26 to 50 of 1,718 Incident Response Jobs in the UK

Incident Response Engineer, UK Security Operations, Hampshire

Location
England, United Kingdom
Incident Response Engineer, UK Security Operations, Hampshire Google is looking for an Incident Response Engineer to join our Security Operations team based in Hampshire. You will be responsible for identifying, mitigating, and responding to security threats, ensuring the safety and integrity of Google's infrastructure … This role is not marked as remote. Company context Google has active SoftwareCareers listings in the current job inventory. Experience signal: Relevant experience in incident response or security operations.. Prepare examples for: Incident Response, Security Operations, Cybersecurity, Network Security, Threat Detection. Job Overview Incident Response ...

Senior security analyst - Sector security

Location
Manchester, England, United Kingdom
users across universities, colleges and research organisations. Combining cutting-edge security technologies, threat intelligence and specialist expertise, we provide 24/7 protection, rapid incident response and advanced threat detection to help our members stay secure and resilient. Our Security Centre brings together Cyber Security Incident Response (CSIRT), Digital Forensics and Incident Response (DFIR), SIEM Analysts and Network Defensive Services specialists. Working at the forefront of cyber defence, we identify and respond to threats, support organisations through cyber incidents, conduct threat hunting activities and continuously evolve our capabilities to stay ahead of emerging risks. ...

Senior security analyst - Sector security

Location
Oxford, England, United Kingdom
users across universities, colleges and research organisations. Combining cutting-edge security technologies, threat intelligence and specialist expertise, we provide 24/7 protection, rapid incident response and advanced threat detection to help our members stay secure and resilient. Our Security Centre brings together Cyber Security Incident Response (CSIRT), Digital Forensics and Incident Response (DFIR), SIEM Analysts and Network Defensive Services specialists. Working at the forefront of cyber defence, we identify and respond to threats, support organisations through cyber incidents, conduct threat hunting activities and continuously evolve our capabilities to stay ahead of emerging risks. ...

Senior security analyst - Sector security

Location
Greater London, England, United Kingdom
users across universities, colleges and research organisations. Combining cutting-edge security technologies, threat intelligence and specialist expertise, we provide 24/7 protection, rapid incident response and advanced threat detection to help our members stay secure and resilient. Our Security Centre brings together Cyber Security Incident Response (CSIRT), Digital Forensics and Incident Response (DFIR), SIEM Analysts and Network Defensive Services specialists. Working at the forefront of cyber defence, we identify and respond to threats, support organisations through cyber incidents, conduct threat hunting activities and continuously evolve our capabilities to stay ahead of emerging risks. ...

Cyber Incident Response Lead

Location
Greater London, England, United Kingdom
EC2R 7BP Manchester, GB, M1 4HN Bristol, GB, BS32 4TP Leiston, GB, IP16 4EW Felixstowe, GB, IP10 0DD Career Area: Data, Tech & IT Cyber Incident Response Lead Sizewell C’s business is to design, finance, construct, commission, operate, maintain, and eventually decommission the nuclear power plant and related … independent organisation and continue building one of the UK’s largest and most important energy projects. We are now recruiting the below position. Cyber Incident Response Lead Location: Based in London on a hybrid basis with travel to Suffolk as required. Contract : Permanent, full-time. Benefits include: Bonus ...

Senior Digital Forensics and Incident Response (DFIR) Consultant

Location
City Of London, England, United Kingdom
swiftly and effectively return to business following a cyber-attack. As a global market leader in ransomware post-breach remediation and cyber-attack first response, we consistently deliver results that exceed market standards for handling cyber-extortion and ransomware events. Our team collaborates with prominent global insurance carriers, leading … firms, and Fortune 1000 businesses. We're seeking a Senior Digital Forensics and Incident Response (DFIR) Consultant to join our team. In this role, you'll lead complex investigations, conduct forensic analyses across various platforms, and develop strategic incident response plans. If you're passionate about ...

Lead Threat Response Operations Analyst

Hiring Organisation
Pfizer
Location
South East, United Kingdom
Employment Type
Permanent
ROLE SUMMARY Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, incident response, and risk mitigation across on-premises, cloud, and hybrid environments. As a Lead Threat Response Operations Analyst within Pfizers Global Cyber Defense organization … will serve as a senior individual contributor, providing technical leadership for the investigation and response to sophisticated cyber threats. While this is not a people-management role, you will lead complex investigations, coordinate the response to security incidents on a global scale, and provide technical guidance to analysts ...

Lead Threat Response Operations Analyst

Location
London, United Kingdom
ROLE SUMMARY Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, incident response, and risk mitigation across on-premises, cloud, and hybrid environments. As a Lead Threat Response Operations Analyst within Pfizers Global Cyber Defense organization … will serve as a senior individual contributor, providing technical leadership for the investigation and response to sophisticated cyber threats. While this is not a people-management role, you will lead complex investigations, coordinate the response to security incidents on a global scale, and provide technical guidance to analysts ...

Head of Security Incident and Response

Location
Newcastle upon Tyne, England, United Kingdom
green and healthy future for all. Find out more about DDTS: Defra digital, data and technology blog LinkedIn Defra Jobs The Head of Security Incident and Response provides operational leadership of the Defra Group Security Incident Response Management (SIRM) capability, ensuring the organisation is prepared … able to respond effectively to, security incidents ranging from routine events to significant security incidents. As the senior lead for security incident management, the role oversees incident response policy, governance and operational coordination, directs the response to complex and high-impact incidents, and provides authoritative advice ...

Cybersecurity Incident Response Analyst

Location
England, United Kingdom
## Cybersecurity Incident Response AnalystApply: Hybrid: Remote - England, United Kingdom: Full time: Posted Today: End Date: September 28, 2026 (13 days left to apply): R0138440**Location:**Remote - England, United Kingdom**Job ID:**R0138440**Date Posted:**2026-07-20**Company Name:**HITACHI ENERGY UK LIMITED**Profession (Job Category … increasingly complex and disruptive cybersecurity landscape. This is where you come in.By joining our Cyber Defense Center (CDC) team as a Cybersecurity Incident Response Analyst, you will play a crucial role in protecting and advancing our mission. You will help safeguard our innovative work in renewable energy, ensuring ...

Incident Response Lead (DFIR)

Hiring Organisation
LT Harper Recruitment Group
Location
England, United Kingdom
Incident Response Lead (DFIR) - Hybrid - Can be based anywhere in the UK - Up to £110k The opportunity: Do you want to lead the response to incidents that matter nationally? A Cyber Consultancy is looking for an Incident Response Lead to join its Cyber Response … senior leadership of a fast-growing capability Hybrid working from London or Manchester hubs Pension contribution and private healthcare [confirm] Your responsibilities as an Incident Response Lead will be to: Manage and coordinate a portfolio of cyber security incidents for clients, working closely with the head of cyber ...

Cyber Defence Analyst

Hiring Organisation
A&O Shearman
Location
City, Belfast, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. … Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand ...

Cyber Defence Analyst

Hiring Organisation
A&O Shearman
Location
Neston, Cheshire, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. … Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand ...

Cyber Defence Analyst

Hiring Organisation
A&O Shearman
Location
Banbridge, County Down, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. … Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand ...

Operational Security Manager

Location
Farnborough, England, United Kingdom
will join a growing team of security professionals to protect and maintain the effectiveness of managed service capabilities. The Operational Security Manager supports cybersecurity incident response, investigation, escalation, and regulatory reporting, with a focus on the EU Cyber Resilience Act. Working across Cybersecurity, Product Security, Legal, Compliance, Privacy … Security Manager also provides technical leadership and continuously improves security processes, controls, and supporting technologies. What You'll Be Doing : Support the full cybersecurity incident response lifecycle, including triage, investigation, containment, escalation, remediation, recovery, and post-incident review across enterprise and product environments. Coordinate incident response ...

Threat Intelligence Analyst

Location
City of Westminster, England, United Kingdom
identifying, analysing, and communicating cyber security threats. You will help strengthen our security posture through actionable threat intelligence, advanced threat hunting, and hands‐on incident response activities. Working closely with Security Operations, Incident Response, Infrastructure, and wider Technology teams, you will monitor the evolving threat landscape … investigate potential cyber threats, and support the continuous improvement of our detection and response capabilities. Leveraging Microsoft Sentinel, Microsoft Defender, DarkIQ, and other intelligence sources, you will provide timely intelligence that helps the business stay ahead of emerging threats. A core focus of the role is to transform threat ...

Lead Security Operations Engineer

Location
Greater London, England, United Kingdom
Define and deliver Pleo's SecOps roadmap for detection, response, and investigation capabilities Build a structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks Lead security investigations and digital forensics through incident response Design, tune, and scale SIEM and standardized logging pipelines Strengthen perimeter … configuration, authorization tuning, and suspicious-traffic monitoring Implement DLP controls aligned with sensitive-data locations Improve the on-call rotation, alerting, escalation paths, and response SLAs Automate detection and response workflows using code and AI Reduce SecOps-attributed compliance risk and collect supporting evidence Build dashboards and reporting ...

Threat Intelligence Analyst

Location
Greater London, England, United Kingdom
external intelligence with internal security events using Microsoft Sentinel and Microsoft Defender Develop and maintain advanced KQL queries for threat hunting, detection engineering, and incident investigation Produce actionable threat intelligence reports, threat actor profiles, IoCs, and executive briefings Support and participate in incident response from initial triage … through containment, eradication, recovery, and post-incident review Conduct forensic investigations and provide threat context during live security incidents Collaborate with SOC teams, security architects, and technology stakeholders to strengthen detection and response capabilities Contribute to threat models, risk assessments, playbooks, and operational processes Maintain awareness of evolving ...

Security Engineer, Detection and Response

Location
Greater London, England, United Kingdom
specific threats including prompt injection, model extraction, data poisoning, adversarial examples, and unauthorized access to training datasets or model weights Build automated response playbooks and orchestration workflows to contain threats and remediate compromised inference endpoints Lead security incident response coordination across Cloud, AppSec, Enterprise, and AI Security … teams Conduct forensic investigations into training pipeline attacks and model manipulation attempts Draft incident communications for engineering and executive leadership Proactively hunt sophisticated threats across GPU clusters and training infrastructure Analyze model outputs for signs of compromise and reproduce AI-specific vulnerabilities Identify visibility gaps in distributed training environments ...

Incident Response Manager/DFIR Manager

Hiring Organisation
Hays Specialist Recruitment Limited
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£90,000 - £115,000 per annum
Your new company You will join an established international cybersecurity services organisation providing digital forensics, incident response and post-breach support to clients worldwide. Operating through a global follow-the-sun model, the organisation is expanding its regional leadership capability in response to continued growth. This … remote UK role, with a preference for candidates based around London, Birmingham or Manchester and occasional client-site travel. Your new role As Incident Response Manager, you will lead complex DFIR engagements while managing and developing a regional team of approximately six to seven professionals. This ...

Senior Incident Response Consultant, Mandiant (Weekend team)

Location
United Kingdom
Senior Incident Response Consultant, Mandiant (Weekend team) Mid Experience driving progress, solving problems, and mentoring more junior team members; deeper expertise and applied knowledge within relevant area. This role follows a weekend schedule covering 10-hour daily shifts from Friday through Monday. Remote location: United Kingdom. Bachelor … investigative experience with network forensics, malware triage analysis, cloud forensics, or disk and memory forensics. 5 years of experience working end-to-end incident response investigations, analysis, or containment actions. Experience in Linux or Unix. Ability to travel up to 30% of the time. Preferred qualifications: Certifications ...

SOC Team Lead

Location
Greater London, England, United Kingdom
Drive performance and operational excellence across Shared Service’s Cyber Services function Act as a technical escalation point and line manager Support threat analysis, incident response, and security assurance activities Foster a proactive culture of cyber hygiene and continuous improvement Collaborate across departments to strengthen Shared Service … security posture Deputise for the Service Desk Manager during high workload or absence periods Lead cyber service operations focused on SLA attainment, incident response, and resolution quality Oversee daily workflow distribution and prioritise emerging threats and investigative escalations Ensure complex or unresolved cybersecurity issues are escalated appropriately Line ...

Senior DFIR Investigator

Location
City Of London, England, United Kingdom
build resilience against cyber threats. We're seeking a Senior DFIR Investigator to join our Global Security Services team. Working at the forefront of incident response, you'll lead complex investigations for organisations around the world, helping clients understand what happened, contain threats and recover with confidence. This … actor activity, attack techniques, malware and potential data exposure. Produce high‐quality forensic reports, attack timelines and actionable recommendations for clients. Deploy and utilise incident response tooling to collect, preserve and analyse forensic evidence. Provide trusted technical guidance to clients throughout the incident response lifecycle. Work ...

Senior Cyber Security Engineer

Hiring Organisation
Comtecs
Location
City of London, London, United Kingdom
Employment Type
Permanent
Cyber Security Specialist/Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team … identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across ...

Incident Response Specialist

Location
England, United Kingdom
# Incident Response Specialist*Marcus Donald People***England**Hybrid · Mid · Contract### The RoleThe specialist responds to sophisticated cyber security incidents within a large banking-sector enterprise, conducting live-response investigations, building host activity timelines, and producing clear incident reports. The role sits within a mature security … operations function alongside threat intelligence, detection engineering, and incident management teams, following a Wednesday–Saturday shift pattern.### Skills & ExperienceCandidates need hands-on experience in incident response, digital forensics, and EDR tooling, plus a track record of creating operational procedures and communicating findings to stakeholders. Relevant certifications ...