1 to 25 of 1,075 Incident Response Jobs in the UK

Senior Manager - Cyber Incident & Response - Consulting

Hiring Organisation
Oliver James
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£100,000 - £110,000 per annum
Senior Manager/Associate Director - Cyber Incident Response Advisory & Incident Management This is a senior opportunity within a leading Cyber Risk & Security practice, working with major organisations to strengthen their ability to prepare for, manage and recover from complex cyber incidents. The role sits across both proactive … cyber incident response advisory and live incident management, helping clients improve resilience while supporting them through high-impact security events. You will work closely with senior stakeholders and C-suite leaders, advising on cyber incident preparedness, crisis and incident management, response strategies and organisational ...

Cyber Response & Recovery Manager (Reactive DFIR) - German Speaking

Hiring Organisation
KPMG UK
Location
London, UK
Employment Type
Full-time
Description Cyber Response & Recovery Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice. Your … specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands-on incident response role and an opportunity to join a high performing team that works with ...

Cybersecurity Incident Response Lead

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Overview Executive level position reporting to the Director of Cyber Threat Management & Incident Response, this is a hands‐on senior security position working within the Information Security group and with the internal IT department. This position’s core focus is to ensure consistent, measurable end‐to‐end triage … successful candidate will work to assess, develop, and deploy detection capabilities and processes ensuring enterprise systems and data are protected, serving as the Incident Response Lead for European and Pacific regions of the organisation. We are looking for candidates who have a passion for cyber security, threat detection ...

ServiceNow SIR Engineer

Hiring Organisation
Talent Smart Limited
Location
Home Based, United Kingdom
Employment Type
Contract
Contract Rate
GBP 700 Daily
ServiceNow Security Incident Response (SIR) Engineer - Contract Contract: Initial contract engagement Rate: £700 per/day Specialism: ServiceNow SIR | SecOps | Cyber Security | Incident Response (Remote working) We are looking for an experienced ServiceNow Security Incident Response (SIR) Engineer to join a major cyber security … programme, helping to strengthen and automate the organisation's security incident response capability. Please note: Hands-on ServiceNow Security Incident Response (SIR) experience is an absolute requirement for this role. This is NOT a general ServiceNow Developer/Engineer position. Applicants without demonstrable ServiceNow SIR experience ...

Head of Cyber Defence & Incident Response London - United Kingdom - Full Time

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Head of Cyber Defence & Incident Response At Quadient, we support businesses of all sizes in their digital transformation and growth journey, unlocking operational efficiency with reliable, secure, and sustainable automation processes. Our success in delivering innovation and business growth is inspired by the connections our diverse teams create … business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection ...

Senior Incident Response Consultant, Rapid Response

Hiring Organisation
Jobleads-UK
Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

Cyber Response & Recovery Manager (Remediation)

Hiring Organisation
KPMG UK
Location
London, UK
Employment Type
Full-time
Description Cyber Response & Recovery Manager (Remediation) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG’s Cyber Advisory practice. Your specific focus … compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience. This ...

Director, Digital Forensics & Incident Response (Global)

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group’s global Digital Forensics … Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
Incident Response Consultant - Mid to Principal - UK Wide UK Remote | Up to £95,000 + benefits | SC Eligible Pref A specialist opportunity for experienced Incident Response professionals looking to work across a varied mix of proactive and reactive Digital Forensics & Incident Response (DFIR) engagements. … This is a hands-on consulting role where you will support organisations through cyber incidents while also helping them improve their readiness, resilience and response capability before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
Incident Response Consultant - Mid to Principal - UK Wide UK Remote | Up to £95,000 + benefits | SC Eligible Pref A specialist opportunity for experienced Incident Response professionals looking to work across a varied mix of proactive and reactive Digital Forensics & Incident Response (DFIR) engagements. … This is a hands-on consulting role where you will support organisations through cyber incidents while also helping them improve their readiness, resilience and response capability before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment ...

SOC Analyst - SC Cleared

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£545 - £590 per day + Inside IR35
environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams. You will … cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions. Key Responsibilities Security Monitoring & Incident Response Monitor and triage security alerts generated through SIEM and security tooling. Investigate and respond ...

Cyber Technical Lead

Hiring Organisation
Jobleads-UK
Location
Maidenhead, England, United Kingdom
Join Maersk’s Groundbreaking Cyber Team: Redefining Incident Management & Response Imagine a career where you’re not just responding to security incidents—you’re revolutionising how it’s done. At Maersk, one of the world’s largest and most respected logistics and shipping companies, our Cyber team … pioneering a whole new approach to incident response. This isn’t your typical SOC/CERT role: our combined fire team approach team is built on cutting‐edge research and designed to drive change, resilience, and agility in ways the industry has never seen before. Here ...

Cyber Operations & 3rd Party Security Manager

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
powered by modern technology. Job Purpose The Cyber Operations & 3rd-Party Security Manager is responsible for the Bank's cyber security operations, threat detection, incident response, vulnerability management and 3rd-party cyber risk management capabilities. The role ensures that cyber threats, vulnerabilities, supplier risks and security events … confidentiality, integrity and availability of the Bank's information assets and services. The role leads the operational execution of the Bank's Cyber Incident Response Plan (CIRP), manages relationships with security service providers, and provides oversight of cyber risks arising from suppliers, outsourced services and 3rd parties. ...

Lead Security Operations Engineer

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Define and deliver Pleo's SecOps roadmap for detection, response, and investigation capabilities Build a structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks Lead security investigations and digital forensics through incident response Design, tune, and scale SIEM and standardized logging pipelines Strengthen perimeter … configuration, authorization tuning, and suspicious-traffic monitoring Implement DLP controls aligned with sensitive-data locations Improve the on-call rotation, alerting, escalation paths, and response SLAs Automate detection and response workflows using code and AI Reduce SecOps-attributed compliance risk and collect supporting evidence Build dashboards and reporting ...

Senior Cyber Security Engineer

Hiring Organisation
Comtecs
Location
City of London, London, United Kingdom
Employment Type
Permanent
Cyber Security Specialist/Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team … identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across ...

Cyber Security Engineer - MS Sentinel, Defender, SSO, PKI, SC-100/200, CISSP

Hiring Organisation
Comtecs Ltd
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£90,000 - £100,000 per annum
Cyber Security Specialist/Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team … identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across ...

Senior Cyber Security Analyst

Hiring Organisation
Anson Mccade
Location
Central London, London, United Kingdom
Employment Type
Permanent
Blue Team within a dynamic Cyber Practice. This senior role offers the chance to work on high-profile client engagements, delivering threat detection, monitoring, incident response, and security operations expertise. The role is ideal for a self-motivated professional with strong technical skills, inquisitive thinking, and a passion … protecting enterprise systems from evolving cyber threats. The Role The Cyber Security Operations Specialist will use advanced tools and threat intelligence to ensure effective incident detection and response across client environments. Working closely with security analysts and wider teams, the role combines detection engineering, monitoring, incident response ...

Cyber Security Engineer II

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Software-as-a-Service business areas. You will be responsible for helping to build out and deploy security automation, harden security configuration, provide incident response, and more within the Cyber Security Engineering team. Cyber Security Engineers are expected to have a broad understanding of security principles … experienced Security Operations Centre analyst, or Site Reliability Engineer looking to transition into Security Engineering. You will: Lead the design, develop, and implementation of incident response playbooks Perform incident response and coordination Lead in the assessment of system design and change Be part of a weekly ...

Senior Security and Cyber Operations Manager

Hiring Organisation
McCabe & Barton
Location
City of London, London, United Kingdom
Employment Type
Permanent
Financial Services organisation is looking for a Senior Security and Cyber Operations Manager to take ownership of its security operations, cyber defence, monitoring and incident response capabilities. This is a senior, hands-on role within the CISO function, responsible for strengthening the organisations cyber defence capability and ensuring … very flexible working. You will work closely with Technology, Cloud, Data, Architecture, Risk and external security partners, with responsibility for security tooling, detection coverage, incident response, operational cyber risk and service performance. Key Responsibilities Own and continually improve the organisations security operations and cyber defence capability Lead security ...

Associate Security Analyst

Hiring Organisation
GTC Recruitment
Location
London, UK
Employment Type
Full-time
protection of critical digital services, infrastructure and information assets against cyber threats. You will join a dedicated Cyber Defence team, supporting security alert triage, incident investigation, threat detection and cyber incident response. Key Responsibilities Triage and investigate cyber security alerts and user-reported security incidents. Investigate systems, files … network traffic and cloud environments to identify potential threats. Use SIEM and EDR technologies to detect, investigate and respond to cyber threats. Support cyber incident response activities, including containment, eradication and recovery. Assist with the coordination and management of security incidents. Contribute to post-incident reviews, lessons ...

Senior Security Consultant (Incident Response)

Hiring Organisation
Jobleads-UK
Location
Birmingham, England, United Kingdom
Select how often (in days) to receive an alert: Create Alert Senior Security Consultant (Incident Response) Job ID:44293 Location:UK : Home Based Position Category:Consulting Position Type:Employee Regular Senior Security Consultant Role Purpose: This is a new, exciting opportunity for a Senior Security Consultant to join … LRQA’s existing dynamic Cyber Incident Response Team. This role follows a hybrid working arrangement and will involve working on client sites and from the office from time to time. We support remote work across the UK; however, the main office is in Birmingham. Applicants are required ...

Cyber Security Consultant

Hiring Organisation
Radius Consultancy
Location
London, United Kingdom
Employment Type
Permanent
Salary
£80000 - £90000/annum
SIEM, NDR, applications, security architecture, IAM, PAM encryption technologies, network security, Zero Trust, secure interconnection patterns and cyber security principles. Experience within Security Operations, Incident Response, Security Assurance, or GRC functions. Experience managing or overseeing MSSP, SOC activities, third party management. Strong understanding of: ISO 27001, SOC2, NIST … Cyber Security Framework, Incident Response methodologies, Cyber Security Governance, GDPR and regulatory compliance Certifications (one or more) CISSP CISM CRISC The Cyber Security Assurance & Incident Response Lead is responsible for strengthening and maintaining Telehouse's cyber security posture through effective security assurance, incident response ...

Graduate SOC Analyst

Hiring Organisation
CyPro
Location
London, UK
Employment Type
Full-time
pigeonholed into one narrow specialism. At CyPro, you’ll have the opportunity to get involved in a wide range of areas including monitoring, incident response, threat intelligence, detection engineering, automation and internal security operations. You’ll play a key role in our Security Operations Centre, delivering … monitoring, detection and response to our growing customer base. You’ll contribute to building out our capabilities, improving tooling and processes, and shaping how we operate as the function matures. As the team grows further, you’ll have the flexibility to focus more deeply on the areas that interest ...

Senior Cyber Threat Intelligence (CTI) Analyst

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Cyber Threat Intelligence (CTI) Analyst to drive hands‐on intelligence analysis and research across our global environment. This role sits within the Detection and Response Engineering, CTI, and Threat Hunting team. The team focuses on identifying emerging threats, conducting in-depth analysis of malicious activity, and enhancing the organization … security posture, detection, and incident response capabilities. THE ROLE This is a hands‐on senior individual contributor role for an analyst who wants to stay technical: researching threat actors and their infrastructure, digging into malware and phishing campaigns, tracking ransomware and the cybercrime ecosystems targeting live entertainment, ticketing ...

Incident Response Engineer Information security London

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
getting started. The role This role exists to ensure security incidents are rare, contained, and unsurprising. You will own the technical direction of security incident response and response readiness across the company. When a serious incident occurs, you lead from the front — investigating, containing, and driving … Security Operations, IT, and Engineering to reduce real risk, not theoretical risk. What you’ll be responsible for Leading the end-to-end technical response to high-severity security incidents Owning investigation, containment, eradication, and recovery activities Acting as the senior technical authority during live incidents Providing clear, decisive ...