326 to 350 of 1,868 Incident Response Jobs in the UK

Cyber Security Manager (Public Sector & Defence)

Hiring Organisation
Searchability NS&D
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£85,000 - £95,000 per annum
complex security concepts to technical and non-technical audiences Advising on security architectures, controls and technologies Developing cyber security strategies and implementation roadmaps Supporting incident response and business continuity planning Applying frameworks including NIST, ISO 27001, CIS and CAF Providing specialist advice across complex Defence and Government environments … Security environments Knowledge of security frameworks including NIST, ISO 27001, CIS or CAF Experience within areas such as security architecture, cyber risk, vulnerability management, incident response, security monitoring or threat intelligence Strong stakeholder management and client-facing communication skills Understanding of network security, encryption, authentication and access controls ...

Chief Information Security Officer (CISO)

Location
England, United Kingdom
maintaining regulatory compliance and client trust. You will act as the organisation's subject matter expert for information security, data protection, risk management, and incident response. What you will do? Develop and own the organisation's information security strategy, roadmap, and risk management framework. Working with our MSSP, lead … response to security incidents, coordinating investigations, remediation activities, and stakeholder communications. Working with our Group Legal and colleagues, implement effective risk and compliance governance to ensure GDPR and data protection compliance, including DPIAs, data processing agreements, and data subject requests. Ensure compliance with Solicitors Regulation Authority (SRA) requirements ...

IT Infrastructure and Security Engineer · Colchester ·

Location
Colchester, England, United Kingdom
troubleshooting and resolution in line with SLAs Create and maintain technical documentation, policies, and procedures, ensuring smooth handover to Service Desk teams. Lead the incident response lifecycle, including managing security incidents and data breach containment, eradication, and post-mortem analysis. Serve as a dedicated Tier 3 escalation point … framework. Monitor, investigate, and remediate security alerts, incidents, and Indicators of Compromise (IOCs). Conduct threat analysis to address new and emerging risks; deploy response strategies to mitigate vulnerabilities. Manage and optimise security tools, including Next-Gen SIEM, SOAR, EDR/MDR/XDR, and cloud security solutions (CASB ...

Information Security Manager Sotheby's · London · On-site · · Yesterday Technology & Digital

Location
Greater London, England, United Kingdom
risk assessments and security reviews, procuring infosec tools, managing projects, drafting policies and processes, conducting risk management meetings, designing controls, overseeing auditors, and leading incident response. And as a key part of a team dedicated to continuous improvement, you will help us get better every day. You obsess over … registers, support assessments, and monitor remediation progress Plan, lead, and execute control validation and testing activities across various domains (e.g., access management, vulnerability management, incident response, data protection) Mentor junior analysts and engineers, providing guidance on control validation methodologies and best practices while fostering a culture of accountability ...

CYBER SECURITY ANALYST L4

Location
Warwick, England, United Kingdom
changing world. For additional information, visit us at www.wipro.com. Job Description Role Purpose The purpose of this role is to analyze attack patterns, develop incident response plans, ensure audit readiness, and implement disaster recovery measures, to ensure adherence to cyber security regulatory frameworks. Areas of responsibility Monitoring … Incident Detection-Analyse attack trends and correlate logs across systems to identify advance threats. Enhance monitoring processes and implement improvements for faster detection, to ensure compliance with security frameworks and regulatory standards. Incident Handling and Analysis-Perform root cause analysis, create incident response plans and implement ...

Senior Platform Engineer, Foundations

Location
Greater London, England, United Kingdom
cloud environments using infrastructure as code and repeatable automation Improve production reliability through well-defined SLOs, graceful degradation, self-healing, automated recovery, and effective incident response Create self-service workflows and platform abstractions that reduce cognitive load and help R&D teams ship and operate software more effectively … networking Experience administering and scaling multi-tenant Kubernetes clusters and streaming platforms such as Kafka in production, including upgrades, workload isolation, reliability, security, and incident response Experience building and maintaining infrastructure as code, pipeline-as-code, containerization, and cloud-native systems using tools such as Terraform, Helm, Ansible ...

Senior SOC Analyst — Incident Response Lead

Location
North East, England, United Kingdom
seeking a Senior SOC Analyst - Incident Response to lead complex, high-severity investigations across a large enterprise. You will own investigations end-to-end, shape critical response decisions and strengthen detection, containment and lessons across the organisation. Reporting to the SOC Manager, you will mentor junior analysts ...

Blockchain Cyber Intelligence Vice President

Location
Greater London, England, United Kingdom
vulnerabilities and compromises, utilizing advanced tools and techniques to detect anomalies and contribute to the development of strategies for security investigation, threat mitigation, and incident response Produce actionable threat intelligence products including IOC development, exploit analysis reports, and threat actor tracking to inform detection engineering and security operations … Computer Science, Cybersecurity, Data Science, or related disciplines 5+ years of experience in cybersecurity threat intelligence or operations, with a focus on threat detection, incident response, and security infrastructure management Demonstrated expertise in multiple security domains, including network security, malware analysis, threat hunting, threat intelligence production, and security ...

Security Pre-Sales Consultant - Cyber Security

Location
England, United Kingdom
Must have 2+ years in Pre-Sales or similar role within an MSP/Reseller organisation Previous experience being part of or working with incident response teams would be beneficial Good understanding of incident response stages and handling preferred Knowledge and/or experience using endpoint ...

IT Systems Engineer

Location
Kidlington, England, United Kingdom
corporate IT environment Support vulnerability remediation, endpoint security and technical cyber security controls Take an active role in security monitoring, vulnerability management and incident response Support the development of internal security operations capability as the UK IT function matures Contribute to the design and implementation of secure … with endpoint security, vulnerability remediation and patch‐management tooling Good understanding of cloud platforms, particularly Microsoft Azure Experience with security monitoring, vulnerability management or incident response Familiarity with SIEM, EDR/XDR or SOC tooling Strong troubleshooting, documentation and communication skills Qualifications Relevant degree, technical qualification, apprenticeship ...

Senior SOC Shift Lead - 24/7 Incident Response

Location
Greater London, England, United Kingdom
慨正橡扯 is seeking a SOC Shift Lead to oversee incident investigation and analysis in London. This role involves leading teams in responding to high-severity incidents and mentoring analysts. The ideal candidate will possess 7–10 years of experience in SOC or Incident Response and hold ...

SOC Analyst (MS Sentinel & Defender, SC Cleared)

Location
Harlow, England, United Kingdom
Demonstrable experience as a SOC Analyst Strong hands-on experience with SIEM, including Microsoft Sentinel Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations … Technical Exposure: IBM QRadar Microsoft Defender/EDRMicrosoft Sentinel (essential) Microsoft Entra ID/Azure AD Email threat response Incident Experience: Phishing & Business Email Compromise Malware & Ransomware Account Compromise Privilege Escalation Insider Threats DLP & Data Exfiltration Alerts Suspicious Authentication Activity Knowledge of: MITRE ATT&CK, Cyber Kill Chain ...

SOC Analyst

Location
Harlow, England, United Kingdom
Requirements: 2-3+ years' SOC experience Strong hands-on experience with IBM QRadar SIEM Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations … Technical Exposure: IBM QRadar Microsoft Defender/EDR Microsoft Sentinel (desirable) Microsoft Entra ID/Azure AD Email threat response Incident Experience: Phishing & Business Email Compromise Malware & Ransomware Account Compromise Privilege Escalation Insider Threats DLP & Data Exfiltration Alerts Suspicious Authentication Activity Knowledge of: MITRE ATT&CK, Cyber Kill ...

Senior Security Operations Analyst

Hiring Organisation
DGH Recruitment
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£90,000
root cause analysis, and implementation of corrective actions to maintain service reliability and security. Required Skills: * 5+ years in Security Operations/SOC or Incident Response, including in a 247 or global environment. * Proven experience across incident response, alert triage, threat hunting, data loss prevention ...

Senior Network Security Engineer: Incident Response

Location
Redhill, England, United Kingdom
monitor cybersecurity across internal and customer networks and systems. You will work with Security, IT, Compliance and Engineering teams to provide expert guidance and incident response support. The role requires hands-on experience with Cisco Firewalls, Juniper, SIEM and IDS/IPS, plus vulnerability management and secure network ...

Security Operations Lead - Incident Response & Compliance

Location
Glasgow, Scotland, United Kingdom
Aggreko in Glasgow is seeking a Security Operations Team Lead to steer a global security operations function, drive incident response, and lead strategic security initiatives across the organisation. You will manage agile teams, align with ISO27001, Cyber Essentials Plus, NIS-2 and SOX audits, and hands ...

Senior SOC Analyst | SIEM, Incident Response, SC Cleared

Location
West Midlands, England, United Kingdom
busy team in the United Kingdom. You will bring a minimum of five years' SOC experience, mentor junior staff, and contribute to rapid incident response and threat detection. This role emphasizes hands-on SIEM work (Splunk, MS Sentinel), log analysis (Wireshark), and strong knowledge of Windows and Linux ...

Senior Cyber Incident Response Lead

Location
Greater London, England, United Kingdom
Methods is seeking a Senior Cyber Analyst to lead complex investigations and incident response, providing strategic direction to maintain a robust security posture for clients. You will own detection rules and playbooks for Microsoft Sentinel, Defender XDR, SIEM, SOAR, EDR and XDR, while mentoring the Cyber Services team. ...

Hybrid SOC Lead — Threat Hunting & Incident Response

Location
Reading, England, United Kingdom
investigations, drive threat detection enhancements, and lead a team across SIEM, EDR, and SOAR platforms in a hybrid UK-based role. The role emphasizes incident response, forensics, automation, and CI/CD security, with collaboration across DevOps, IT, and development teams to strengthen the organisation's security posture. ...

Blockchain Security Operations Vice President

Location
Greater London, England, United Kingdom
vulnerabilities and compromises, utilizing advanced tools and techniques to detect anomalies and contribute to the development of strategies for security investigation, threat mitigation, and incident response Collaborate with cross-functional teams to ensure a coordinated approach to blockchain and enterprise security, sharing insights, and promoting best practices across … Degree in Computer Science, Cybersecurity, Data Science, or related disciplines 5+ years of experience in cybersecurity operations, with a focus on threat detection, incident response, and security infrastructure management Demonstrated expertise in multiple security domains, including network security, malware analysis, threat hunting, and security architecture and design, with ...

Azure Security Engineer — SIEM, XDR & Incident Response (Contract)

Location
Greater London, England, United Kingdom
Flagstone is seeking a senior security engineer to own and operate detection and incident response across our Azure cloud security stack. You will work hands-on with Microsoft Sentinel, Defender for Cloud, and XDR tooling, while coordinating remediation with engineering squads. You'll drive security through code, pipelines ...

Security Detection Engineer

Hiring Organisation
McCabe & Barton
Location
London, United Kingdom
Employment Type
Contract
Experienced building detection rules (SIEM, EDR, or cloud-native tooling) Deep understanding of attack patterns (MITRE ATT&CK framework) SOC operations, threat analysis, or incident response Datadog & Cloud Monitoring Hands-on Datadog OR equivalent Sentinel/SIEM experience Azure Monitor and Log Analytics familiarity GCP Cloud Logging … similar) Security & Compliance Knowledge of financial services threats (insider threats, data theft, credential abuse) Understanding of regulatory requirements (DORA, FCA, SOC2) Familiarity with incident response frameworks Comfortable in 24/7 on-call environment during integration crisis period Ideal candidate: Seasoned Security engineer who can operate independently Experience ...

Blockchain Cyber Intelligence Vice President

Location
Greater London, England, United Kingdom
vulnerabilities and compromises, utilizing advanced tools and techniques to detect anomalies and contribute to the development of strategies for security investigation, threat mitigation, and incident response Produce actionable threat intelligence products including IOC development, exploit analysis reports, and threat actor tracking to inform detection engineering and security operations … Computer Science, Cybersecurity, Data Science, or related disciplines 5+ years of experience in cybersecurity threat intelligence or operations, with a focus on threat detection, incident response, and security infrastructure management Demonstrated expertise in multiple security domains, including network security, malware analysis, threat hunting, threat intelligence production, and security ...

Senior Cyber Defence Analyst - Incident Response Lead

Location
Belfast City District, Northern Ireland, United Kingdom
Shearman, based in Belfast, seeks a Senior Cyber Defence Analyst to join its Information Security team. The role focuses on in-depth analysis, incident response, and guiding junior colleagues within a global firm. Weekend working is a requirement with premium pay for weekend hours; you will be part … follow-the-sun model, supporting threat detection, response, and continuous improvement of cyber defence processes. #J-18808-Ljbffr ...

Security Engineer

Location
Luton, England, United Kingdom
easyJet's information and information systems through effective security engineering, tooling and technical controls. Working closely with colleagues across Technology, Security Operations and Incident Response, you'll help ensure our security services remain resilient, effective and ready to support the evolving needs of the business. THE ROLE … security control improvement activities. Producing and maintaining technical documentation, runbooks and operational guidance. Supporting security investigations and remediation activities alongside Security Operations and Incident Response teams. Providing security-focused technical support and consultancy to Technology teams across the business. Contributing to the development and delivery of the security ...