276 to 300 of 1,874 Incident Response Jobs in the UK

Information Security Officer

Location
Salford, England, United Kingdom
mobile) are configured securely. Vulnerability Management: Run and remediate vulnerability scans; don’t just report the issues; help figure out how to fix them. Incident Response: Be a key part of our incident response team, investigating alerts and refining our "playbooks" for future threats. Identity & Access ...

Naimuri - Information Security Officer

Location
Manchester, England, United Kingdom
mobile) are configured securely. Vulnerability Management: Run and remediate vulnerability scans; don’t just report the issues; help figure out how to fix them. Incident Response: Be a key part of our incident response team, investigating alerts and refining our \"playbooks\" for future threats. Identity & Access ...

Senior Security Operations Centre Analyst

Location
Farnborough, England, United Kingdom
capabilities, develop your expertise, and work with cutting-edge security technologies in a fast-paced operational environment. If you’re passionate about threat detection, incident response, and staying one step ahead of attackers, we'd love to hear from you. Office based: Farnborough. Clearance: You do need … triage and investigate security incidents across critical client environments. Analyse network traffic, logs and security events to identify threats and vulnerabilities. Lead and support incident response activities, providing expert guidance on containment, eradication and recovery. Enhance detection rules and use cases using MITRE ATT&CK and threat-informed ...

Senior Security Operations Centre Analyst

Hiring Organisation
Sopra Steria
Location
United Kingdom
Employment Type
Permanent
Salary
GBP Annual
help protect systems that matter. Apply today and take your cyber security career to the next level. If you're passionate about threat detection, incident response, and staying one step ahead of attackers, we'd love to hear from you. Office based: Farnborough. Clearance: You do need … triage and investigate security incidents across critical client environments. Analyse network traffic, logs and security events to identify threats and vulnerabilities. Lead and support incident response activities, providing expert guidance on containment, eradication and recovery. Enhance detection rules and use cases using MITRE ATT&CK and threat-informed ...

Security Engineer

Location
Redhill, England, United Kingdom
internal and customer networks and systems. The role will work closely with Security, IT, Compliance and Engineering teams, providing technical expertise in network security, incident response, vulnerability management and security monitoring. The successful candidate will act as a key technical authority and provide third-line support for complex … device security. Monitor and investigate security events using SIEM, IDS/IPS and other security tools. Investigate and resolve security incidents and provide incident response support. Manage vulnerabilities and support penetration testing and security assessments. Provide through-life cybersecurity support and recommend improvements. Provide third-line technical support ...

Lead SRE - AWS,Python

Location
Glasgow, Scotland, United Kingdom
availability and performance standards Define and enforce service level objectives, error budgets, and reliability targets in partnership with engineering and product stakeholders Drive incident response, root cause analysis, and post-incident reviews to identify systemic improvements and reduce mean time to recovery Develop and maintain automation frameworks … tooling decisions to ensure alignment with reliability, scalability, and security requirements Leverage enterprise-authorized AI-assisted engineering practices to improve operational outcomes, including incident triage support, test strategy acceleration, and delivery workflow optimization, while ensuring consistent validation and secure handling of inputs and outputs Required Qualifications, Capabilities, And Skills ...

Senior Security Engineer, Detection and Response

Location
Greater London, England, United Kingdom
integrity, ensuring trust and accountability. Employees, researchers, customers, and partners Win Together by fostering empowerment, inclusion, respect, and accountability. Senior Security Engineer, Detection and Response Remote Location: Austin TX, Seattle, WA, Washington, DC, San Francisco, CA, Boston, MA Position Summary At HackerOne, we’re rebuilding our Detection & Response … function with an AI-first approach—focused on engineering, not just triage. As a Senior Security Engineer, you will design and deliver detection and response capabilities that protect a modern, cloud-native environment by writing code, building AI-powered tooling, and automating workflows end-to-end. This role operates ...

Site Reliability Engineer

Location
Newcastle upon Tyne, England, United Kingdom
increase operational efficiency and reduce manual intervention. Evaluate system designs and architectures for reliability, performance, security, and efficiency, ensuring best practices are followed. Lead incident response efforts and conduct deep-dive root cause analysis to implement long-term, innovative technical solutions. Develop and maintain comprehensive runbooks and procedures … incident response and operational tasks. Collaborate with cross-functional teams to review and provide feedback on technical designs, ensuring alignment with SRE principles. Participate in on-call rotations and handle critical incidents with confidence and expertise. Continuously improve documentation for systems and services, contributing to a knowledge-sharing ...

SOC Automation Engineer

Location
Pocklington, England, United Kingdom
focused on designing, developing and enhancing security automation solutions that improve the effectiveness, efficiency and scalability of SOC operations. Working closely with SOC Analysts, Incident Responders and Service Owners, you will help automate security processes, streamline investigations and improve customer outcomes through intelligent automation and orchestration. What will … doing? Design, develop and maintain security automation workflows to support SOC operations. Create and optimise automated playbooks that improve detection, triage, enrichment and response activities. Work closely with SOC, engineering and service delivery teams to understand operational requirements and deliver automation solutions. Build and maintain integrations with security technologies ...

Senior Detection and Response Engineer

Location
Cambridge, England, United Kingdom
queries and monitoring logic across cloud, endpoint, network and application environments. Develop tooling and automation to improve security telemetry, alert enrichment, investigation workflows and response times. Conduct threat hunting using adversary behaviours, TTPs and frameworks such as MITRE ATT&CK, incorporating findings into security controls and detections. Create … continuously improve incident runbooks, playbooks and detection processes based on findings from real-world investigations. Work with the external SOC and internal engineering teams to strengthen monitoring coverage, investigate escalations and continuously improve detection and response capability. Participate in an on-call rotation. Requirements Hands-on experience investigating ...

Cyber Security Analyst

Location
Quintrell Downs, England, United Kingdom
between KSC and university campuses in London). Accountabilities & Responsibilities You will be responsible for: Queue Management – day-to-day management of the security incident/service request queue in alignment with SLA, identifying recurring issues, inefficiencies and opportunities for process improvement. Security Incident Response & Digital Investigations … including but not limited IPS/IDS, firewalls and end user protections. Operational Improvement & Security Engineering Support – Participating in security operational activities including monitoring, incident response and on-call duties to identify opportunities for improvements in processes, detections, automation and security controls. Working with colleagues across Cyber Operations ...

IT Operations Manager

Location
Birmingham, England, United Kingdom
compliance, and a positive customer experience. The post holder will lead operational teams, manage service delivery processes, oversee infrastructure and cloud operations, coordinate major incident response, and ensure operational readiness across all supported services. Key Responsibilities People and Operational Leadership Lead and manage service desk, infrastructure, and cloud … Cyber Essentials Plus requirements. Oversee operational security controls including access reviews, vulnerability remediation, patch compliance, and monitoring activities. Participate in incident response, disaster recovery, and business continuity exercises. Ensure audit evidence, service records, and operational documentation are accurate and maintained. Promote a culture where security, compliance, and risk ...

Cyber Security Engineer

Location
City Of London, England, United Kingdom
implement, and continuously refine preferably automated tooling and reporting to perform some level of dynamic penetration testing of systems and reporting of vulnerabilities. Lead incident response activities, including detection, containment, eradication, and recovery. Conduct forensic investigations and post‐incident reviews, reporting findings to senior management. When … come under new or sustained attack, be front and centre owning our response and mitigation, taking the lead and organising across technology to repel the attempted intrusion. Identify, evaluate, and mitigate cyber risks related to PSP operations, including payment processing systems, customer data, and third‐party integrations. Conduct regular ...

SOC Subject Matter Expert (UK)

Location
Horsham, England, United Kingdom
Their primary responsibility lies in translating SOC analyst pain points, workflows, and use cases into actionable product features, with particular focus on alert/incident prioritisation and intelligent playbook execution that helps analysts make critical security decisions. Their responsibilities will include: Providing expert SOC operational guidance to product management … operational needs. Translating SOC analyst pain points, workflows, and use cases into actionable product features and user stories. Designing and validating alert prioritisation algorithms, incident triage workflows, and automated playbook logic based on operational experience. Collaborating with product managers to shape product strategy, roadmap priorities, and feature definitions. Conducting ...

Principal Security Design Consultant

Location
Greater London, England, United Kingdom
source onboarding, data connector, normalisation, retention, ingestion, cost-management and data-residency requirements across cloud, on-premises and third-party services. Develop detection and response architectures covering analytics rules, MITRE ATT&CK-aligned use cases, threat hunting, workbooks, watchlists, automation and SOAR playbooks. Design secure integrations with ITSM, CMDB … threat intelligence, vulnerability management, identity, network and incident response processes. Produce and own architecture artefacts including requirements, High-Level Designs (HLDs), Low-Level Designs (LLDs), reference patterns, design decisions, migration roadmaps, test criteria and as-built assurance. Broader security architecture: Lead architecture reviews and design engagements across cloud ...

L3 Security Analyst

Location
Newbury, England, United Kingdom
role in protecting millions of customers from global cyber threats. As a Level 3 Security Analyst, you’ll be at the forefront of advanced incident response, tackling complex security challenges and driving continuous improvement in our cyber defence posture. You’ll investigate and validate threats using cutting‐edge … tools, collaborate with global teams on incident investigations, and mentor colleagues to uplift skills across the CSOC. From fine‐tuning SIEM systems and automating response actions to delivering insightful security reports and advisories, your expertise will help shape Vodafone’s resilience against evolving threats. This is a role ...

NMC Cyber Incident Responder (Digital Forensics)

Location
Wigan, England, United Kingdom
# NMC Cyber Incident Responder (Digital Forensics)*Police Digital Service***Wigan, England**Hybrid · Senior · Full-time### The RoleWorking within a National Management Centre Cyber Incident Response team, the role involves leading investigations into ransomware, malware, unauthorised access and insider threat incidents affecting UK policing. … analysis of endpoints, servers and cloud environments, producing defensible findings for operational and legal audiences, and briefing Chief Officers and senior IT leaders throughout incident lifecycles.### Skills & ExperienceCandidates should have hands-on experience in enterprise digital forensic investigations, endpoint and memory forensics, and log analysis using EDR telemetry ...

Director of DevOps & SRE

Location
Greater London, England, United Kingdom
access. Enterprise directory services, role-based and privileged access controls, Auth0 machine-to-machine credentials, and least-privilege access across engineering and QA. Incident response and resilience. Escalation paths, root-cause analysis and postmortems, production readiness reviews, automated failover, and our disaster recovery and RTO/RPO commitments. … background (GitHub Actions and/or Azure DevOps Pipelines) and infrastructure as code with Terraform, including module development and state management. Production support and incident response experience for a multi-tenant SaaS platform. Containerisation and orchestration in production (Docker, Kubernetes). Solid grounding in identity and access management ...

Principal Cyber Security Analyst (IAM)

Location
Glasgow, Scotland, United Kingdom
Cyber Security Analysts protect the confidentiality, integrity and availability of government information and systems. They provide expert cyber security leadership, manage cyber threats and incident response, influence senior stakeholders, and deliver trusted advice on security controls and best practice. They also oversee cyber security operations, including team leadership … develop the Identity and Access Management (IAM) team, establishing governance, standards and performance metrics to drive effective identity security, access control, threat detection, response and continuous capability improvement in line with organisational risk appetite and a cloud-first strategy. Own and optimise the organisation's IAM tooling and security ...

Senior Incident Response Lead & Systems Integrator

Location
England, United Kingdom
cybersecurity solutions provider is seeking an Incident Response Consultant in the Midlands. The role involves leading the response to security incidents, analyzing logs, and developing strategies to improve resilience against cyber threats. Applicants must have SOC experience and good communication skills, with a base salary between ...

Cyber Security Engineer - Threat Detection

Location
Greater London, England, United Kingdom
detection content that security operation teams depend on, and hunt proactively for threats that existing controls do not catch, working alongside threat intelligence, incident response, and red team functions to keep coverage grounded in real adversary behavior. Job Description Job Purpose The ICE Cybersecurity Threat Detection team … detection content that security operation teams depend on, and hunt proactively for threats that existing controls do not catch, working alongside threat intelligence, incident response, and red team functions to keep coverage grounded in real adversary behavior. Responsibilities Detection Engineering - Design, build, test, and maintain detection content across ...

Cyber Security Engineer - Assistant Vice President

Location
Greater London, England, United Kingdom
maintain of workspaces, including data connectors, Logic App, Function App, analytics rules, workbooks, and playbooks. Develop and refine custom queries for advanced threat hunting, incident investigation, and reporting. Optimize SIEM performance, cost, and data retention policies Identify new log sources work closely with infrastructure teams Identify, onboard, and configure … detect anomalies and incidents across the applications and infrastructure estate. Collaborate with SOC team to enrich detection logic based on known vulnerabilities and misconfigurations. Incident Response & Security Operations: Formulate proactive threat hunting rule based on emerging threats and intelligence. Contribute to the development and improvement of security playbooks ...

Senior IT Technician - Cyber Security

Location
Rotherham, England, United Kingdom
standard IT tickets and more complex ones. You will identify tickets relating to security vulnerabilities, threats, and non-compliant devices and assist in the response to security incidents and investigations. You will work with the Cyber Security and Systems Managers to identify trends and seek to implement proactive, long … AMRC IT, University Information Security, and other stakeholders across the organisation. Projects: Provide technical input for projects needing tailored security or enhanced standards. Technical Incident Response Support: As an important member of the AMRC IT Support team you will carry out some regular support activities, but will focus ...

Cyber Security & Infrastructure Engineer

Hiring Organisation
Adria Solutions
Location
Newcastle-upon-Tyne, Tyne and Wear, North East, United Kingdom
Employment Type
Permanent
Salary
£50,000
their systems, networks and data. This is a hands-on position offering the opportunity to work across cyber security, infrastructure, cloud, threat detection and incident response within a small, technically capable IT team. The Role As Cyber Security & Infrastructure Engineer, you will be responsible for maintaining and improving … with internal teams and third-party suppliers to improve security, resilience and operational performance. Key Responsibilities Monitor security alerts, investigate potential incidents and lead incident response activities Conduct forensic investigations and contribute to threat detection and intelligence activities Develop and refine security monitoring, detection rules and use cases ...

devops engineer in low-latency trading infrastructure

Location
Greater London, England, United Kingdom
configuration, database schema creation, and operational workflows across cloud and on-premises platforms; Support production systems with a focus on high availability, disaster recovery, incident response, vulnerability management, patching, and change management; Containerize applications and support deployments using container orchestration platforms; Partner with development teams to understand application … engineering tools to accelerate development, automation, troubleshooting, documentation, and operational workflows; Identify, design, and help implement AI-enabled operational capabilities for infrastructure automation, observability, incident response, and platform engineering; Contribute to the strategy for safe, practical, and secure adoption of AI across infrastructure and DevOps practices; Lead ...