1 to 25 of 432 Incident Response Jobs in the UK

Cyber Response & Recovery Manager (Reactive DFIR) - German Speaking

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice. Your specific … focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands-on incident response role and an opportunity to join a high performing team that works with a wide ...

Associate Manager - Cyber Security Incident Response

Hiring Organisation
WTW
Location
Greater London, United Kingdom
Employment Type
Full Time
myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. Description The Associate Manager - Cyber Security Incident Response will play a pivotal role within WTW’s Global Information and Cyber Security Defence (ICSD) function, leading the response to complex security … incidents and driving initiatives to enhance WTW’s Cyber incident management capabilities. This mid senior-level role requires a highly experienced professional with strong expertise in incident response and cybersecurity. The individual will work as part of a global, multi-disciplined security community with strong support across ...

Cyber Response & Recovery Assistant Manager (Reactive DFIR)

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Assistant Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Assistant Manager role will be working in the Cyber Response Services (CRS) Team within our Advisory practice. Your … specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a junior case manager on smaller cases, or part of a team (reporting to a case manager or senior case manager) on larger cases. This is a hands-on role ...

Cyber Response & Recovery Manager (Remediation)

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Manager (Remediation) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG’s Cyber Advisory practice. Your specific focus will … compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience. This ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
Incident Response Consultant - Mid to Principal - UK Wide UK Remote | Up to £95,000 + benefits | SC Eligible Pref A specialist opportunity for experienced Incident Response professionals looking to work across a varied mix of proactive and reactive Digital Forensics & Incident Response (DFIR) engagements. … This is a hands-on consulting role where you will support organisations through cyber incidents while also helping them improve their readiness, resilience and response capability before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
Incident Response Consultant - Mid to Principal - UK Wide UK Remote | Up to £95,000 + benefits | SC Eligible Pref A specialist opportunity for experienced Incident Response professionals looking to work across a varied mix of proactive and reactive Digital Forensics & Incident Response (DFIR) engagements. … This is a hands-on consulting role where you will support organisations through cyber incidents while also helping them improve their readiness, resilience and response capability before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment ...

Associate/Senior Associate - Data & Cyber

Hiring Organisation
RPC
Location
Greater London, United Kingdom
Employment Type
Full Time
ROLE OVERVIEW The team The Data & Cyber team advises a wide range of clients across a variety of industry sectors on cyber incidents, regulatory response, technology and data-related claims, and cyber/technology insurance coverage. We are recognised for combining deep cyber incident response capability with … understanding of the insurance market, enabling us to support clients across the lifecycle of a cyber event and its downstream exposures: from immediate breach response and crisis management, through policy notification and coverage strategy, to regulatory engagement and dispute resolution. The role Based in London, the Associate ...

SOC Analyst - SC Cleared

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£545 - £590 per day + Inside IR35
environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams. You will … cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions. Key Responsibilities Security Monitoring & Incident Response Monitor and triage security alerts generated through SIEM and security tooling. Investigate and respond ...

Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA

Hiring Organisation
Appcast
Location
Remote, UK
affiliated with, and do not endorse products or services of GitLab.An overview of this roleAs a Senior Security Engineer on GitLab’s Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats. You will lead … high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows.Operating within a 24/7 global environment (follow the sun model), you will own incidents end-to-end - from detection and triage through containment, eradication ...

Incident Response Specialist

Hiring Organisation
Pontoon
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Contract
Contract Rate
£700/day
take your cyber security expertise to the next level? Our client, a leader in the energy sector, is on the lookout for an Incident Response Specialist to join their dynamic cyber security team. Role: Incident Response Specialist Duration: 6 Months (ext. options) Location: Warwick (Hybrid … mindset, promoting shared responsibility among Security Operations teams. Your contributions will be vital in defending against an ever-evolving threat landscape. Key Responsibilities Include: Incident Response: Triage and manage high-priority incidents while ensuring appropriate responses are executed. Produce clear incident summaries quickly and adapt your communication ...

Principal Consultant, Incident Response (Weekend Schedule)

Hiring Organisation
Appcast
Location
Remote, UK
will lead and produce deliverables for reactive services engagements. You will work directly with a variety of customers and key stakeholders to manage incident response engagements from start to finish, providing expert guidance on immediate containment and long-term remediation to enhance their security posture.This is a weekend … will have every Tuesday, Wednesday and Thursday as your normal days off. Eligibility for UK SC is an essential requirementKey ResponsibilitiesManage and lead incident response engagements, including scoping work, guiding clients through forensic investigations, and containing security incidents.Perform reactive incident response and host-based analysis ...

Data and Cyber Associate/Senior Associate

Hiring Organisation
Auston Legal Limited
Location
London Area, United Kingdom
regarding cyber incidents, regulatory responses, technology and data-related claims, and cyber/technology insurance coverage. They are known for their expertise in cyber incident response and their comprehensive understanding of the insurance market, which allows them to assist clients throughout the entire process of a cyber event … associated risks, including immediate breach response and crisis management, policy notification and coverage strategy, as well as regulatory engagement and dispute resolution. The Role: The London team is seeking to recruit an Associate (1-4PQE) and Senior Associate (4-8PQE) who will support Partners in delivering cyber ...

SOC Shift Lead

Hiring Organisation
Anson McCade
Location
City of London, London, United Kingdom
security operation in Central London. This is not a traditional SOC Analyst position. You’ll be the senior technical escalation point on shift , leading incident response activity, supporting analysts and taking ownership of complex and high-severity security incidents. What you’ll be doing Lead the response … sources Perform root cause analysis and coordinate containment, eradication and recovery Correlate events across SIEM, EDR and other security tooling to build a clear incident narrative Identify detection gaps and support improvements to rules, thresholds and playbooks Mentor and provide technical guidance to L1 SOC Analysts Produce detailed investigation ...

Cyber Security Consultant

Hiring Organisation
Radius Consultancy
Location
London, United Kingdom
Employment Type
Permanent
Salary
£80000 - £90000/annum
SIEM, NDR, applications, security architecture, IAM, PAM encryption technologies, network security, Zero Trust, secure interconnection patterns and cyber security principles. Experience within Security Operations, Incident Response, Security Assurance, or GRC functions. Experience managing or overseeing MSSP, SOC activities, third party management. Strong understanding of: ISO 27001, SOC2, NIST … Cyber Security Framework, Incident Response methodologies, Cyber Security Governance, GDPR and regulatory compliance Certifications (one or more) CISSP CISM CRISC The Cyber Security Assurance & Incident Response Lead is responsible for strengthening and maintaining Telehouse's cyber security posture through effective security assurance, incident response ...

Graduate SOC Analyst

Hiring Organisation
CyPro
Location
City of London, London, United Kingdom
pigeonholed into one narrow specialism. At CyPro, you’ll have the opportunity to get involved in a wide range of areas including monitoring, incident response, threat intelligence, detection engineering, automation and internal security operations. You’ll play a key role in our Security Operations Centre, delivering … monitoring, detection and response to our growing customer base. You’ll contribute to building out our capabilities, improving tooling and processes, and shaping how we operate as the function matures. As the team grows further, you’ll have the flexibility to focus more deeply on the areas that interest ...

Senior IT Security Analyst

Hiring Organisation
Prime Personnel
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£75,000 - £90,000 per annum
practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions … cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365/Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve ...

Senior IT Security Analyst / Engineer

Hiring Organisation
Prime Personnel UK
Location
SW1E, Victoria, Greater London, United Kingdom
Employment Type
Permanent
Salary
£75000 - £90000/annum c£85,000
practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions … cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365/Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve ...

Cyber Incident Response Specialist

Hiring Organisation
Adecco
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Contract
Cyber Incident Response Specialist 6-Month Contract - Inside IR35 - Hybrid (Warwick 1 day per week) Our client, a leading energy company is looking for an experienced Cyber Incident Response Specialist to take ownership of cyber security incidents from escalation through to resolution. Working within a dedicated … Incident Response team, you will coordinate containment, remediation and recovery activities, lead incident calls, engage key stakeholders, and ensure incidents are managed effectively through to closure. Key Requirements Experience managing cyber/security incidents end-to-end Strong understanding of cyber threats including phishing, malware and insider ...

Information Security Engineer

Hiring Organisation
Appcast
Location
London, UK
Aside from infrastructure, the candidate should have experience and working knowledge of SIEM and vulnerability management platforms. The role will cover elements of cyber incident response, so a background in supporting a wider incident response function is a necessity.Key ResponsibilitiesCloud Security Assessment & Advisory:Assess the security … configurations of Azure IaaS and Google Cloud environments, including infrastructure.Provide recommendations based on industry best practices and emerging security threats.The ability to provide Cyber Incident Responders subject matter expertise in Cloud security when required.Defender & Security Monitoring Advisory:Evaluate and optimise the use of Azure Defender and other security monitoring ...

SPLUNK SOAR Engineer - FTC 12m £110k UK REMOTE

Hiring Organisation
Circle Group
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Temporary
optimising security automation across a large-scale enterprise environment. This is a hands-on engineering position focused on delivering scalable Security Orchestration, Automation and Response (SOAR) capabilities using the Splunk Security platform . Working alongside Incident Response and Threat Management teams, you will develop advanced automation, improve … detection and response processes, and build new use cases that strengthen cyber resilience. This is a 12-month fixed term contract with a strong likelihood of renewal , offering a salary of up to £110,000 , an excellent benefits package and fully expensed travel and accommodation for occasional business travel ...

SOC Shift Lead

Hiring Organisation
Anson Mccade
Location
City of London, London, United Kingdom
Employment Type
Permanent
join a high-performing cyber security operations team supporting critical, secure infrastructure in a 24/7 environment. This is an opportunity to lead incident response activities, mentor analysts, and play a key role in protecting complex enterprise environments from evolving cyber threats. What You'll Be Doing … Lead the investigation and response to medium and high-severity security incidents. Act as the escalation point for complex cyber security events and threat activity. Conduct root cause analysis and produce detailed incident reports. Coordinate containment, eradication and recovery activities with technical teams. Correlate data across SIEM ...

SOC Analyst

Hiring Organisation
Reed
Location
Central London, London, England, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £60,000 per annum, Inc benefits
protecting a large-scale, international technology environment. This is an excellent opportunity for a security professional with experience in SOC operations, threat detection, incident response, and threat hunting to join a mature security function that is investing heavily in its cyber capabilities. You'll work within a hybrid … cyber security alerts, incidents and threats Act as the key operational contact for the Managed Security Service Provider (MSSP), ensuring effective monitoring and incident response Prioritise and manage security incidents based on business risk and impact Conduct proactive threat hunting across endpoint, network, identity and cloud environments Develop ...

Cyber Security Engineer/Specialist

Hiring Organisation
Exalto Consulting
Location
Surrey, United Kingdom
Employment Type
Permanent
Salary
£70000 - £80000/annum Up to 80k (+ benefits)
risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems … vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security ...

FINEX Cyber Incident Response Leader

Hiring Organisation
Appcast
Location
London, UK
Join WTW’s Cyber team as a trusted advisor and incident leader, supporting clients through high-impact cyber events such as ransomware, data breaches and non-malicious system outages.This is a high-visibility, client-facing role where you’ll guide organisations through critical moments, working closely with brokers, claims … advisory functions within FINEX and across other Willis business units such as Industry focused teams.The RoleLead and coordinate cyber incident response for clients across complex and time-critical situationsProvide clear, confident guidance on insurance coverage during live incidentsManage and collaborate with insurer panels and external response partners ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
Manchester, United Kingdom
Employment Type
Permanent
Salary
GBP 95,000 Annual
Incident Response Consultant - Mid to Principal - UK Wide UK Remote Up to £95,000 + benefits SC Eligible Pref A specialist opportunity for experienced Incident Response professionals looking to work across a varied mix of proactive and reactive Digital Forensics & Incident Response (DFIR) engagements ...