1 to 25 of 1,388 Incident Response Jobs in the UK

Security Incident Response (ServiceNow SIR) Engineer

Hiring Organisation
Talent Smart Limited
Location
Home Based, United Kingdom
Employment Type
Contract
Contract Rate
GBP 700 Daily
Important: ServiceNow SIR certification is mandatory for this role. Candidates who do not hold a current, relevant ServiceNow SIR/Security Incident Response certification cannot be considered. ServiceNow Security Incident Response (SIR) Engineer - Contract £700 per day | Initial 6 months | Major Cyber Security Programme … looking for a specialist ServiceNow Security Incident Response Engineer to join a major enterprise cyber security programme and help build, automate and strengthen its security incident response capability. This is not a general ServiceNow development role. We need someone who genuinely specialises in ServiceNow Security Operations ...

Senior Manager - Cyber Incident & Response - Consulting

Hiring Organisation
Oliver James
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£100,000 - £110,000 per annum
Senior Manager/Associate Director - Cyber Incident Response Advisory & Incident Management This is a senior opportunity within a leading Cyber Risk & Security practice, working with major organisations to strengthen their ability to prepare for, manage and recover from complex cyber incidents. The role sits across both proactive … cyber incident response advisory and live incident management, helping clients improve resilience while supporting them through high-impact security events. You will work closely with senior stakeholders and C-suite leaders, advising on cyber incident preparedness, crisis and incident management, response strategies and organisational ...

Cyber Response & Recovery Manager - German Speaker

Hiring Organisation
KPMG
Location
London, UK
Employment Type
Full-time
Cyber Response & Recovery Manager (Reactive DFIR)This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the roleThe Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice. Your specific focus … will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands-on incident response role and an opportunity to join a high performing team that works with a wide variety ...

Cyber Response & Recovery Manager (Reactive DFIR) - German Speaking

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice. Your specific … focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands-on incident response role and an opportunity to join a high performing team that works with a wide ...

Cyber Defense Incident Responder - Associate Director

Location
Greater London, England, United Kingdom
responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Senior Manager, Cybersecurity Incident Response

Hiring Organisation
ARM
Location
Cambridge, Cambridgeshire, UK
Employment Type
Full-time
Overview: Interested in defending a global tech company from the latest cyber threats? Arm is seeking a passionate, experienced Senior Manager of Cybersecurity Incident Response to join our growing Cyber Defence Operations (CDO) team, protecting Arm against current and future cyber-attacks! Situated within Arm's Enterprise Security … function, this role will lead Arm's global incident response team across the US, UK and India, including acting as a senior technical and operational leader for major cyber incidents. CDO enables Arm to be successful, delivering scalable and defendable security services that not only provide ...

Senior Incident Response Consultant 2

Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

Cyber Defense Incident Responder

Location
Greater London, England, United Kingdom
responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Cyber Response & Recovery Assistant Manager (Reactive DFIR)

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Assistant Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Assistant Manager role will be working in the Cyber Response Services (CRS) Team within our Advisory practice. Your … specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a junior case manager on smaller cases, or part of a team (reporting to a case manager or senior case manager) on larger cases. This is a hands-on role ...

Head of Cyber Defence & Incident Response London - United Kingdom - Full Time

Location
Greater London, England, United Kingdom
Head of Cyber Defence & Incident Response At Quadient, we support businesses of all sizes in their digital transformation and growth journey, unlocking operational efficiency with reliable, secure, and sustainable automation processes. Our success in delivering innovation and business growth is inspired by the connections our diverse teams create … business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection ...

Senior Incident Response Consultant, Rapid Response

Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

Cyber Defense Incident Responder - Assistant Director

Hiring Organisation
EY (Ernst & Young)
Location
London, UK
Employment Type
Full-time
detects, responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunityThe Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Cyber Response & Recovery Manager (Remediation)

Hiring Organisation
KPMG UK
Location
City of London, London, United Kingdom
Cyber Response & Recovery Manager (Remediation) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG’s Cyber Advisory practice. Your specific focus will … compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience. This ...

SOC and Incident Response Lead

Location
Greater London, England, United Kingdom
experienced SOC and Incident Response Lead at ASOS, you will provide hands-on technical leadership across security monitoring, detection, engineering, incident response, and threat-led investigations. You will lead the SOC and Incident Response team, ensure security incidents are investigated and resolved effectively … role will act as the bridge between wider technology teams, the cyber security team, and third-party partners, ensuring a coordinated and consistent response to cyber security incidents. This role reports to the Head of Security Operations. Lead the SOC and Incident Response team ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection … response and recovery. Reports directly to the CISO and leads cyber defence operations (including the MSSP) and cybersecurity incident response across the organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology. A key focus is optimising security tooling (e.g., SIEM ...

Regional CERT Manager

Location
Manchester, England, United Kingdom
planet. That’s why our purpose is ‘to make sustainable living commonplace’ Role Overview The Regional CERT Manager is responsible for leading cyber incident response operations across the region, ensuring effective detection, containment, investigation, remediation, and recovery from security incidents. This role combines strategic leadership with hands … technical expertise to drive operational excellence, strengthen security capabilities, and enhance organisational cyber resilience. Key Responsibilities Lead regional Cyber Emergency Response Team (CERT) operations, providing both strategic direction and technical guidance for complex cyber security incidents. Own and continuously improve the end‐to‐end Incident Management lifecycle, ensuring ...

Regional CERT Manager

Location
Kingston, England, United Kingdom
planet. That’s why our purpose is ‘to make sustainable living commonplace’ ### **Role Overview**The Regional CERT Manager is responsible for leading cyber incident response operations across the region, ensuring effective detection, containment, investigation, remediation, and recovery from security incidents. This role combines strategic leadership with hands … technical expertise to drive operational excellence, strengthen security capabilities, and enhance organisational cyber resilience.### **Key Responsibilities*** Lead regional Cyber Emergency Response Team (CERT) operations, providing both strategic direction and technical guidance for complex cyber security incidents.* Own and continuously improve the end-to-end Incident Management lifecycle, ensuring ...

Regional CERT Manager

Location
Kingston upon Thames, England, United Kingdom
planet. That's why our purpose is 'to make sustainable living commonplace' Role Overview The Regional CERT Manager is responsible for leading cyber incident response operations across the region, ensuring effective detection, containment, investigation, remediation, and recovery from security incidents. This role combines strategic leadership with hands … technical expertise to drive operational excellence, strengthen security capabilities, and enhance organisational cyber resilience. Key Responsibilities Lead regional Cyber Emergency Response Team (CERT) operations, providing both strategic direction and technical guidance for complex cyber security incidents. Own and continuously improve the end-to-end Incident Management lifecycle, ensuring ...

SOC Analyst - SC Cleared

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£545 - £590 per day + Inside IR35
environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams. You will … cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions. Key Responsibilities Security Monitoring & Incident Response Monitor and triage security alerts generated through SIEM and security tooling. Investigate and respond ...

Cyber Analyst in CYBER DEFENCE CENTRE

Hiring Organisation
Bank of England
Location
London, UK
Employment Type
Full-time
successful candidate will take part in the operations rota ensuring security alerts are thoroughly investigated, escalated appropriately and take part in subsequent Cyber Security incident response activities as part of the wider Cyber Security incident response team where required. When not responding to security alerts … function, the role holder will be expected to proactively seek opportunities to improve the team's operational capability for both detection and response processes through a greater use of automation. The role will require close collaboration across all of the CDC's core functions and has varied and challenging ...

Senior Security & Cyber Operations Manager (Financial Services)

Hiring Organisation
Consol Partners
Location
London, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
Manager Location: Corporate Offices/Hybrid (UK) Industry: Financial Services/Insurance (Regulated Environment) Type: Full-Time, Permanent Senior Security & Cyber Operations Manager | Operations, Incident Response & AI Innovation End-to-end operational ownership of enterprise security operations (SOC), incident response, threat detection, and cyber defence capabilities. … Drive detection engineering, SOAR automation, and AI integration across cloud, hybrid infrastructure, endpoints, and third-party services. Key focus: Incident leadership, MSSP/vendor management, response playbooks, metrics (MTTD/MTTR), and executive risk governance. About the Opportunity A leading UK financial services organisation is seeking a high ...

Threat Response Technology and Capabilities Product Owner

Hiring Organisation
MasterCard
Location
Ringwood, Hampshire, UK
Employment Type
Full-time
networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and SummaryThreat Response Technology and Capabilities Product OwnerOverviewThe Corporate Security Threat and Response Management product ownership team is looking for a Lead Security Engineer to help … ideal candidate is passionate about the modern security tools, capabilities, and strategies. As a Product Owner, you will be defining, owning, and driving the incident response technology and capability strategy across global Security Operations. This role sets the vision for response tooling, automation, AI augmentation, and digital ...

Cyber Incident Response Lead

Location
Greater London, England, United Kingdom
EC2R 7BP Manchester, GB, M1 4HN Bristol, GB, BS32 4TP Leiston, GB, IP16 4EW Felixstowe, GB, IP10 0DD Career Area: Data, Tech & IT Cyber Incident Response Lead Sizewell C’s business is to design, finance, construct, commission, operate, maintain, and eventually decommission the nuclear power plant and related … independent organisation and continue building one of the UK’s largest and most important energy projects. We are now recruiting the below position. Cyber Incident Response Lead Location: Based in London on a hybrid basis with travel to Suffolk as required. Contract : Permanent, full-time. Benefits include: Bonus ...

Lead Threat Response Operations Analyst

Hiring Organisation
Pfizer
Location
Sandwich, Kent, South East, United Kingdom
ROLE SUMMARY Our Global Cyber Defense team is responsible for safeguarding Pfizer's digital assets and infrastructure through proactive threat detection, incident response, and risk mitigation across on-premises, cloud, and hybrid environments. As a Lead Threat Response Operations Analyst within Pfizers Global Cyber Defense organization … will serve as a senior individual contributor, providing technical leadership for the investigation and response to sophisticated cyber threats. While this is not a people-management role, you will lead complex investigations, coordinate the response to security incidents on a global scale, and provide technical guidance to analysts ...

Incident Response Lead (DFIR)

Hiring Organisation
LT Harper Recruitment Group
Location
England, United Kingdom
Incident Response Lead (DFIR) - Hybrid - Can be based anywhere in the UK - Up to £110k The opportunity: Do you want to lead the response to incidents that matter nationally? A Cyber Consultancy is looking for an Incident Response Lead to join its Cyber Response … senior leadership of a fast-growing capability Hybrid working from London or Manchester hubs Pension contribution and private healthcare [confirm] Your responsibilities as an Incident Response Lead will be to: Manage and coordinate a portfolio of cyber security incidents for clients, working closely with the head of cyber ...