1 to 25 of 261 Incident Response Jobs in the UK

Cyber Incident Response Consultant

Hiring Organisation
Experis
Location
Basingstoke, Hampshire, United Kingdom
Employment Type
Contract
title: Cyber Incident Response Consultant (Contractor) Contract: Six Months (possibility of extension) Location: Basingstoke (X3 days onsite; X2 working remote) Role Overview We are seeking an experienced Cyber Incident Response Consultant to support our cybersecurity function on a contract basis. The consultant will be responsible … collaborating with organisation stakeholders in developing, updating, and enhancing a comprehensive set of tactical and operational cyber incident response documents, including the Incident Response Plan, Communication Plan, Incident Response Playbooks, and Containment & Eradication procedures. This engagement is focused on delivering high-quality, actionable documentation ...

Director of Group Cyber Security Services

Hiring Organisation
Information Security Solutions
Location
London, United Kingdom
Employment Type
Permanent
Salary
£140000 - £160000/annum
relentless focus on operational excellence, the Head of Security Services builds and empowers high-performing teams to deliver 24/7 threat detection, rapid incident response, and proactive risk management. This includes ownership of security controls, security testing, tech assurance and vulnerability and threat management, and incident response across the organisation. Collaboration is at the heart of this position. By working across the GCS Leadership Team, with business and technology stakeholders, and with industry experts to align strategy, share intelligence, and drive a single, cohesive approach to security services, this leader ensures the Group ...

Cloud Security Engineer

Hiring Organisation
SR2 | Socially Responsible Recruitment | Certified B Corporation™
Location
Hereford, England, United Kingdom
integrating SAST, DAST, and SCA tooling to maintain supply chain integrity Engineer Kubernetes security solutions, including RBAC, network policies, and runtime protection Detection, Monitoring & Incident Response Perform incident response activities including triage, containment, eradication, and recovery Develop and optimise security detections (e.g. Sentinel, KQL, YARA) Manage … logging, ingestion pipelines, and monitoring infrastructure Conduct threat hunting and analysis to identify emerging risks Lead or support incident investigations, including post-incident reviews and remediation Vulnerability & Risk Management Identify, track, and remediate vulnerabilities across cloud, endpoint, and infrastructure environments Implement controls arising from security assessments, audits ...

Investigator - Cyber Incident Response

Hiring Organisation
Accenture
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
Investigator - Cyber Incident Response Location Flexible (UK) Please Note: Due to the nature of client work you will be undertaking, you will need to be willing to go through a Security Clearance process as part of this role, which requires 5+ years UK address history at the point … working with cutting-edge technologies and will have the opportunity to develop a wide range of new skills. At Accenture, our global Incident Response team takes on some of the hardest and most meaningful challenges in cyber security. When major organisations are breached, when ransomware hits the headlines ...

Security Operations Engineer | Strategic Financial Risk Solutions Firm

Hiring Organisation
Techfellow Limited
Location
London Area, United Kingdom
modernisation of its technology and security environment. As part of this programme, the organisation is strengthening its Security Operations capability to improve threat detection, response, and operational automation across its infrastructure and cloud platforms. This role sits within a small, hands-on Security Operations team reporting into the Head … SecOps. The team works closely with an external MSSP that provides 24/7 monitoring support, while internal engineers focus on detection quality, incident response, and improving operational capabilities. The position is intentionally broad - blending elements of detection engineering, alert investigation, threat hunting, and automation - and will play ...

DFIR Specialist

Hiring Organisation
Opus Recruitment Solutions
Location
United Kingdom
Remote - £70,000 - £95,000 + Bonus Opus is partnered with a major UK enterprise undergoing significant investment in its cyber defence and incident response capability. They are looking for highly experienced DFIR Specialists to join their growing security function. This role is fully remote within … suited to professionals who thrive in complex, large‐scale environments where digital forensics and incident response are critical to business resilience. Key Responsibilities Lead and support end‐to‐end incident response, from initial triage through containment, eradication, and recovery. Conduct digital forensic investigations across endpoints, servers ...

Cyber Security Operations Manager

Hiring Organisation
Searchability (UK) Ltd
Location
Deeside, Flintshire, Wales, United Kingdom
Employment Type
Permanent, Work From Home
CYBER SECURITY OPERATIONS MANAGER - CHESTER (HYBRID) KEY POINTS Senior operational security leadership role Lead Security Operations, Incident Response & Vulnerability Management Hybrid working - minimum 2 days per week onsite in the Chester Area Competitive salary ABOUT THE CLIENT We're working with a well-established UK organisation recognised … responsible for leading the day-to-day operational security activities that protect the organisation's systems and data. You'll manage security monitoring, incident response, and vulnerability management processes, ensuring they remain effective, efficient, and aligned with industry best practice. A key part of the role will ...

Incident and Vulnerability Manager

Hiring Organisation
Intellectual Property Office
Location
Newport, Gwent, Wales, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£55,000
Incident and Vulnerability Manager This role is for an experienced professional in vulnerability management and threat intelligence to join our Cyber Operations team. You will work closely with colleagues across the organisation to further mature and continuously improve our cyber defence capabilities. Cyber Operations forms part of a wider … intelligence products with internal and external stakeholders and use this intelligence to support vulnerability management and threat hunting activities. Additionally, you will contribute to incident response processes and provide support to colleagues responsible for the IPOs protection, detection, and response capabilities. if you have strong relevant expertise ...

Security Operations Team Lead

Hiring Organisation
Forward Role
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£85,000
ensuring the organisation's systems, networks, and data remain protected against evolving cyber threats. As the SecOps Lead, you will manage security monitoring and incident response activities while providing strategic direction for security tools including SIEM and Endpoint Detection & Response (EDR) platforms. You will work closely with … daily operational activities and performance. Define and implement the strategy and operational roadmap for security monitoring, detection, and response. Own and manage the security incident response lifecycle, including investigation, containment, remediation, and post-incident reviews. Lead incident response efforts during high-severity security events ...

Senior Cyber Security Engineer

Hiring Organisation
NTT Global Data Centers EMEA UK ltd
Location
Hemel Hempstead, Hertfordshire, South East, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. Directs complex security incident response efforts across multiple vectorsendpoint protection, EDR, malware analysis, network and computer forensicsensuring rapid containment and root cause analysis. Designs and executes advanced vulnerability ...

Palo Alto XSoar Developer

Hiring Organisation
iBSC
Location
London, United Kingdom
Employment Type
Permanent
Salary
GBP 70,000 - 80,000 Annual
Developer Role Candidates in this role are responsible for the development and maintenance of the code and capabilities of the Security Orchestration, Automation and Response (SOAR) platform. Candidates will work with the Manager of Detection & Response Engineering and will work jointly with our detection engineering, threat detection … response teams to specify clear priorities, evaluate technical tradeoffs, and build high-impact features within the SOAR platform. The candidates' main responsibilities will be to: Focus on the development, maintenance, and delivery of new Security Orchestration and Automation content including custom SOAR Playbooks, Automations/Scripts, Jobs, dashboards, reports ...

Lead SOC Analyst - London

Hiring Organisation
Anson Mccade
Location
London, United Kingdom
Employment Type
Permanent
Salary
£65,000
Lead SOC Analyst, the position will act as the escalation point for complex security incidents, driving investigations, guiding junior analysts, and ensuring effective response and remediation across critical systems. Whats on Offer Salary: £55,000 £65,000 25% shift allowance on top of base salary Structured shift pattern … days and nights (3 days on/4 days off rotation) Exposure to highly secure, cutting-edge infrastructure environments Opportunity to work on advanced incident response and threat analysis Career progression within a specialist cyber security function What You Need To be successful in this role, candidates should ...

AD Engineer JD L2

Hiring Organisation
Stackstudio Digital Ltd
Location
United Kingdom
Employment Type
Permanent
with hybrid identity, AAD Connect, and secure authentication methods (MFA, SSO). Familiarity with privileged access management (PAM) or PIM solutions. Strong troubleshooting and incident-response skills. Soft Skills Strong communication skills and ability to work with business stakeholders. Strong communication skills with the ability to interact with … PowerShell and Microsoft Identity solutions. Manage service accounts, privileged accounts, and password policies. Work with HR and application teams to streamline identity lifecycle operations. Incident Response & Troubleshooting Investigate authentication failures, account lockouts, replication issues, and access anomalies. Support incident response for identity related threats such ...

SOC Shift Lead - London

Hiring Organisation
Anson Mccade
Location
London, United Kingdom
Employment Type
Permanent
Salary
£80,000
platforms. The SOC Shift Lead will take ownership of security operations during assigned shifts, acting as the senior escalation point for complex incidents, leading response activities, and ensuring effective coordination across teams. This role also carries leadership responsibility, including oversight of analysts and accountability in the absence of senior … Clear progression within a specialist cyber security function What You Need To succeed in this role, candidates should demonstrate: 710 years experience in SOC, incident response, or threat analysis Strong leadership capability, with experience mentoring or guiding analysts Proven experience acting as an escalation point for high-severity ...

Senior Cyber Operations Analyst

Hiring Organisation
Anson Mccade
Location
United Kingdom
Employment Type
Permanent, Work From Home
Salary
£75,000
heart of a thriving Cyber Practice covering Assurance, Compliance, SecOps, Offensive Security and Research. You'll play a pivotal part in threat detection, incident response, detection engineering, and security monitoring - helping defend major UK organisations. This role is perfect for someone who thrives in technical depth, enjoys problem … improvements Review and uplift existing SecOps standards, logging maturity, BAU monitoring and threat-led optimisation Perform day-to-day security monitoring, alert triage and incident response (9am-5:30pm rota) Investigate cyber security incidents and provide technical leadership during escalations Mentor junior analysts through shadowing and hands ...

Senior Security Analyst

Hiring Organisation
Surrey County Council
Location
Reigate, Surrey, United Kingdom
Employment Type
Permanent
work will include proactive security monitoring across our hybrid cloud and on premises environment, triaging and investigating alerts, and supporting coordinated incident response activities. You will operate our vulnerability management processes, translate threat intelligence into actionable defences, and contribute to the improvement of detection content and security controls. … contribute to several high impact initiatives including: Establishing a more mature, risk based vulnerability management lifecycle and reducing exposure windows across critical systems Enhancing incident response readiness through improved playbooks, scenario testing, and lessons learned processes Uplifting monitoring coverage and the effectiveness of SIEM/EDR/ ...

SOC Analyst (L2 / L3)

Hiring Organisation
InvitISE Ltd
Location
London, South East, England, United Kingdom
Employment Type
Contractor
Contract Rate
£400 - £600 per day
This is an initial 6 month contract paying up to £600 per day Outside IR35. The role focuses on supporting security operations monitoring and incident response activities within a large enterprise environment. This role allows remote working with occasional travel to London when required. The successful SOC Analyst … cyber security incidents and responding appropriately • Working with SIEM platforms such as Splunk, Sentinel or QRadar • Conducting threat analysis and triaging security alerts • Supporting incident response and remediation activities • Working with security engineering teams to improve detection capabilities Experience within financial services, fintech or other regulated environments would ...

Privacy Solutions Product Owner

Hiring Organisation
Sky
Location
TW75QD, Syon, Greater London, United Kingdom
Employment Type
Permanent
targeting. Drawing on deep experience in how datadriven products work, you'll guide teams through complex devicelevel data flows, assess realworld impacts, and lead incident response when risks surface. Alongside this, you'll help build and evolve a practical privacy toolkit-patterns, guardrails, and automated checks-that teams … with delivery teams - review technical designs, implementations, and onboarding of new tools, SDKs, vendors, and platforms, challenging approaches where privacy risks emerge. Lead privacy incident response - act as the onpoint SME during incidents, supporting rootcause analysis, impact assessment, and remediation. Raise capability across teams - coach engineers and product ...

ServiceNow SecOps Architect - london, UK

Hiring Organisation
Infoplus Technologies UK Ltd
Location
East London, London, United Kingdom
Employment Type
Contract
energy assets, and millions of customers. Your responsibilities: (Up to 10, Avoid repetition) Design and own the architecture for ServiceNow SecOps modules including Security Incident Response, Vulnerability Response, Threat Intelligence, and Configuration Compliance. Lead integration of ServiceNow with key cybersecurity tools: SIEM, SOAR, EDR, CMDB, threat intelligence … platforms, and OT/ICS systems. Collaborate across cybersecurity, IT, engineering, and energy operations to define secure workflows and automation for vulnerability and incident response. Shape the roadmap and best practices for our ServiceNow platform across multiple business units. Champion platform governance, scalability, reuse, and alignment with ServiceNow ...

Cyber Security Engineer

Hiring Organisation
Womble Bond Dickinson
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent, Work From Home
endpoint, email, identity, network, cloud and application layers. Manage and integrate a broad ecosystem of third-party cyber security platforms, including managed detection and response services, email security gateways, vulnerability management tools, privileged access management and threat intelligence services. Lead and support cyber security incident response activities … including investigation, containment, remediation and post incident review. Oversee security monitoring, alerting and response processes, working closely with managed service providers where applicable. Conduct and coordinate vulnerability assessment and remediation activities across infrastructure, endpoints, applications and cloud services. Support regulatory, client and internal audits (e.g. ISO 27001), including ...

Security Operations Manager

Hiring Organisation
Vitality Corporate Services Limited - Tech
Location
Bournemouth, Dorset, South West, United Kingdom
Employment Type
Permanent
Salary
£65,000
Vitality BournemouthOffice.Full time, 35 hours per week. We are happy to discuss flexible working! Top 3 skills needed for this role: Security Operations Leadership & Incident Response Risk, Governance & Regulatory Compliance Technical Depth in Monitoring & Security Engineering What this role is all about: Join our dynamic, values-led organisation … CISO in delivering our security strategy, lead a team of analysts, and oversee key controls that protect member data. The role includes security monitoring, incident response, developing playbooks, and managing the CSIRT function. Key Actions Leadership and management of the Cyber Security Operations team Conducting cyber security maturity ...

Site Reliability Engineer (Contractor)

Hiring Organisation
Harnham - Data & Analytics Recruitment
Location
London, South East, England, United Kingdom
Employment Type
Contractor
Contract Rate
£540 - £550 per day
centralised SRE model, you'll partner closely with product and engineering teams while maintaining horizontal responsibility for production health, resilience, and scalability.You'll lead incident response, define reliability standards, influence architectural decisions, and build automation that elevates deployment safety and operational efficiency. This is a hands-on, senior … risks and drive long-term preventative improvements* Define and refine SLIs, SLOs, and error budgets aligned to customer and business outcomes* Lead high-severity incident response, post-incident reviews, and remediation planningArchitecture & Resilience* Influence system architecture to improve scalability, availability, and failure isolation* Design multi-region ...

Information Security Manager

Hiring Organisation
Saab UK
Location
Hull, North Humberside, North East, United Kingdom
Employment Type
Permanent
GDPR and guidance from the National Cyber Security Centre. Work with internal teams and suppliers to implement proportionate and effective security controls. Security Operations & Incident Management Act as the primary point of contact for security incidents, leading or coordinating response activities. Take a hands-on role in incident investigation, root cause analysis, and remediation. Ensure that incident response processes are aligned to the operational needs of emergency service environments, including timely escalation and communication. Oversee vulnerability management, security testing, and remediation activities, engaging third parties where required (e.g., CHECK providers). Service Resilience & Operational Security ...

SOC Analyst (L1)

Hiring Organisation
Chapman Tate Associates
Location
Aylesbury, Buckinghamshire, England, United Kingdom
Employment Type
Full-Time
Salary
£25,000 per annum
dashboards, alerts, and log data to identify suspicious or malicious activity. Alert Triage: Perform initial investigation and prioritisation of security alerts, escalating where necessary. Incident Response (L1): Assist in incident investigation, gather relevant evidence, and support escalation to senior analysts or IR teams. Threat Detection: Support detection … Exposure to SIEM tools (e.g., Sumo Logic, Microsoft Sentinel) Familiarity with EDR/XDR tools (e.g., CrowdStrike, Microsoft Defender) Basic understanding of: Security operations Incident response lifecycle Networking fundamentals (TCP/IP, DNS, etc.) Strong analytical and problem-solving skills Good communication skills (written and verbal) Ability ...

Senior Security Analyst

Hiring Organisation
Arthur
Location
City of London, London, England, United Kingdom
Employment Type
Full-Time
Salary
Competitive salary
built for you.We’re hiring a hands-on Senior Security Analyst/Security Engineer to strengthen a Microsoft-centric security posture across detection, response, tooling, and infrastructure hardening. Not a one-lane SOC role. Not governance-heavy. This role blends incident response with security engineering and hardening … Cyber Essentials, NIST, SOC2) Contribute to threat hunting, threat intelligence application and proactive monitoring Support operational resilience: scenario testing, DR exercises, post-incident reviews Assist with security tooling assessments (including AD hardening tools ) Essential Experience (Must Haves) Candidates must have: Security Engineering & Hardening IAM, PIM/PAM , identity lifecycle ...