226 to 250 of 1,873 Incident Response Jobs in the UK

Cyber Security Analyst

Hiring Organisation
Digital Waffle
Location
London Area, United Kingdom
Analyse logs from endpoints, networks, cloud services and security tools to detect suspicious behaviour Escalate incidents where appropriate and work closely with engineering and incident response teams Develop and improve SIEM detection rules and alert tuning to reduce false positives Produce clear incident reports and maintain accurate … documentation Participate in the on-call rota and support major incident response when required Contribute to the continuous improvement of SOC processes, tooling and operational procedures Skills & Experience Experience working withi n a 24/7 Security Operations Centre ( SOC) or equivalent cyber security environment Strong hands ...

Information Security Analyst

Location
Manchester, England, United Kingdom
readiness, and ongoing compliance monitoring. Assist with the identification, assessment, and documentation of security risks. Track remediation actions and follow up with control owners. Incident Response & Problem Support Support security incident response activities, including investigation and evidence gathering. Assist with root cause analysis and documentation … Experience Experience in an information security, IT risk, or IT operations role. Understanding of common cybersecurity risks, threats, and control types. Familiarity with incident management, risk assessment, and assurance activities. Ability to analyse information, identify issues, and document findings clearly. Strong written and verbal communication skills. Ability to manage ...

Senior CSIRT Analyst

Location
Greater London, England, United Kingdom
next step in your career. The role As a Senior CSIRT Analyst you will play a key role in G-Research’s Cyber Security Incident Response Team (CSIRT), specialising in cloud detection and response across AWS and hybrid environments. You will investigate, respond and proactively hunt … corporate Windows environments. You will use cloud-native security tooling and multi-SIEM operations, such as Elastic, Azure, AWS, to strengthen detection and response capabilities. You will also participate in purple team and red team exercises, continuously validating and improving the team’s effectiveness against advanced adversaries. ...

Cyber Security Specialist (Operational)

Location
Manchester, England, United Kingdom
full list of responsibilities. Person Specification Knowledge Knowledge of Microsoft Defender, Sentinel, including Kusto Query Language (KQL), threat hunting, analytics rule development, security monitoring, incident investigation and automation capabilities. Education/Qualifications Holds highly developed specialist knowledge and expertise acquired through master's degree level or equivalent qualification/… ACSP) ,BCS Certificate in Information Security Management Principles (CISMP), SSCP Systems Security Certified Practitioner Experience Extensive technical expertise across cyber security operations, threat detection, incident response, vulnerability management, security monitoring, and cyber risk reduction within complex enterprise environments. Experience gained through roles such as Security Analyst, SOC Analyst ...

Senior SOC Analyst

Location
England, United Kingdom
cyber security transformation programme within a global enterprise environment. This role is ideal for a senior, hands‐on Security Operations professional who combines strong incident investigation and threat analysis skills with experience in detection engineering, operational process development, and stakeholder engagement. Working as a key bridge between regional … Utilise KQL, SPL, SQL, log analysis, event correlation, and telemetry investigation to validate detection's and support investigations. Support continuous improvement of detection and response capabilities. Stakeholder Management & Collaboration Work closely with Security Operations, Detection Engineering, Threat Intelligence, Incident Response, and Global SOC teams. ...

Cyber Security Specialist (Operational)

Hiring Organisation
NICE – The National Institute for Health and Care Excellence
Location
Manchester, M1 3BN, United Kingdom
Salary
£57528.00 to £64750.00
list of responsibilities. Person Specification Knowledge Desirable Knowledge of Microsoft Defender, Sentinel, including Kusto Query Language (KQL), threat hunting, analytics rule development, security monitoring, incident investigation and automation capabilities. Education/Qualifications Essential Holds highly developed specialist knowledge and expertise acquired through master's degree level or equivalent qualification … Certificate in Information Security Management Principles (CISMP), SSCP Systems Security Certified Practitioner Experience Essential Extensive technical expertise across cyber security operations, threat detection, incident response, vulnerability management, security monitoring, and cyber risk reduction within complex enterprise environments. Experience gained through roles such as Security Analyst, SOC Analyst, Cyber ...

Cyber Security Analyst

Hiring Organisation
The Portfolio Group
Location
Manchester, United Kingdom
Employment Type
Permanent
Salary
£50000 - £55000/annum
infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service … with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will ...

Senior SOC Analyst

Location
Manchester, England, United Kingdom
dual‐focused position combining hands‐on technical expertise with day‐to‐day operational leadership, ensuring high‐quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts—driving both … dual‐focused position combining hands‐on technical expertise with day‐to‐day operational leadership, ensuring high‐quality delivery of managed detection and response services across a diverse customer base. You'll lead SOC operations, act as the escalation point for complex security incidents, and mentor junior analysts—driving both ...

Senior SOC Analyst: Incident Response & Threat Hunting

Location
City Of London, England, United Kingdom
Franklin Fitch in London is seeking an experienced Senior SOC Analyst to join a growing security operations team. This hands-on role focuses on incident detection, investigation, and response, with leadership on complex incidents. You will mentor junior analysts and help develop and improve SIEM rules and detection … cases. You will work four days on site in London with one day remote, collaborating with incident response, security engineering and IT teams to strengthen controls and #J-18808-Ljbffr ...

Senior Security Analyst

Location
United Kingdom
Senior level, the role is about more than your own output. You will help junior analysts develop their triage tradecraft, normalise pairing on incident response, contribute to shared detection standards across the practice, and model the kind of blameless, collaborative culture that makes a security team genuinely effective. … against defined requirements, track actor TTPs, manage indicator lifecycles, and produce situational‐awareness products that inform both detection priorities and client risk decisions. Lead incident response and drive improvement — co‐ordinate containment across engineering and analyst teams, communicate incident detail clearly to client stakeholders, and turn every ...

Senior Security Analyst

Location
Greater London, England, United Kingdom
scheduled information security on‐call rotation; assess urgent alerts and incidents, initiate containment or escalation procedures, engage appropriate stakeholders, and maintain clear incident handoffs. Key Deliverables Security alerts, incidents, and ServiceNow requests resolved and documented within defined service‐level targets. Zscaler, email‐security, identity‐security, and Microsoft security‐platform … security risk, with identified control gaps, exceptions, and remediation actions documented and tracked. On‐call security events triaged, documented, and escalated within established response targets. Required Experience Five or more years of progressive experience in information security, security operations, incident response, or a related discipline. Hands ...

Site Reliability Software Engineer (Hybrid)

Location
Greater London, England, United Kingdom
Improve monitoring, alerting, logging, and reporting across applications and infrastructure. Troubleshoot incidents involving applications, servers, databases, APIs, network connectivity, and system integrations. Participate in incident response, root cause analysis, and post-incident remediation. Build and maintain CI/CD pipelines for safer and more consistent deployments. Partner … networking, DNS, SSL/TLS, firewalls, and system performance. Experience with Linux and/or Windows server environments. Experience with monitoring, logging, alerting, and incident troubleshooting. Experience using Git and CI/CD workflows. Ability to analyze complex technical issues across application, server, database, and network layers. Strong documentation ...

Sr InfoSec Analyst

Location
Belfast City District, Northern Ireland, United Kingdom
will manage security incidents and review security alerts, determine if the security events are false positives, true positives, or false negatives, while working with incident responders on known or suspected security threats. The Senior SOC Analyst will work on log analysis, vulnerabilities and emerging threats, threat hunting and incident response that adhere to best practices and recognized control frameworks while mentoring analysts and being their escalation point. You will help provide security metrics, threat landscape updates and emerging trends. This role requires both deep analytical skills for threat detection and response, as well as technical engineering ...

Network Support Engineer

Hiring Organisation
Bright Purple Resourcing
Location
Scotland, United Kingdom
Employment Type
Permanent
Salary
£65,000
support). Monitor, analyse, and investigate network traffic and emerging threats, including active DDoS activity. Support customer maintenance, upgrades, and technical communications. Contribute to incident response and post-incident reviews that sharpen our detection and mitigation playbooks. Work within ITIL processes (Incident, Change, Problem, Service Requests … A+, Network+, Security+, CySA+, or CyberOps. If youre early in your career and hungry to build deep expertise in network security, traffic analysis, and incident response, this role was designed for you. Bright Purple is an equal opportunities employer: we are proud to work with clients who share ...

ML Ops Lead

Location
Greater London, England, United Kingdom
spot instances, and down-scaling policies to eliminate waste, while providing full visibility into the unit economics of training and serving LLM models. Observability & Incident Response: Establish 24/7 incident response, telemetry, and observability metrics to monitor system performance, model drift, and data pipelines. Data ...

Senior Cloud Security Engineer (GCP) - Engine by Starling

Location
City Of London, England, United Kingdom
architecture design reviews to identify risks and vulnerabilities, triage found risks, identify improvements appropriately and design controls to implement as corrective actions Lead incident response efforts, including investigation and remediation of security breaches Support our internal security awareness and training programs, advocating the DevSecOps mindset that we have … risk and impact to us A proactive approach to staying updated with the latest security threats, vulnerabilities and mitigation techniques Thorough understanding of the incident response process (preparation, identification, containment, eradication, recovery, lessons learned) What skills are desirable: In-depth knowledge of network security, including core routing ...

Lead Software Engineer - LLM Ops Platform Reliability

Hiring Organisation
Hackajob Ltd
Location
Glasgow, Lanarkshire, Scotland, United Kingdom
Employment Type
Permanent
production at scale, with deep instrumentation and strong operational rigor. You will partner across engineering to deliver secure software, improve stability, and lead incident response and continuous improvement. Job Responsibilities Design, develop, troubleshoot, and deliver secure, high-quality production software and services for AI infrastructure Build backend services … parallelism, speculative decoding) Lead reliability engineering for LLM endpoints through capacity planning, load/soak testing, safe rollouts (blue/green, canary), failover, and incident response for outages and model-quality regressions Participate in an on-call rotation, lead incident triage and mitigation, and produce clear post ...

Lead Software Engineer - LLM Ops Platform Reliability

Location
Paisley, Scotland, United Kingdom
production at scale, with deep instrumentation and strong operational rigor. You will partner across engineering to deliver secure software, improve stability, and lead incident response and continuous improvement. Job Responsibilities Design, develop, troubleshoot, and deliver secure, high-quality production software and services for AI infrastructure Build backend services … parallelism, speculative decoding) Lead reliability engineering for LLM endpoints through capacity planning, load/soak testing, safe rollouts (blue/green, canary), failover, and incident response for outages and model-quality regressions Participate in an on-call rotation, lead incident triage and mitigation, and produce clear post ...

Cyber Security Analyst-VM

Location
West of England, England, United Kingdom
Servers (Windows & Linux) Windows & Linux OS Job Description Job Description Role Purpose The purpose of this role is to analyze attack patterns, develop incident response plans, ensure audit readiness, and implement disaster recovery measures, to ensure adherence to cyber security regulatory frameworks. Areas of responsibility Monitoring and Incident … across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards. Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement disaster recovery measures to minimize business disruption Threat Assessment ...

Cyber Security Analyst-VM

Location
Norwich, England, United Kingdom
changing world. For additional information, visit us at www.wipro.com. Job Description Role Purpose The purpose of this role is to analyze attack patterns, develop incident response plans, ensure audit readiness, and implement disaster recovery measures, to ensure adherence to cyber security regulatory frameworks. Areas of responsibility Monitoring … Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards. Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement ...

Cyber Security Analyst-VM

Location
Norwich, England, United Kingdom
changing world. For additional information, visit us at www.wipro.com. Job Description Role Purpose The purpose of this role is to analyze attack patterns, develop incident response plans, ensure audit readiness, and implement disaster recovery measures, to ensure adherence to cyber security regulatory frameworks. Areas of responsibility Monitoring … Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards. Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement ...

GRC Consultant

Location
Greater London, England, United Kingdom
actively participates in supporting/governing forums Contribute to the analysis and mitigation of data protection risks Monitors information security incidents, contributing to incident response and root cause analysis. Will own resulting actions as required where they relate to required changes in IT Security and Information Risk Management … policy and controls Security operations and incident response, liaison with internal teams and 3rd party suppliers To thrive in this role, you need to have A track record of delivering security solutions for large-scale infrastructure, transformation or integration programmes Practical knowledge and understanding of industry security frameworks ...

Cloud Security Engineer Manchester National Security West

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Cloud Security Engineer Leeds National Security West

Hiring Organisation
Hackajob Ltd
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Cloud Security Engineer Gloucester- National Security West

Hiring Organisation
Hackajob Ltd
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...