76 to 100 of 1,764 Incident Response Jobs in the UK

SOC Analyst - Active SC required

Location
Essex, England, United Kingdom
defence/aerospace client on a short term contract. The successful candidate will have proven experience using IBM QRadar SIEM in a monitoring and incident response capacity. Key Responsibilities: Monitor and analyse security events using IBM QRadar SIEM Investigate and respond to security incidents across various platforms Manage … full incident lifecycle, from identification to resolution Conduct threat detection and analysis, along with threat hunting activities Perform detailed log analysis across multiple security platforms Produce incident reports and post-incident reviews Collaborate with team members to ensure robust security controls Investigate non-standard Cyber requests ...

Cyber Incident Manager (CIM)

Location
Welwyn Garden City, England, United Kingdom
About the role As a Cyber Incident Manager at Tesco, you will lead the coordinated response to cyber incidents, protecting the integrity of the retail ecosystem that serves millions of customers every day. Acting as a central orchestrator, you will ensure swift, structured, and effective incident resolution … minimising operational disruption and customer impact. This role is critical to maintaining trust in Tesco's digital platforms by driving proactive, intelligence-led response and embedding continuous improvement across the cyber defence lifecycle. You will operate at the intersection of technology, business impact, and customer outcomes, championing innovation ...

Acquisition Cybersecurity Operations (ACO) - Senior SOC Analyst

Location
City Of London, England, United Kingdom
Description Seize the opportunity to enhance cybersecurity, utilizing your expertise in threat analysis and incident response to protect vital data and systems. As a Security Operations Senior Associate in the Cybersecurity and Tech Controls line of business, you will play a critical role in safeguarding the organization … help maintain the integrity, confidentiality, and availability of sensitive data and systems. Job responsibilities Monitor and analyze security infrastructure, contributing to detection and response to threats, vulnerabilities, and incidents to ensure the integrity, confidentiality, and availability of sensitive data and systems Conduct in-depth security investigations, including log analysis ...

Acquisition Cybersecurity Operations (ACO) - Senior SOC Analyst

Location
Greater London, England, United Kingdom
Seize the opportunity to enhance cybersecurity, utilizing your expertise in threat analysis and incident response to protect vital data and systems. As a Security Operations Senior Associate in the Cybersecurity and Tech Controls line of business, you will play a critical role in safeguarding the organization's digital … help maintain the integrity, confidentiality, and availability of sensitive data and systems. Job responsibilities Monitor and analyze security infrastructure, contributing to detection and response to threats, vulnerabilities, and incidents to ensure the integrity, confidentiality, and availability of sensitive data and systems Conduct in-depth security investigations, including log analysis ...

Product Engineer, Cloud Security (Multiple Levels) TLNT1 NI

Hiring Organisation
Allstate Northern Ireland
Location
Belfast, UK
implementation through deployment and production support and are accountable for the reliability, adoption, and effectiveness of cloud security controls, including their role in incident detection, response, and recovery. Key Responsibilities: Design, build, and operate cloud-native security controls as software products across cloud infrastructure, data platforms, and application … implementation through deployment and production support and are accountable for the reliability, adoption, and effectiveness of cloud security controls, including their role in incident detection, response, and recovery. Key Responsibilities: Design, build, and operate cloud-native security controls as software products across cloud infrastructure, data platforms, and application ...

Global Cyber Incident Response Director

Location
Greater London, England, United Kingdom
seeking a Senior Cyber Incident Response Coordinator to lead global cybersecurity incident responses and coordinate with legal, privacy, risk, and business stakeholders. You will drive incident response programs and mentor junior team members. The role requires extensive incident response, forensics, and SIEM experience ...

Senior SOC Engineer

Hiring Organisation
Appcast
Location
Glasgow, UK
Type: PermanentSenior SOC EngineerA leading organisation is seeking a Senior SOC Engineer to strengthen its security operations capability and drive continuous improvement across detection, response, and automation. This pivotal role requires deep expertise in IBM QRadar, with a strong focus on playbook development, analytical rule creation, and threat modelling. … Senior SOC Engineer will play a key role in building and optimising detection and response strategies, ensuring robust protection against evolving threats.Key ResponsibilitiesSIEM Engineering & ManagementDeploy, configure, and maintain the QRadar SIEM platform.Onboard and normalise log sources across on-premises and cloud environments.Develop and optimise analytical rules for threat detection ...

Legal Counsel

Hiring Organisation
CyberClan
Location
United Kingdom
carefully selected team of experts are capable of solving complex cyber security challenges – keeping data secure and businesses running as usual. CyberClan’s Global Incident Response Teams are available 24/7/365 to leap into action, responding to all cyber-attacks with proven defensive methodology … business operations. Role Overview: This role supports the CERT/Sales team with reviewing insurance policies, assisting with claims assessments, and contributing to breach response efforts. Ideal for someone with early in house or private practice experience who’s ready to grow into a broader commercial legal role. This ...

Senior Security Consultant (Incident Response)

Hiring Organisation
Appcast
Location
Birmingham, UK
Employee RegularSenior Security Consultant Role Purpose:This is a new, exciting opportunity for a Senior Security Consultant to join LRQA’s existing dynamic Cyber Incident Response Team.This role follows a hybrid working arrangement and will involve working on client sites and from the office from time to time. … improving the team’s capability, in line with managerial direction. The role will lead a team of responders, as well as conduct solo incident investigations, where the actor operates with a high level of sophistication (Organised Crime or above) using agreed mitigation, preparedness, and response and recovery approaches ...

Cyber Incident Lead

Location
Greater London, England, United Kingdom
bring your ambition to work every day, which is why, at British Airways the sky is never the limit. The role: Cyber Incident Lead This role reports into the Cyber Incident Manager, and works with stakeholders across the organisation to ensure BA is able to effectively identify, respond … across the BA estate 24/7 365 days a year as part of an on call function Responsible for developing, maintaining, and managing incident response processes Ability to present on complex, technical concepts to a wide range of stakeholders of varying seniority and knowledge Confident to engage ...

Incident Response Lead (DFIR)

Location
United Kingdom
# Incident Response Lead (DFIR)*LT Harper Recruitment Group***England**Hybrid · Lead/Principal · Full-time · £90,000.00/yr - £110,000.00/yr### The RoleThis hands-on leadership position sits within a cyber consultancy’s incident response practice. Day to day, the postholder manages … exposure to high-profile government and critical national infrastructure incidents, funded certifications, and a structured progression framework within a growing practice.Typical advertised salary forIncident Response roles in United Kingdom:**£53,000–£90,000**(median £70,000 — from30 recent listings analysed by Forensic Focus).Compare Incident Response salaries ...

Tier 2 SOC Analyst

Hiring Organisation
Oscar Technology
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£40,000 - £50,000 per annum
security threats across complex client environments. You'll play a key role in identifying potential security incidents, conducting detailed investigations and supporting the response to emerging threats. The role offers exposure to a wide range of technologies, security tools and client environments, with the opportunity to develop your technical … take ownership of more complex security alerts and incidents, including: Investigating and analysing escalated security alerts from Tier 1 analysts Conducting detailed incident investigations to determine scope, impact and root cause Monitoring and analysing activity across SIEM, EDR and other security platforms Identifying indicators of compromise, suspicious activity ...

Senior Information Security Analyst, UK

Location
Greater London, England, United Kingdom
Senior Information Security Analyst supports the day-to-day operations of the global Information Security program, with a focus on security alert triage, incident investigation, and operational effectiveness across the environment.This role is responsible for monitoring and responding to security alerts, performing assigned operational tasks, and optimizing security tooling … documentation, and escalation.* Perform daily operational information security tasks, including the management and resolution of ServiceNow incidents assigned to the Information Security team.* Support incident response efforts through investigation, coordination, and detailed documentation of findings.* Participate occasionally in an on-call rotation as required to support timely response ...

Global Cyber Incident Response Lead

Location
Greater London, England, United Kingdom
Technology is seeking a Senior Cyber Incident Response Coordinator to lead global cybersecurity incident response activities. You will coordinate across international teams, manage on‐call rotations, and work with General Counsel, Data Privacy, and Risk Management to protect EY’s information assets. The role requires deep … incident response knowledge, forensics capability, and experience with SIEM tools (Splunk/Sentinel). #J-18808-Ljbffr ...

Senior Cyber Analyst

Location
Greater London, England, United Kingdom
your unique needs. We help organisations improve processes such as threat management by building an identity management programme, and establishing prevention, detection and response capabilities to cyber-attacks. Role Summary The Senior Cyber Analyst is the senior technical lead within the Cyber Services function, responsible for complex cyber investigations … incident response, threat detection, and security platform optimisation. Acting as the highest technical escalation point within cyber operations, the role provides leadership, mentoring, and strategic direction to ensure customers maintain a strong and resilient security posture. Incident Response & Threat Management Lead the investigation and resolution ...

Site Reliability Engineer

Location
Cambridge, England, United Kingdom
continuous improvement of the Bango Platform end-to-end — from the infrastructure and pipelines that build and deploy it, to the observability and incident response that keep it running to agreed service levels. You combine three things that have historically sat in separate teams: platform and cloud infrastructure … engineering, automation and delivery pipeline ownership, and proactive/reactive reliability engineering including incident response and customer impact management. You design, build and operate the automation, observability and platform capabilities that other engineering teams rely on, and you are equally comfortable diagnosing a live incident ...

Cyber Risk Advisory Consultant, London Cyber security London

Location
Greater London, England, United Kingdom
Cyber Security practice is the newest and fastest-growing part of S-RM. The cyber sector is always evolving, and our Advisory, Testing, Incident Response and Forensics practices are in more demand than ever. We’re building a team to meet this challenge. This means we’re quick … Security Consulting At the core of the Associate role is hands‐on cyber security consulting. You will lead delivery across multiple domain areas, including: Incident Response Preparedness Cy ber incident response strategy, policy, and plan development. Simulation exercising at leadership and operational levels. Digital Resilience Business ...

Lead SOC & Incident Response Architect

Location
City Of London, England, United Kingdom
ASOS is seeking an experienced SOC and Incident Response Lead to provide hands-on technical leadership across security monitoring, detection, engineering, incident response, and threat-led investigations. You will lead the SOC and Incident Response team, coordinate with an external MSSP, and ensure efficient ...

Senior Security Analyst (L3 SOC Analyst)

Location
City Of London, England, United Kingdom
sustainable future. This role is part of Inchcape's Global Cyber Security team, supporting our worldwide operations through advanced security monitoring, threat detection and incident response capabilities. You'll play a critical role in protecting our people, systems and data, working alongside highly skilled security professionals … technical escalation point for complex cyber security incidents and advanced threat investigations. You'll drive continuous improvement across detection engineering, threat hunting, automation and incident response capabilities, helping strengthen Inchcape's cyber resilience and security maturity. This is a unique opportunity to combine deep technical expertise with strategic ...

Staff Security Engineer London, UK

Location
Greater London, England, United Kingdom
Operations team, you will help Ripple detect, investigate, and respond to security threats across our environment. You’ll work across detection and data engineering, incident response, and security automation — building the tooling and detection logic that lets the team scale. You’ll operate independently on sophisticated investigations … Design, build, and tune detections across our security stack (Google Security Operations) to improve our ability to identify and mitigate threats. Lead incident response for the most complex and high-severity investigations, from initial triage through root cause and remediation. Build and maintain security automation workflows (e.g. ...

Associate Consultant, Digital Forensics, Incident Response

Location
Greater London, England, United Kingdom
Responsibilities Provide technical expertise and consultative solutions in Digital Forensics, Incident Response, Cyber Security and eDiscovery Serve law firms, Fortune 500 multinationals and government/law-enforcement clients Preserve digital data and conduct forensic analysis of digital evidence Prepare reporting for regional and international Discovery & Data Insights teams … Collaborate with Cyber Response, Crisis Management and Investigations teams Support experienced professionals in investigating data breaches and security incidents Collect and preserve digital data using industry-standard tools and techniques Assist with forensic analysis and cyber security services Support Investigation teams across all regions Deliver high-quality client deliverables ...

Senior Security Analyst (L3 SOC Analyst)

Location
Greater London, England, United Kingdom
carbon, sustainable future.This role is part of Inchcape's Global Cyber Security team, supporting our worldwide operations through advanced security monitoring, threat detection and incident response capabilities. You'll play a critical role in protecting our people, systems and data, working alongside highly skilled security professionals … technical escalation point for complex cyber security incidents and advanced threat investigations. You'll drive continuous improvement across detection engineering, threat hunting, automation and incident response capabilities, helping strengthen Inchcape's cyber resilience and security maturity.This is a unique opportunity to combine deep technical expertise with strategic influence ...

Client-Facing Incident Response Project Manager

Location
United Kingdom
Abacus is seeking a Project Manager of Incident Response to drive external, client-facing projects within the Incident Response team. You will lead robust deliverables, establish trust with clients, and own containment and recovery directions, coordinating with the primary engineer and on-call rotation for rapid … response. You will manage project scope, budget, and timelines while ensuring QA, reporting to the Director of Incident Response PMO and collaborating with Abacus engineers on strategic #J-18808-Ljbffr ...

Staff Cloud Security Engineer, GCP

Location
Greater London, England, United Kingdom
environments Perform security assessments, audits, threat modelling and architecture design reviews Identify and triage risks and vulnerabilities, recommend improvements and design corrective controls Lead incident response, including investigation and remediation of security breaches Support internal security awareness and training programs Advocate the DevSecOps mindset across technology teams Work … identify security gaps and create risk-minimising solutions Proactive approach to staying updated with security threats, vulnerabilities and mitigation techniques Thorough understanding of incident response processes Desirable: network security, TCP/IP, BGP, VPNs, firewalls, WAFs, IDS/IPS and hybrid GCP/on-premise connectivity Desirable: data ...

Senior Cyber Threat Intelligence Analyst

Location
Portsmouth, England, United Kingdom
could impact Babcock's people, information, systems, programmes and customers. You will transform complex threat data into actionable intelligence that supports proactive cyber defence, incident response, vulnerability management and risk reduction activities across the organisation. Day-to-day, you'll work closely with Security Operations, Incident Response … threat intelligence to support proactive cyber defence activities. Analysing threat actor activity, malware campaigns, phishing threats and emerging cyber risks. Collaborating with Security Operations, Incident Response and Security Assurance teams to improve cyber resilience. Creating high-quality intelligence assessments and reports that support business decision-making. Monitoring ...