426 to 450 of 2,252 Incident Response Jobs in the UK

Cyber Security Manager

Hiring Organisation
SAAB
Location
Fareham, Hampshire, United Kingdom
Salary
£ 70 K
wider government standards.Act as the Saab UK representative on the Global Cyber Council.Lead risk assessments, threat modelling, and vulnerability management within Saab Uk process.Manage incident response and coordinate with other company parties.Lead on the compliance of Cyber controls including DefStan 05-138, ISO 27001, NIST.Responsible for the completion … environments.Strong knowledge of classified information handling and secure communication protocols.Expertise in intrusion detection, SIEM tools, and advanced threat intelligence systems.Proven track record of leading incident response in high-security environments.Familiarity with defence-specific compliance frameworks (MOD JSPs, NIST SP 800 series, ITAR, GDPR).Excellent leadership, stakeholder management ...

Security & Network Engineer - 12 months Fixed term

Location
Maidenhead, England, United Kingdom
/CD pipelines Operational Delivery & Strategic Projects: Lead network delivery for strategic initiatives (e.g., data centre migrations, office relocations, cloud landing zones) Manage incident response for critical infrastructure events; lead post-mortems and remediation Collaborate with infrastructure teams to build monitoring, alerting, and observability stacks that surface security … configuration management (Ansible, etc.) Proficiency with network monitoring and observability tools (e.g., Splunk, Datadog, New Relic, Elasticsearch, Prometheus, RSA NetWitness, Tenable) Strong incident response and troubleshooting background; comfort operating in high-pressure environments Experience mentoring junior/mid-level engineers and building security culture within technical teams Desirable ...

Senior SOC Analyst

Hiring Organisation
Searchability NS&D
Location
Farnborough, England, United Kingdom
improve detection capabilities and contribute to the ongoing maturity of the SOC. You will also: Monitor and investigate security events across enterprise environments Perform incident response activities and support remediation efforts Analyse network traffic, endpoint activity and system logs Improve detection rules using MITRE ATT and CK techniques … application to our client in conjunction with this vacancy only. Key Skills SOC Analyst, Senior SOC Analyst, Security Operations Centre, Microsoft Sentinel, Splunk, SIEM, Incident Response, Threat Detection, Cyber Security, MITRE ATT and CK, Blue Team ...

SIEM Security Engineer

Location
Birmingham, England, United Kingdom
ingestion of our security information and event management (SIEM) system. Your focus will be on leveraging Elasticsearch and related technologies to enhance threat detection, incident response, and overall security posture. The role is hybrid (3 days in office) & based in Birmingham What you’ll be doing Data Ingestion … performance of the SIEM infrastructure. Security Engineering Contribute to security engineering projects, transitions, and transformations. Work closely with security operations and associated security incident response systems Stay informed about emerging threats and security best practices. Essential Skills/Experience Proven experience in SIEM Detection Engineering. Experience using cyber ...

Information Security Manager — Lead SOC & Incident Response

Location
England, United Kingdom
Kingdom is seeking an Information Security Manager to own and run the 1st line security operations, including SIEM, EDR, vulnerability management, identity security and incident response. You will work alongside the Information Security Officer, manage MSSP relationships, lead incident response, drive threat hunting, and deliver the security ...

SOC Manager

Location
Glasgow, Scotland, United Kingdom
organisations strengthen their security posture, protect critical assets, and deliver high-quality digital solutions. Our teams operate across multiple specialist disciplines, including Digital Forensics, Incident Response, SOC Operations, Quality & Compliance, and Technical Consultancy. We are committed to excellence, continuous improvement, and delivering trusted, customer-focused services that meet … complex transition projects (e.g., insourcing, offshore in-shore). Operational familiarity with CREST, NIS2, DORA, and the EU AI Act. Hands-on experience leading incident response, threat hunting, and investigations. Broad technical knowledge across Windows, Linux, cloud, hybrid environments, firewalls, EDR/XDR, IDS/IPS, VPNs ...

SOC Manager

Location
Birmingham, England, United Kingdom
organisations strengthen their security posture, protect critical assets, and deliver high-quality digital solutions. Our teams operate across multiple specialist disciplines, including Digital Forensics, Incident Response, SOC Operations, Quality & Compliance, and Technical Consultancy. We are committed to excellence, continuous improvement, and delivering trusted, customer-focused services that meet … complex transition projects (e.g., insourcing, offshore in-shore). Operational familiarity with CREST, NIS2, DORA, and the EU AI Act. Hands-on experience leading incident response, threat hunting, and investigations. Broad technical knowledge across Windows, Linux, cloud, hybrid environments, firewalls, EDR/XDR, IDS/IPS, VPNs ...

SOC Manager

Location
West of England, England, United Kingdom
organisations strengthen their security posture, protect critical assets, and deliver high-quality digital solutions. Our teams operate across multiple specialist disciplines, including Digital Forensics, Incident Response, SOC Operations, Quality & Compliance, and Technical Consultancy. We are committed to excellence, continuous improvement, and delivering trusted, customer-focused services that meet … complex transition projects (e.g., insourcing, offshore in-shore). Operational familiarity with CREST, NIS2, DORA, and the EU AI Act. Hands-on experience leading incident response, threat hunting, and investigations. Broad technical knowledge across Windows, Linux, cloud, hybrid environments, firewalls, EDR/XDR, IDS/IPS, VPNs ...

Senior SOC Analyst — Threat Detection & Incident Response

Location
City Of London, England, United Kingdom
Morgan in London is looking for a Security Operations Senior Associate to strengthen threat analysis and incident response across our cybersecurity program. You will detect, assess, and respond to threats, coordinating with cross-functional teams to improve security controls and awareness. The role requires hands-on experience with ...

Cyber Security Analyst TLNT1 NI

Hiring Organisation
HAYS Specialist Recruitment
Location
Belfast, UK
Compliance & Assurance Support cybersecurity compliance activities aligned to UK and European regulatory frameworks. Maintain compliance documentation, evidence repositories, and control registers. Assist with security incident reporting processes and regulatory obligations. Monitor emerging guidance and regulations, assessing their impact on the business. Cyber Assessment Framework (CAF) Participate in assessments against … Monitor emerging cyber threats associated with AI and advance awareness across the organisation. Cybersecurity Operations Support security monitoring and vulnerability management activities. Assist with incident response and cyber risk assessments. Contribute to supplier and third-party security reviews. Support the development of security policies, standards, and awareness initiatives. ...

SOC Analyst

Location
Harlow, England, United Kingdom
Requirements: 2-3+ years' SOC experience Strong hands-on experience with IBM QRadar SIEM Experience monitoring, triaging, and investigating security incidents Knowledge of incident response lifecycle and root cause analysis Experience with Microsoft Defender (essential) KQL knowledge desirable Ability to work independently and manage complex cyber investigations … Technical Exposure: IBM QRadar Microsoft Defender/EDR Microsoft Sentinel (desirable) Microsoft Entra ID/Azure AD Email threat response Incident Experience: Phishing & Business Email Compromise Malware & Ransomware Account Compromise Privilege Escalation Insider Threats DLP & Data Exfiltration Alerts Suspicious Authentication Activity Knowledge of: MITRE ATT&CK, Cyber Kill ...

Senior Security Operations Analyst

Hiring Organisation
DGH Recruitment
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£90,000
root cause analysis, and implementation of corrective actions to maintain service reliability and security. Required Skills: * 5+ years in Security Operations/SOC or Incident Response, including in a 247 or global environment. * Proven experience across incident response, alert triage, threat hunting, data loss prevention ...

Data & Cyber Associate: Incident Response & Insurance

Location
West of England, England, United Kingdom
Data & Cyber team advises insurers and corporates on breach response, policy interpretation and multi-insurer claims, combining incident response with regulatory engagement. Based in Bristol, the Associate/Senior Associate role supports partners, supervises juniors, and handles complex cyber coverage matters, including ransomware scenarios, data privacy issues ...

Chief Cyber Defence & Incident Response

Location
Greater London, England, United Kingdom
Doist is seeking a Head of Cyber Defence and Incident Response to own the organisation’s cyber defence across a hybrid environment. You will monitor, detect, respond and recover, reporting to the CISO and guiding cyber defence operations including the MSSP. Focus areas include optimising tooling (SIEM, SOAR …/XDR, NDR), vulnerability management, and threat intel-driven prioritisation. You will drive threat and incident management with governance, metrics, and executive updates. #J-18808-Ljbffr ...

Security Operations Lead - Remote (UK wide) TLNT1 NI

Hiring Organisation
Ocho
Location
Belfast, UK
security working group, setting priorities and driving resolution Translate threat intelligence into actionable engineering tasks and deliver monthly risk summaries to the ELT Vulnerability & Incident Management Own the full vulnerability lifecycle: discovery, triage, remediation, and reporting Coordinate incident response and set risk-based remediation timelines Security Tooling … classes (OWASP Top 10 and beyond) and practical experience with SAST, DAST, SCA, and secrets scanning tooling Proven end-to-end vulnerability management and incident response experience, including supply chain risk mitigation The ability to assess risk and make clear prioritisation calls, even with imperfect information A track ...

IT Infrastructure and Security Engineer · Colchester ·

Location
Colchester, England, United Kingdom
troubleshooting and resolution in line with SLAs Create and maintain technical documentation, policies, and procedures, ensuring smooth handover to Service Desk teams. Lead the incident response lifecycle, including managing security incidents and data breach containment, eradication, and post-mortem analysis. Serve as a dedicated Tier 3 escalation point … framework. Monitor, investigate, and remediate security alerts, incidents, and Indicators of Compromise (IOCs). Conduct threat analysis to address new and emerging risks; deploy response strategies to mitigate vulnerabilities. Manage and optimise security tools, including Next-Gen SIEM, SOAR, EDR/MDR/XDR, and cloud security solutions (CASB ...

Senior Security Operations Analyst

Location
Leeds, England, United Kingdom
root cause analysis, and implementation of corrective actions to maintain service reliability and security. Required Skills: 5+ years in Security Operations/SOC or Incident Response, including in a 24×7 or global environment. Proven experience across incident response, alert triage, threat hunting, data loss prevention ...

Senior Platform Engineer, Foundations

Location
Greater London, England, United Kingdom
cloud environments using infrastructure as code and repeatable automation Improve production reliability through well-defined SLOs, graceful degradation, self-healing, automated recovery, and effective incident response Create self-service workflows and platform abstractions that reduce cognitive load and help R&D teams ship and operate software more effectively … networking Experience administering and scaling multi-tenant Kubernetes clusters and streaming platforms such as Kafka in production, including upgrades, workload isolation, reliability, security, and incident response Experience building and maintaining infrastructure as code, pipeline-as-code, containerization, and cloud-native systems using tools such as Terraform, Helm, Ansible ...

Senior SOC Analyst — Incident Response Lead

Location
North East, England, United Kingdom
seeking a Senior SOC Analyst - Incident Response to lead complex, high-severity investigations across a large enterprise. You will own investigations end-to-end, shape critical response decisions and strengthen detection, containment and lessons across the organisation. Reporting to the SOC Manager, you will mentor junior analysts ...

Security Pre-Sales Consultant - Cyber Security

Location
England, United Kingdom
Must have 2+ years in Pre-Sales or similar role within an MSP/Reseller organisation Previous experience being part of or working with incident response teams would be beneficial Good understanding of incident response stages and handling preferred Knowledge and/or experience using endpoint ...

IT Systems Engineer

Location
United Kingdom
corporate IT environment Support vulnerability remediation, endpoint security and technical cyber security controls Take an active role in security monitoring, vulnerability management and incident response Support the development of internal security operations capability as the UK IT function matures Contribute to the design and implementation of secure … with endpoint security, vulnerability remediation and patch‐management tooling Good understanding of cloud platforms, particularly Microsoft Azure Experience with security monitoring, vulnerability management or incident response Familiarity with SIEM, EDR/XDR or SOC tooling Strong troubleshooting, documentation and communication skills Qualifications Relevant degree, technical qualification, apprenticeship ...

IT Systems Engineer

Location
Kidlington, England, United Kingdom
corporate IT environment Support vulnerability remediation, endpoint security and technical cyber security controls Take an active role in security monitoring, vulnerability management and incident response Support the development of internal security operations capability as the UK IT function matures Contribute to the design and implementation of secure … with endpoint security, vulnerability remediation and patch-management tooling Good understanding of cloud platforms, particularly Microsoft Azure Experience with security monitoring, vulnerability management or incident response Familiarity with SIEM, EDR/XDR or SOC tooling Strong troubleshooting, documentation and communication skills Qualifications Relevant degree, technical qualification, apprenticeship ...

Senior SOC Shift Lead - 24/7 Incident Response

Location
Greater London, England, United Kingdom
慨正橡扯 is seeking a SOC Shift Lead to oversee incident investigation and analysis in London. This role involves leading teams in responding to high-severity incidents and mentoring analysts. The ideal candidate will possess 7–10 years of experience in SOC or Incident Response and hold ...

Threat Intelligence Lead

Hiring Organisation
Iberdrola
Location
Glasgow, Lanarkshire, United Kingdom
Salary
£ 60 K
role you will be responsible for monitoring the threat landscape, analysing emerging risks, and delivering timely intelligence that supports Security Operations Centre (SOC) activities, incident response, threat hunting, detection engineering, risk management and the wider business. You will assess adversary tactics, techniques and procedures (TTPs), develop intelligence … aligned to real-world adversary tradecraft. You will help transform intelligence into actionable decisions, strengthen monitoring capabilities and drive improvement across the detection and response lifecycle. There will also be the chance to research new and specialist techniques, working cross industry, and helping to shape our OT LAB.You will ...

Threat Intelligence Lead

Location
Glasgow, Scotland, United Kingdom
role you will be responsible for monitoring the threat landscape, analysing emerging risks, and delivering timely intelligence that supports Security Operations Centre (SOC) activities, incident response, threat hunting, detection engineering, risk management and the wider business. You will assess adversary tactics, techniques and procedures (TTPs), develop intelligence … aligned to real-world adversary tradecraft. You will help transform intelligence into actionable decisions, strengthen monitoring capabilities and drive improvement across the detection and response lifecycle. There will also be the chance to research new and specialist techniques, working cross industry, and helping to shape our OT LAB. ...