1 to 25 of 581 Incident Response Jobs in the UK

Cyber Response & Recovery Manager - German Speaker

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Cyber Response & Recovery Manager - German Speaker Cyber Response & Recovery Manager (Reactive DFIR) About the role This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team … within our Cyber Advisory practice. Your specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands‐on incident response role and an opportunity to join a high ...

Director, Digital Forensics & Incident Response (Global)

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group’s global Digital Forensics … Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. ...

Security Incident Response Engineer (ServiceNow)

Hiring Organisation
INTEC SELECT LIMITED
Location
Warrington, Cheshire, England, United Kingdom
Employment Type
Contractor
Contract Rate
£100.00 per hour
Security Incident Response Engineer (ServiceNow) Contract: 6 Months (Likely Extension)Location: HybridIR35: Outside/LTD – £700PDSC Cleared/BPSSA highly reputable corporation is hiring an experienced ServiceNow Security Incident Response (SIR) Consultant to support the design, implementation and optimisation of a Security Incident Response capability for a Cyber Security Operations Centre (CSOC).This is an excellent opportunity to play a key role in enhancing cyber incident management processes, automating security workflows and integrating ServiceNow Security Operations with wider security tooling. Key Responsibilities ServiceNow SIR Workflow Design & Development Design and configure ...

Head of Threat Defence, Paddington

Hiring Organisation
Morson Edge
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
ownership of a threat defence strategy and service. The role will focus on leading a team responsible for security operations, incident detection and response and threat intelligence which will be delivered through partnership with outsourced providers and IT. We're looking for a motivated and experienced individual … This role will have line management responsibilities for 3 of the team: a Threat Intelligence Lead, a TD Service Operations Lead and a Cyber Incident Response Lead. The role requires DV clearance and a minimum of 2 days per week in the Paddington Office. Occasional travel to other ...

Incident Response (CSIRT) / SOC Level 3 Analyst

Hiring Organisation
Morson Edge
Location
Hampshire, South East, United Kingdom
Employment Type
Contract
Incident Response (CSIRT)/SOC Level 3 Analyst - Outside IR35 Location: Crawley (2-3 days onsite) Contract: 6 Months Outside IR35 We are looking for an experienced Incident Response (CSIRT)/SOC Level 3 Analyst to join a high-performing cyber security operations team … initial 6-month contract. This is an excellent opportunity for a senior cyber security professional with strong incident response, threat hunting, and SOC expertise to play a critical role in protecting enterprise IT and operational environments from advanced cyber threats. You will work closely with cyber security operations ...

Cyber Incident Response Manager

Hiring Organisation
Hays Specialist Recruitment Limited
Location
Liverpool, Merseyside, England, United Kingdom
Employment Type
Contractor
Contract Rate
£750 - £800 per day
Rate: £750 per dayIR35 Status: Outside IR35Contract Length: 6 months initiallyLocation: Hybrid - Liverpool Overview I'm supporting an organisation seeking an experienced Cyber Incident Response Manager to lead and mature its Incident Response capability across a complex enterprise environment. Responsibilities Own and manage cyber incidents from … detection through to resolution. Review, enhance, and develop Incident Response frameworks, runbooks, and playbooks. Ensure alerts from SIEM, EDR, CTI, and SOC services are effectively integrated into Incident Response processes. Lead tabletop exercises and testing activities. Work closely with SOC, Threat Intelligence, Technology, and Business teams. ...

Security Incident Response Engineer

Hiring Organisation
NonStop Consulting
Location
Warrington, Cheshire, United Kingdom
Employment Type
Contract
Contract Rate
£100/hour
Details at a Glance Role: Security Incident Response Engineer Location: Warrington - hybrid, typically 2 days per week on site Contract length: 6 months (with strong potential for extension based on performance and project needs) IR35 status: Out of Scope Rate: 100/hour Clearance: Existing SC preferred … Would Be Doing This role sits at the intersection of cyber operations and ServiceNow engineering. You would be responsible for designing and embedding robust incident response capabilities in the ServiceNow Security Incident Response (SIR) module, closely aligned to NCSC and best-practice frameworks. ServiceNow SIR workflow ...

Incident Response Manager

Hiring Organisation
17918
Location
Exeter, Devon, United Kingdom
create opportunities for you to shape your own career. Ready to make a splash? Join our team today. We're looking for an experienced Incident Response Manager to lead our incident management, business continuity and emergency preparedness capability. In this high-profile role, you'll be responsible … organisation is ready to respond effectively to operational incidents, emergencies and major events. You'll provide strategic leadership, oversee a 24/7 incident response function, and help protect the delivery of essential services for our customers and communities. If you thrive in fast-paced environments, enjoy solving ...

Embedded Cyber Detection and Response Deputy Team Lead

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Cyber Detection and Response Deputy Team Lead serves as the operational second-in-command of the Cyber Detection and Response Team (DART), bridging the gap between hands-on cyber operations and team leadership. The role supports the Team Lead in the ongoing development, maturation, and delivery … client's detection and response capabilities, while providing technical leadership and operational oversight across day-to-day security operations. This position remains actively involved in threat detection, incident response, threat hunting, and detection engineering activities while also assuming supervisory and coordination responsibilities. The Deputy Team Lead acts ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
United Kingdom
Security Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents as Incident Commander, and lead digital forensic investigations in support of Employee Relations, Legal, Compliance, or Information Security cases. Although you will be focused on security incident response, you will also have the opportunity to create and maintain runbooks, automated workflows, and assist in process refinement and implementation. You will collaborate with a diverse team of engineers and key stakeholders on security initiatives across the company. Above all, your focus is bringing Security expertise ...

Head of Cyber, Band 8b

Hiring Organisation
Gloucestershire Hospitals NHS Foundation Trust
Location
Gloucester, GL1 2EL, United Kingdom
Salary
£66582.00 to £77368.00
participation in the regional "Defend as One" model. The role combines governance, assurance and hands-on leadership of proactive and preventative tactics, threat intelligence, incident response, vulnerability management, strategy and cultural change to build cyber resilience across the Integrated Care System (ICS). Main duties … within large, complex or multi-organisation environments. They will possess deep technical and governance expertise across areas such as threat detection, vulnerability management and incident response, with the ability to translate complex technical risk into clear, articulate, actionable information for senior executives and boards with assurance and confidence. ...

Network Security Manager

Hiring Organisation
Pearson Whiffin IT & Digital
Location
Dartford, Kent, South East, United Kingdom
Employment Type
Permanent
Salary
£95,000
Cyber & Network Security Manager We are seeking an experienced Cyber & Network Security Manager to lead the delivery of all security operations, drive cyber incident response, and provide enterprise-wide oversight of network security. This is an operational leadership role at the centre of the cyber defence function. … Security Operations Centre (SOC) services. Act as the senior operational escalation point for cyber security incidents and major security events. Own and coordinate cyber incident response activities, ensuring effective containment, eradication, recovery, and lessons learned. Develop, maintain, and test cyber incident response plans, procedures, and playbooks. ...

Senior IT Security Analyst

Hiring Organisation
Prime Personnel UK
Location
SW1E, Victoria, Greater London, United Kingdom
Employment Type
Permanent
Salary
£70000 - £82500/annum
practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions … cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365/Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve ...

Senior IT Security Analyst

Hiring Organisation
Prime Personnel
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£70,000 - £82,500 per annum
practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions … cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365/Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve ...

Cyber Incident Response Team Lead (CSIRT)

Hiring Organisation
Robert Walters
Location
Merseyside, England, United Kingdom
Employment Type
Contractor
Contract Rate
£500 - £600 per day
Blends hands-on incident command and digital forensics with programmatic capability building. Establishes the CSIRT operating model, creates scenario playbooks (ransomware, exfiltration) from scratch, and leads technical containment/recovery during active security events. About the Role My client is a well established business, looking for a hands … CSIRT Lead to establish and run the cyber incident response capability across a complex, multi-site industrial and corporate estate. The role blends hands-on incident command and digital forensics coordination with the programmatic build-out of incident playbooks and operational runbooks from scratch. Key Responsibilities ...

Head of Security Operations

Hiring Organisation
Jobleads-UK
Location
Wolverhampton, England, United Kingdom
will be accountable for the effective operation, continuous improvement and resilience of the Bank's security operations capability, covering Security Operations Centre monitoring and response, Identity and Access Management services, security analysis, operational security controls and supplier-delivered security services. The Head of Security Operations is a senior leadership … India offices, supported where appropriate by third-party managed security service providers. The team provides 24x7 or extended-hours security monitoring and response, identity and access management operations, vulnerability and threat analysis, security tooling administration, control assurance support, reporting, and operational support. Your responsibilities will include... Security Operations Leadership ...

IT Security & Compliance Lead

Hiring Organisation
Jobleads-UK
Location
City of Edinburgh, Scotland, United Kingdom
company grows. You'll build our IT security function from the ground up — covering device management, identity and access, infrastructure controls, and incident response — while also owning the compliance and AI governance work that keeps enterprise customers confident in how we operate. It's a hands‐on, build … tools like Okta. Own infrastructure and cloud security controls across our environment (e.g. AWS), working closely with Engineering to keep systems hardened. Security Operations & Incident Response Lead security incident response — full lifecycle investigations, coordinating with internal teams and external partners (e.g. SOCaaS providers), and running post ...

SPLUNK SOAR Engineer - FTC 12m £110k UK REMOTE

Hiring Organisation
Circle Recruitment
Location
Birmingham, West Midlands, England, United Kingdom
Employment Type
Temporary
Salary
£80,000 - £110,000 per annum
optimising security automation across a large-scale enterprise environment. This is a hands-on engineering position focused on delivering scalable Security Orchestration, Automation and Response (SOAR) capabilities using the Splunk Security platform . Working alongside Incident Response and Threat Management teams, you will develop advanced automation, improve … detection and response processes, and build new use cases that strengthen cyber resilience. This is a 12-month fixed term contract with a strong likelihood of renewal , offering a salary of up to £110,000 , an excellent benefits package and fully expensed travel and accommodation for occasional business travel ...

Cyber Security Engineer/Specialist

Hiring Organisation
Exalto Consulting
Location
Surrey, United Kingdom
Employment Type
Permanent
Salary
£70000 - £80000/annum Up to 80k (+ benefits)
risk reduction rather than purely operational support. You'll be responsible for strengthening the organisation's security posture through threat assessment, vulnerability management, incident response and continuous security improvement initiatives. Key responsibilities include: Enterprise Threat Management Identify, assess and mitigate cyber threats across enterprise infrastructure and business systems … vulnerability analysis Develop and implement security controls and remediation strategies Monitor emerging threats and recommend appropriate defensive measures Enhance threat detection, monitoring and incident response capabilities Develop and maintain incident response playbooks and operational procedures Work closely with third-party security providers during incidents and security ...

Security Operations Technical Lead

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands‐on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements … detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. Key Responsibilities Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support ...

Senior Security Engineer

Hiring Organisation
Intec Select Ltd
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
GBP 700 Daily
must have active SC clearance. You will play a key role in implementing, configuring, and managing Palo Alto Networks XSIAM to improve threat detection, incident response, security monitoring, and operational resilience. This is an excellent opportunity for a senior security professional to support a major cyber security initiative … Cyber Security Standard. Key Responsibilities: Implement and manage Palo Alto Networks XSIAM security platform Configure security policies, rules, and monitoring capabilities Improve threat detection, response, and security automation Investigate security alerts and support incident response activities Integrate security tools and enhance operational workflows Provide technical guidance ...

Senior Security Engineer

Hiring Organisation
Intec Select Ltd
Location
London, Canary Wharf, United Kingdom
Employment Type
Contract
Contract Rate
£700/day
must have active SC clearance. You will play a key role in implementing, configuring, and managing Palo Alto Networks XSIAM to improve threat detection, incident response, security monitoring, and operational resilience. This is an excellent opportunity for a senior security professional to support a major cyber security initiative … Cyber Security Standard. Key Responsibilities: Implement and manage Palo Alto Networks XSIAM security platform Configure security policies, rules, and monitoring capabilities Improve threat detection, response, and security automation Investigate security alerts and support incident response activities Integrate security tools and enhance operational workflows Provide technical guidance ...

Cyber Security Analyst

Hiring Organisation
Holt Executive
Location
London, United Kingdom
Employment Type
Permanent
team. This is an excellent opportunity to join a fast-paced cybersecurity environment, helping to protect critical infrastructure and enterprise systems through proactive monitoring, incident response, and threat analysis. Working as part of a 24/7 operational security function, you will play a key role in identifying … monitoring tools, network infrastructure, and endpoint technologies. Investigate and triage security alerts to identify malicious activity and determine attack methods and techniques. Follow established incident response and escalation procedures to contain and mitigate security risks. Ensure all incidents are accurately documented, including indicators of compromise, evidence, and investigation ...

MDR Team Lead

Hiring Organisation
Jobleads-UK
Location
Oxford, England, United Kingdom
Role Summary Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement. As part … Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes. What you will ...

Senior Cyber Security Engineer

Hiring Organisation
NTT Global Data Centers EMEA UK ltd
Location
City of London, London, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. Directs complex security incident response efforts across multiple vectorsendpoint protection, EDR, malware analysis, network and computer forensicsensuring rapid containment and root cause analysis. Designs and executes advanced vulnerability ...