1 to 25 of 529 Incident Response Jobs in the UK

Director, Digital Forensics & Incident Response (Global)

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group’s global Digital Forensics … Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. ...

Security Incident Response Engineer (ServiceNow)

Hiring Organisation
INTEC SELECT LIMITED
Location
Warrington, Cheshire, England, United Kingdom
Employment Type
Contractor
Contract Rate
£100.00 per hour
Security Incident Response Engineer (ServiceNow) Contract: 6 Months (Likely Extension)Location: HybridIR35: Outside/LTD – £700PDSC Cleared/BPSSA highly reputable corporation is hiring an experienced ServiceNow Security Incident Response (SIR) Consultant to support the design, implementation and optimisation of a Security Incident Response capability for a Cyber Security Operations Centre (CSOC).This is an excellent opportunity to play a key role in enhancing cyber incident management processes, automating security workflows and integrating ServiceNow Security Operations with wider security tooling. Key Responsibilities ServiceNow SIR Workflow Design & Development Design and configure ...

Head of Threat Defence, Paddington

Hiring Organisation
Morson Edge
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
ownership of a threat defence strategy and service. The role will focus on leading a team responsible for security operations, incident detection and response and threat intelligence which will be delivered through partnership with outsourced providers and IT. We're looking for a motivated and experienced individual … This role will have line management responsibilities for 3 of the team: a Threat Intelligence Lead, a TD Service Operations Lead and a Cyber Incident Response Lead. The role requires DV clearance and a minimum of 2 days per week in the Paddington Office. Occasional travel to other ...

Senior Security Engineer, Security Incident Response Team (SIRT)

Hiring Organisation
Jobleads-UK
Location
United Kingdom
listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Security Incident Response Team (SIRT) based in United Kingdom. This is an exciting opportunity to join a globally distributed cybersecurity team responsible for protecting large … scale cloud environments and critical platforms against evolving threats. In this role, you will lead high-impact incident response activities, investigate sophisticated security events, and help shape modern detection and response capabilities through automation and AI-driven approaches. You will work closely with cross-functional teams across ...

Security Incident Response Engineer

Hiring Organisation
NonStop Consulting
Location
Warrington, Cheshire, United Kingdom
Employment Type
Contract
Contract Rate
£100/hour
Details at a Glance Role: Security Incident Response Engineer Location: Warrington - hybrid, typically 2 days per week on site Contract length: 6 months (with strong potential for extension based on performance and project needs) IR35 status: Out of Scope Rate: 100/hour Clearance: Existing SC preferred … Would Be Doing This role sits at the intersection of cyber operations and ServiceNow engineering. You would be responsible for designing and embedding robust incident response capabilities in the ServiceNow Security Incident Response (SIR) module, closely aligned to NCSC and best-practice frameworks. ServiceNow SIR workflow ...

Head of Cyber Defence

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
operational execution of all defensive security capabilities. Reporting directly to the Chief Information Security Officer (CISO), the role provides leadership across threat detection, incident response, vulnerability management, application security, cloud and platform security, and identity security. The organisation operates a Managed Security Service Provider (MSSP/MSP) model … ensure high quality, risk aligned security operations. The role leads five specialist domains through the following direct reports: Lead – SecOps Incident Management & Response, Lead – Application Security & Vulnerabilities, Lead – Cloud & Platform Security, Lead – IAM/PAM, and Lead – Incident Response and Cyber Resilience. Key Results Areas 1. ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
United Kingdom
Security Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents as Incident Commander, and lead digital forensic investigations in support of Employee Relations, Legal, Compliance, or Information Security cases. Although you will be focused on security incident response, you will also have the opportunity to create and maintain runbooks, automated workflows, and assist in process refinement and implementation. You will collaborate with a diverse team of engineers and key stakeholders on security initiatives across the company. Above all, your focus is bringing Security expertise ...

Head of Cyber, Band 8b

Hiring Organisation
Gloucestershire Hospitals NHS Foundation Trust
Location
Gloucester, GL1 2EL, United Kingdom
Salary
£66582.00 to £77368.00
participation in the regional "Defend as One" model. The role combines governance, assurance and hands-on leadership of proactive and preventative tactics, threat intelligence, incident response, vulnerability management, strategy and cultural change to build cyber resilience across the Integrated Care System (ICS). Main duties … within large, complex or multi-organisation environments. They will possess deep technical and governance expertise across areas such as threat detection, vulnerability management and incident response, with the ability to translate complex technical risk into clear, articulate, actionable information for senior executives and boards with assurance and confidence. ...

Senior Cyber Security Analyst

Hiring Organisation
Hays Technology
Location
Bolton, Greater Manchester, United Kingdom
Employment Type
Permanent
Salary
£45000 - £55000/annum plus bonus and benefits
Senior Cyber Security Analyst to help strengthen its security posture and safeguard critical systems. This is an excellent opportunity for someone passionate about incident response and proactive threat management within a dynamic, fast-paced environment. The ideal candidate will have a positive go-getter attitude, and will have … experience of incident response, using MS security tools and ideally an understanding of Tanium. Key Responsibilities Working with the Head of Cyber to mature the incident response capability Using your understanding of the contemporary threat environment to assist with your vulnerability investigations and response Lead ...

Head of Cyber Defence

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
leader responsible for developing and executing enterprise-wide cyber defence strategies to protect critical business systems, data, and infrastructure. Leads security operations, threat detection, incident response, and cyber resilience initiatives while ensuring alignment with organisational risk management objectives. Key Responsibilities Lead and manage the Cyber Defence function, overseeing … security operations, threat intelligence, vulnerability management, and incident response capabilities. Develop and implement cyber defence strategies, policies, and procedures to protect against evolving cyber threats. Direct Security Operations Centre (SOC) activities, ensuring effective monitoring, detection, investigation, and response to security incidents. Oversee threat intelligence programmes, identifying emerging ...

Network Security Manager

Hiring Organisation
Pearson Whiffin IT & Digital
Location
Dartford, Kent, South East, United Kingdom
Employment Type
Permanent
Salary
£95,000
Cyber & Network Security Manager We are seeking an experienced Cyber & Network Security Manager to lead the delivery of all security operations, drive cyber incident response, and provide enterprise-wide oversight of network security. This is an operational leadership role at the centre of the cyber defence function. … Security Operations Centre (SOC) services. Act as the senior operational escalation point for cyber security incidents and major security events. Own and coordinate cyber incident response activities, ensuring effective containment, eradication, recovery, and lessons learned. Develop, maintain, and test cyber incident response plans, procedures, and playbooks. ...

Head of Security Operations

Hiring Organisation
Jobleads-UK
Location
Wolverhampton, England, United Kingdom
will be accountable for the effective operation, continuous improvement and resilience of the Bank's security operations capability, covering Security Operations Centre monitoring and response, Identity and Access Management services, security analysis, operational security controls and supplier-delivered security services. The Head of Security Operations is a senior leadership … India offices, supported where appropriate by third-party managed security service providers. The team provides 24x7 or extended-hours security monitoring and response, identity and access management operations, vulnerability and threat analysis, security tooling administration, control assurance support, reporting, and operational support. Your responsibilities will include... Security Operations Leadership ...

IT Security & Compliance Lead

Hiring Organisation
Jobleads-UK
Location
City of Edinburgh, Scotland, United Kingdom
company grows. You'll build our IT security function from the ground up — covering device management, identity and access, infrastructure controls, and incident response — while also owning the compliance and AI governance work that keeps enterprise customers confident in how we operate. It's a hands‐on, build … tools like Okta. Own infrastructure and cloud security controls across our environment (e.g. AWS), working closely with Engineering to keep systems hardened. Security Operations & Incident Response Lead security incident response — full lifecycle investigations, coordinating with internal teams and external partners (e.g. SOCaaS providers), and running post ...

Security Operations Technical Lead

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands‐on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements … detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. Key Responsibilities Act as the primary technical escalation point for security events and incidents identified by the Security Operations team. Support ...

Security Operations Technical Lead

Hiring Organisation
AJ BELL BUSINESS SOLUTIONS LIMITED
Location
Salford, Greater Manchester, North West, United Kingdom
Employment Type
Permanent
that security operations activities are executed efficiently, consistently and in line with defined SLAs and operational standards, through hands-on technical leadership across SOC, Incident Response, Threat Intelligence, Insider Risk and Vulnerability Management. This role acts as a senior technical escalation point, supporting complex investigations and driving improvements … detection, response, automation and operational processes. The role holder is expected to lead through expertise, supporting analysts and ensuring Security Operations operates with discipline, quality and continuous improvement. The key responsibilities of the role are: Act as the primary technical escalation point for security events and incidents identified ...

Senior Security Engineer

Hiring Organisation
Intec Select Ltd
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
GBP 700 Daily
must have active SC clearance. You will play a key role in implementing, configuring, and managing Palo Alto Networks XSIAM to improve threat detection, incident response, security monitoring, and operational resilience. This is an excellent opportunity for a senior security professional to support a major cyber security initiative … Cyber Security Standard. Key Responsibilities: Implement and manage Palo Alto Networks XSIAM security platform Configure security policies, rules, and monitoring capabilities Improve threat detection, response, and security automation Investigate security alerts and support incident response activities Integrate security tools and enhance operational workflows Provide technical guidance ...

Senior Security Engineer

Hiring Organisation
Intec Select Ltd
Location
London, Canary Wharf, United Kingdom
Employment Type
Contract
Contract Rate
£700/day
must have active SC clearance. You will play a key role in implementing, configuring, and managing Palo Alto Networks XSIAM to improve threat detection, incident response, security monitoring, and operational resilience. This is an excellent opportunity for a senior security professional to support a major cyber security initiative … Cyber Security Standard. Key Responsibilities: Implement and manage Palo Alto Networks XSIAM security platform Configure security policies, rules, and monitoring capabilities Improve threat detection, response, and security automation Investigate security alerts and support incident response activities Integrate security tools and enhance operational workflows Provide technical guidance ...

Sr. Backend Engineer, Cloud - Threat Detection / Incident Response (Hybrid, London)

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
join a mission that matters? The future of cybersecurity starts with you.About the Role:Does building systems that help security analysts close a critical incident before it becomes a breach excite you? Does correlating and analyzing data at trillions-of-events-per-day scale sound like the kind … defend themselves from sophisticated cyberattacks? We'd love to meet you.We are seeking a Senior Software Engineer, Cloud to join our Threat Detection and Incident Response (TDIR) team, helping revolutionize security management with our AI-native Falcon Next-Gen SIEM platform – enabling customers to detect, investigate, and hunt ...

Cyber Security Analyst

Hiring Organisation
Holt Executive
Location
London, United Kingdom
Employment Type
Permanent
team. This is an excellent opportunity to join a fast-paced cybersecurity environment, helping to protect critical infrastructure and enterprise systems through proactive monitoring, incident response, and threat analysis. Working as part of a 24/7 operational security function, you will play a key role in identifying … monitoring tools, network infrastructure, and endpoint technologies. Investigate and triage security alerts to identify malicious activity and determine attack methods and techniques. Follow established incident response and escalation procedures to contain and mitigate security risks. Ensure all incidents are accurately documented, including indicators of compromise, evidence, and investigation ...

MDR Team Lead

Hiring Organisation
Jobleads-UK
Location
Oxford, England, United Kingdom
Role Summary Sophos is seeking an experienced MDR Manager to support its Managed Detection and Response customers. The successful candidate will lead MDR analysts and day-to-day operations, ensuring operational quality, timely incident handling, effective customer communication, consistent reporting, and continuous service improvement. As part … Managed Detection and Response team, you will help deliver best-in-class monitoring, detection, and response services that proactively defend customer environments. You will guide investigations, review quality, coach analysts, manage escalations, and use operational insights to improve team performance, investigation consistency, and customer outcomes. What you will ...

Senior Cyber Security Engineer

Hiring Organisation
NTT Global Data Centers EMEA UK ltd
Location
City of London, London, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. Directs complex security incident response efforts across multiple vectorsendpoint protection, EDR, malware analysis, network and computer forensicsensuring rapid containment and root cause analysis. Designs and executes advanced vulnerability ...

Senior Security Platform Engineer

Hiring Organisation
NTT Global Data Centers
Location
EC4N, Cordwainer, Greater London, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: • Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. • Directs complex security incident response efforts across multiple vectors—endpoint protection, EDR, malware analysis, network and computer forensics—ensuring rapid containment and root cause analysis. • Designs and executes ...

SOC Operations Technical Lead

Hiring Organisation
Jobleads-UK
Location
Birmingham, England, United Kingdom
reports to Head of SOC Operations. This hands‐on position serves as the senior technical authority for SOC operations, driving excellence in threat detection, incident response, and security operations across a diverse multi-client portfolio. You will combine deep technical proficiency with strong consulting skills to mentor analysts … manage shift rotations, optimise SOC processes and tools, lead complex incident escalations, and act as a trusted advisor. Although you will manage a team of SOC analysts, this is not a purely managerial role; you will remain deeply involved in technical work while elevating team capabilities and delivering strategic ...

Cyber Security Analyst

Hiring Organisation
Hays Technology
Location
Newport, Gwent, United Kingdom
Employment Type
Permanent
Salary
£43000 - £47000/annum Up to £47k + good benefits
will require knowledge and understanding of attack and exploitation techniques and adversarial TTP's. Help to provide resilience to our threat monitoring and response capabilities. Handle security incident response with internal teams and other third parties to ensure that the incident response life cycle … Good knowledge and understanding of SOC processes and procedures. Basic experience using SIEM systems such as MS Sentinel, LogRhythm, AlienVault, Splunk Good understanding of incident response stages and handling. Basic knowledge and experience using leading endpoint detection and threat management products and managing their operation. Good knowledge ...

Cyber Security Engineer

Hiring Organisation
DCV Technologies Limited
Location
Tring, Hertfordshire, South East, United Kingdom
Employment Type
Contract
Contract Rate
£65,000
network estate (including Cisco Meraki). The role is hands-on and operational, partnering with IT teams to implement security controls, supportmonitoringand incident response through Sophos MDR, and improve cyber resilience by supporting Disaster Recovery (DR) testing and Business Continuity (BC) readiness. Key Responsibilities Cloud Security (Azure) Implement … whererequiredand ensure changes follow change control. Enable and review network security logging/alerting (e.g., syslog/SIEM integrations where applicable). Monitoring, Detection & Incident Response (Sophos MDR) Act as the internal technical point of contact for Sophos MDR and ensure smooth collaboration with MDR analysts. Maintain coverage ...