repeatable automation Improve production reliability through SLOs, graceful degradation, self-healing, automated recovery, and incident response Create self-service workflows and platform abstractions that reduce cognitive load for R&D teams Partner with Information Security, Cost Optimization, and engineering teams … Experience administering and scaling multi-tenant Kubernetes clusters and production Kafka or other streaming platforms Experience with Kubernetes upgrades, workload isolation, reliability, security, and incident response Experience building and maintaining infrastructure as code, pipeline-as-code, containerization, and cloud-native systems Experience with Terraform, Helm, Ansible, Jenkins, GitHub ...

Cyber Security Manager

Location
Slough, England, United Kingdom
complex security concepts to technical and non-technical audiences Advising on security architectures, controls and technologies Developing cyber security strategies and implementation roadmaps Supporting incident response and business continuity planning Applying frameworks including NIST, ISO 27001, CIS and CAF Providing specialist advice across complex Defence and Government environments … Security environments Knowledge of security frameworks including NIST, ISO 27001, CIS or CAF Experience within areas such as security architecture, cyber risk, vulnerability management, incident response, security monitoring or threat intelligence Strong stakeholder management and client-facing communication skills Understanding of network security, encryption, authentication and access controls ...

Cyber Security Manager

Location
Greater London, England, United Kingdom
complex security concepts to technical and non-technical audiences Advising on security architectures, controls and technologies Developing cyber security strategies and implementation roadmaps Supporting incident response and business continuity planning Applying frameworks including NIST, ISO 27001, CIS and CAF Providing specialist advice across complex Defence and Government environments … Security environments Knowledge of security frameworks including NIST, ISO 27001, CIS or CAF Experience within areas such as security architecture, cyber risk, vulnerability management, incident response, security monitoring or threat intelligence Strong stakeholder management and client-facing communication skills Understanding of network security, encryption, authentication and access controls ...

Monitoring & Observability Engineer

Location
Reading, England, United Kingdom
operational responses that improve reliability and reduce downtime. What You'll Be Working On Monitor live systems, triage operational alerts and provide first-line incident response to maximise system availability. Develop and maintain dashboards that deliver clear visibility into system health, trends and operational performance. Analyse recurring incidents … tooling and operational processes. Define monitoring thresholds, alerting strategies and operational metrics that support reliable live quantum computing services. Produce documentation covering monitoring processes, incident response, escalation procedures and operational handovers. Contribute to automation and continuous improvement initiatives that reduce manual intervention and improve service reliability. What ...

Cyber Security Manager

Hiring Organisation
Searchability NS&D
Location
City of London, London, United Kingdom
complex security concepts to technical and non-technical audiences Advising on security architectures, controls and technologies Developing cyber security strategies and implementation roadmaps Supporting incident response and business continuity planning Applying frameworks including NIST, ISO 27001, CIS and CAF Providing specialist advice across complex Defence and Government environments … Security environments Knowledge of security frameworks including NIST, ISO 27001, CIS or CAF Experience within areas such as security architecture, cyber risk, vulnerability management, incident response, security monitoring or threat intelligence Strong stakeholder management and client-facing communication skills Understanding of network security, encryption, authentication and access controls ...

Senior DFIR Incident Response Lead & Mentor

Location
Manchester, England, United Kingdom
Group plc is seeking a DFIR Managing Consultant to lead incident response engagements and manage a team of DFIR consultants. The role requires extensive experience in incident response and digital forensics, providing critical guidance during complex situations. Key responsibilities include coordinating teams, delivering thorough investigations ...

Senior SOC Lead – Threat Detection & Incident Response

Location
Hursley, England, United Kingdom
Consulting UK FutureNow is seeking a Senior SOC Analyst to monitor, triage and respond to security threats in a 24x7 SOC. You will lead incident response activities, guide Tier 1/2 analysts, and ensure high-quality security operations across client environments. Role requires strong SIEM experience (Microsoft … Sentinel, QRadar, Splunk, Elastic), knowledge of incident response processes, and collaboration with detection/engineering teams to reduce false positives and improve playbooks. #J-18808-Ljbffr ...

Senior Linux DevOps Engineer

Hiring Organisation
RedTech Recruitment Ltd
Location
City of London, London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£90,000
Terraform and Ansible Experience building and managing CI/CD pipelines using GitLab CI/CD, GitHub Actions, Jenkins or similar Experience with incident response, root cause analysis and driving improvements to the reliability and performance of production systems Commercial experience with Microsoft Azure or another major cloud … automate large-scale Linux-based production environments Build and improve containerised environments using Docker and Kubernetes Diagnose complex infrastructure, networking and performance issues, supporting incident response and root cause analysis Develop automation, Infrastructure as Code and CI/CD processes to improve engineering efficiency and reliability Implement ...

Cyber SOC Lead Ref No: 3594

Location
Glasgow, Scotland, United Kingdom
Enterprise Information Services (EIS), you'll be responsible for driving the maturity of our Security Operations Centre, leading a team of analysts, shaping incident response capabilities and influencing cyber security strategy across the partnership. You'll work at the forefront of cyber defence, using technologies such as Microsoft … Security Copilot, you'll turn insight into action, improve detection capabilities and help build a modern, intelligence-led security operation. You'll lead major incident response activities, challenge and influence suppliers, run cyber exercises, and help define what great security operations looks like for the future. This ...

Head of Cyber Security Operations

Location
Greater London, England, United Kingdom
protecting QA against cyber threats, vulnerabilities and exploits. You will lead both direct and virtual teams responsible for 24/7 security operations, incident response and continuous risk reduction across on‐premise and cloud environments. Role Responsibilities Lead and manage the Security Operations Centre (SOC), ensuring effective …/7 monitoring and on‐call coverage. Oversee security event monitoring, incident response, and threat intelligence across QA Coordinate and manage security incidents end‐to‐end, ensuring rapid and effective resolution. Ensure monitoring, logging, and prevention tools are fit for purpose and deliver best value. Lead security teams ...

Regional Cyber Incident Response Lead (Hybrid)

Location
Manchester, England, United Kingdom
Unilever is seeking a Regional CERT Manager to lead cyber incident response across the region. Hybrid role based in Manchester, with 3 days in the office weekly. You will guide the CERT, manage end-to-end incident response, and partner with SOC teams to strengthen detection ...