26 to 50 of 327 Incident Response Jobs in the UK

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Analyst

Hiring Organisation
Holt Executive
Location
London, United Kingdom
Employment Type
Permanent
team. This is an excellent opportunity to join a fast-paced cybersecurity environment, helping to protect critical infrastructure and enterprise systems through proactive monitoring, incident response, and threat analysis. Working as part of a 24/7 operational security function, you will play a key role in identifying … monitoring tools, network infrastructure, and endpoint technologies. Investigate and triage security alerts to identify malicious activity and determine attack methods and techniques. Follow established incident response and escalation procedures to contain and mitigate security risks. Ensure all incidents are accurately documented, including indicators of compromise, evidence, and investigation ...

Senior Security Platform Engineer

Hiring Organisation
NTT Global Data Centers EMEA UK ltd
Location
Hemel Hempstead, Hertfordshire, South East, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. Directs complex security incident response efforts across multiple vectorsendpoint protection, EDR, malware analysis, network and computer forensicsensuring rapid containment and root cause analysis. Designs and executes advanced vulnerability ...

Security Lead

Hiring Organisation
Method-Resourcing
Location
Maidenhead, Berkshire, South East, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
Up to £500 per day
improvement Lead security engagement within client Design Authority and Enterprise Architecture forums Manage integration with the client SOC, including security reporting, SIEM alignment, and incident response coordination Oversee security incident management in line with the client Cyber Security Incident Response Plan Own joiner/mover … Strong understanding of NCSC HMG IAS5, Cyber Assessment Framework (CAF), ISO 27001, and GDPR Hands-on experience integrating with a UK Government SOC, including incident response and security reporting Strong working knowledge of Oracle Cloud security (OCI IAM, Vault, network security, audit, PAM) Experience securing Oracle SaaS applications ...

Cyber Security Analyst

Hiring Organisation
Hays Technology
Location
Newport, Gwent, United Kingdom
Employment Type
Permanent
Salary
£42000 - £48000/annum £42k - £48k
will require knowledge and understanding of attack and exploitation techniques and adversarial TTP's. Help to provide resilience to our threat monitoring and response capabilities. Handle security incident response with internal teams and other third parties to ensure that the incident response life cycle … Good knowledge and understanding of SOC processes and procedures. Basic experience using SIEM systems such as MS Sentinel, LogRhythm, AlienVault, Splunk Good understanding of incident response stages and handling. Basic knowledge and experience using leading endpoint detection and threat management products and managing their operation. Good knowledge ...

Cyber Security Engineer

Hiring Organisation
Job Board Direct
Location
Omagh, County Tyrone, Northern Ireland, United Kingdom
Employment Type
Permanent, Work From Home
This position offers an exciting opportunity to work in a fast-paced environment, handling cutting-edge technology and complex challenges in cybersecurity. Key Responsibilities: Incident Response (IR): Investigate and respond to security incidents, ensuring rapid containment, eradication, and recovery. Conduct root cause analysis of security breaches and create … detailed incident reports. Collaborate with stakeholders to refine and enhance the incident response plan and playbooks. Security Operations Center (SOC): Monitor and analyse security alerts and logs from various tools such as SIEM, IDS/IPS, and endpoint detection systems. Identify and escalate potential security threats ...

Tech lead - SOC responder

Hiring Organisation
Colt Technology Services UK
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
with global impact upon Colt, business units, partners, and customers. While working as part of this team, the successful individual will provide world class incident response functions to detect, protect, respond, and sustain operations within cyberspace. This role operates at a Tier 3 level , with the expectation that … operational activities, Technology escalation support, Security Solution assessment, existing Service maturing and Build activities assist Analyse potential infrastructure security incidents to determine if incident qualifies as a legitimate security breach Establishing and governing the security incident response processes, investigations and security operational processes Maintenance and enhancement ...

Senior SOC Analyst - DV Cleared

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Portsmouth, Hampshire, United Kingdom
Employment Type
Contract
Contract Rate
£590 - £630/day
Cyber Security Operations Centre supporting critical national security environments. This is an opportunity to work at the forefront of cyber defence, leading threat detection, incident response, vulnerability management, and continuous improvement of security monitoring capabilities. As a Senior SOC Analyst, you will play a key role in protecting … complex enterprise environments through the management and optimisation of security tooling, threat detection, incident response, and forensic investigations. You will work closely with internal and external stakeholders to enhance SOC capabilities, improve security visibility, and strengthen cyber resilience. Key Responsibilities Maintain and optimise SOC Protect, Detect and Respond ...

Senior SOC Analyst

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
Corsham, Wiltshire, United Kingdom
Employment Type
Contract
Contract Rate
GBP 575 - 650 Daily
Cyber Security Operations Centre supporting critical national security environments. This is an opportunity to work at the forefront of cyber defence, leading threat detection, incident response, vulnerability management, and continuous improvement of security monitoring capabilities. As a Senior SOC Analyst, you will play a key role in protecting … complex enterprise environments through the management and optimisation of security tooling, threat detection, incident response, and forensic investigations. You will work closely with internal and external stakeholders to enhance SOC capabilities, improve security visibility, and strengthen cyber resilience. Key Responsibilities Maintain and optimise SOC Protect, Detect and Respond ...

CSOC Consultant

Hiring Organisation
Experis
Location
Corsham, Wiltshire, United Kingdom
Employment Type
Contract
Contract Rate
£700 - £750/day Inside IR35
opportunity to play a key role in protecting critical systems and services, working alongside security, infrastructure, and cloud teams to enhance security monitoring, incident response, threat detection, and operational resilience. The successful candidate will bring a strong background in cyber security operations, ideally gained within Defence, Government … other highly regulated environments. Responsibilities Support the operation and continual improvement of cyber security monitoring and incident response capabilities. Investigate and manage cyber security incidents, ensuring appropriate containment, remediation, and reporting. Analyse security alerts, events, and threat intelligence to identify potential risks and vulnerabilities. Develop and refine detection ...

Senior Security Engineer

Hiring Organisation
Richmond Square Consulting Limited
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
experience. This is a senior, hands-on role working across firewalling, on-premise and cloud security, secure infrastructure, network security, workload segmentation, hardening, monitoring, incident response and security architecture. The environment is highly secure and regulated, with a strong focus on enterprise firewalling, Elastic/Elasticsearch, VMware-based … Server environments, Active Directory, Group Policy and endpoint configurations Implementing, auditing and remediating against CIS Benchmarks, STIGs and security hardening standards Supporting vulnerability management, incident response, root cause analysis and remediation planning Embedding security into DevSecOps/CI/CD practices, including automated security testing and policy ...

Systems Engineer (AWS)

Hiring Organisation
Elsevier
Location
Greater London, United Kingdom
Employment Type
Full Time
able to translate complex technical concepts into clear, meaningful communications that resonate with a range of audiences? Do you have experience supporting system reliability, incident response and continuous improvement within cloud-based environments? Location: [Remote] About the team A&G, STMJ Technology is a global team that builds … change and release activities. Through collaboration and problem-solving, you will help improve system reliability, enhance monitoring and alerting capabilities, and support effective incident response and recovery. Key Responsibilities - Monitor system health and respond to alerts to maintain stability and performance - Support troubleshooting and resolution of system ...

IT Security Manager London Hybrid Financial Services £750/800d

Hiring Organisation
Adecco
Location
City of London, London, United Kingdom
Employment Type
Contract
Contract Rate
£750 - £800/day
intersection of cyber leadership, risk governance, and business engagement . This is a people-focused leadership role , managing a capable, self-sufficient team across incident response, engineering, and architecture-while acting as a key deputy to the CISO (EMEA). Key Responsibilities Lead and manage cyber teams across … incident response, engineering, and architecture Act as deputy to CISO , supporting risk, governance, and leadership forums Oversee incident response , providing executive-level updates Ensure security controls and architecture align to CISO strategy and risk appetite Manage senior stakeholders (CIO, COO, CFO) and translate risk into business ...

IT Security Manager London Hybrid Financial Services £750/800d

Hiring Organisation
Adecco
Location
London, South East, England, United Kingdom
Employment Type
Contractor
Contract Rate
£750 - £800 per day
intersection of cyber leadership, risk governance, and business engagement . This is a people-focused leadership role , managing a capable, self-sufficient team across incident response, engineering, and architecture-while acting as a key deputy to the CISO (EMEA). Key Responsibilities Lead and manage cyber teams across … incident response, engineering, and architecture Act as deputy to CISO , supporting risk, governance, and leadership forums Oversee incident response , providing executive-level updates Ensure security controls and architecture align to CISO strategy and risk appetite Manage senior stakeholders (CIO, COO, CFO) and translate risk into business ...

SC Cleared - Cybersecurity Consultant - Remote - 3 Month Rolling Contract

Hiring Organisation
The Huntsmith Limited
Location
London, South East, England, United Kingdom
Employment Type
Contractor
Contract Rate
Salary negotiable
frameworks such as NIST CSF, IEC 62443 and other recognised industry standards. Assess critical network infrastructure, including segmentation, remote access, identity, monitoring, resilience and incident response capabilities. Review OT architecture, asset inventories, data flows, firewall rules, network zones and conduits. Identify security gaps, operational risks, vulnerabilities and control … senior business stakeholders. Produce high-quality client deliverables, including assessment reports, risk registers, maturity scorecards, architecture recommendations and implementation roadmaps. Contribute to OT incident response planning, tabletop exercises, cyber resilience testing and recovery planning. Support pre-sales activity, including solution shaping, proposal input and client presentations where required. ...

OT Analyst/Technician

Hiring Organisation
Centrica - CHP
Location
Windsor, Berkshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
control systems remain secure, compliant and operationally robust. You'll work closely with engineers, cybersecurity specialists, and external partners to monitor OT environments, support incident response, maintain asset and patch records, and contribute to risk, compliance and audit activities. The role also supports the ongoing improvement … safe, secure and continuous delivery of energy to millions. Location: UK-based hybrid role, Occasional travel to site. Day to day Support OT cybersecurity incident response, including investigation, evidence gathering, containment, remediation, and technical actions such as system isolation and patching, under CSIRT and GSOC guidance. Operate ...

OT Security Engineer

Hiring Organisation
Sanderson Recruitment
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Contract
Contract Rate
£500 - £550 per day
system environments. This role sits within a Security Operations function but is heavily engineering focused, combining hands on OT security tooling, detection engineering and incident response to strengthen resilience across critical infrastructure. Key Responsibilities: Act as the OT security engineering SME, supporting both operational and project based activities … equivalent) Develop and refine detection rules, alerting logic and monitoring coverage across OT and IT/OT convergence points Lead technical investigations and incident response for OT-related cyber events Analyse industrial network traffic to identify anomalies, threats and protocol misuse Integrate OT telemetry into SIEM ...

OT Security Engineer

Hiring Organisation
Sanderson Recruitment
Location
United Kingdom
system environments. This role sits within a Security Operations function but is heavily engineering focused, combining hands on OT security tooling, detection engineering and incident response to strengthen resilience across critical infrastructure. Key Responsibilities: Act as the OT security engineering SME, supporting both operational and project based activities … equivalent) Develop and refine detection rules, alerting logic and monitoring coverage across OT and IT/OT convergence points Lead technical investigations and incident response for OT-related cyber events Analyse industrial network traffic to identify anomalies, threats and protocol misuse Integrate OT telemetry into SIEM ...

Cyber Security Engineer

Hiring Organisation
DCV Technologies Limited
Location
Tring, Hertfordshire, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
network estate (including Cisco Meraki). The role is hands-on and operational, partnering with IT teams to implement security controls, support monitoring and incident response through Sophos MDR, and improve cyber resilience by supporting Disaster Recovery (DR) testing and Business Continuity (BC) readiness. Key Responsibilities Cloud Security … ensure changes follow change control. Enable and review network security logging/alerting (e.g., syslog/SIEM integrations where applicable). Monitoring, Detection & Incident Response (Sophos MDR) Act as the internal technical point of contact for Sophos MDR and ensure smooth collaboration with MDR analysts. Maintain coverage ...

SOC Shift Lead

Hiring Organisation
Sopra Steria
Location
Hemel Hempstead, Hertfordshire, South East, United Kingdom
Employment Type
Permanent
Salary
£75,000
Lead SOC Analyst to help protect multiple critical client environments. The role offers real variety and continued hands-on involvement, combining leadership with incident response, threat detection, and operational delivery. We will also consider experienced SOC professionals who are ready to step into a leadership position while remaining …/7 SOC, acting as the primary escalation point for complex incidents, supporting operational delivery, and helping to mature our detection and response capabilities across multiple clients. This role is site-based in Hemel Hempstead and follows a shift pattern of two day shifts (6am6pm), two night shifts (6pm6am ...

Senior Detection and Response Engineer

Hiring Organisation
eBay
Location
Greater London, United Kingdom
Employment Type
Full Time
with world-class teams including SOC, engineering, HR/Legal, and other security teams to reduce risk and secure eBays global marketplace. Responsibilities Lead incident response across a broad range of scenarios including external intrusion, insider threats, and misuse involving endpoints, identity, cloud, Kubernetes/container layers … eradication, and recovery. Apply a threat-modeling approach to new systems, infrastructure, and features. Identify potential issues, the signals needed to detect them, and response methods. Then translate these into specific telemetry and response requirements for engineering teams. Build and improve detections by developing, tuning, and maintaining SIEM ...

Cyber Security Consultant

Hiring Organisation
CBSbutler Holdings Limited trading as CBSbutler
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
GBP 550 - 580 Daily
Cyber Security Consultant - Incident and Vulnerability Management +6 months + +1 day a week on site in London/Preston/Birmingham - 4 days WFH +Inside IR35 + 550 - 580 a day +SC cleared role - must have current active clearance +Sole British nationals only due to nature … project Role Description: Security Incident & Vulnerability Management Consultant (Operational Integrator/SIAM - Transition Role) UK Sole National ONLY Security Clearance required Role Summary The Security Incident & Vulnerability Management Consultant operates within the Operational Integrator (OI) function to support the transition to a multi-supplier (SIAM) model within ...

IT Disaster Recovery & Business Continuity Manager

Hiring Organisation
Yorkshire Water
Location
Bradford, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent, Work From Home
business continuity requirements. Drive accountability by maintaining clear roles, responsibilities and escalation paths across IT and business teams, ensuring a coordinated and effective response during incidents. Review test outcomes, identify lessons learned and champion continuous improvement initiatives that enhance resilience and recovery capability across the organisation. Monitor and assess … continuity dependencies. Provide meaningful governance, reporting and assurance to senior stakeholders on DR and BC readiness, resilience posture, identified risks and remediation activity. Ensure incident response, cyber resilience and major incident management processes integrate seamlessly with the wider DR and BC framework. Act as a key leader ...

Head of Security

Hiring Organisation
Jobleads-UK
Location
United Kingdom
teams, and remediation within SLA — and manage external pen tests and targeted assessments. Report regularly on status, SLA performance, and trends. Security operations and incident response: Manage our MSSP partner for 24/7 SIEM and SOC monitoring; ensure telemetry, detections, and playbooks match our threat model. Serve … incident commander for real events, and run regular tabletops and post‐incident reviews. Policy, controls, and risk: Define and maintain Reach’s security policies and control framework. Design, implement, and measure the effectiveness of controls; maintain a risk register; and surface material risk decisions to leadership. Compliance ...