1 to 25 of 1,215 Incident Response Jobs in the UK

Security Incident Response (ServiceNow SIR) Engineer

Hiring Organisation
Talent Smart Limited
Location
Home Based, United Kingdom
Employment Type
Contract
Contract Rate
GBP 700 Daily
Important: ServiceNow SIR certification is mandatory for this role. Candidates who do not hold a current, relevant ServiceNow SIR/Security Incident Response certification cannot be considered. ServiceNow Security Incident Response (SIR) Engineer - Contract £700 per day | Initial 6 months | Major Cyber Security Programme … looking for a specialist ServiceNow Security Incident Response Engineer to join a major enterprise cyber security programme and help build, automate and strengthen its security incident response capability. This is not a general ServiceNow development role. We need someone who genuinely specialises in ServiceNow Security Operations ...

Senior Manager - Cyber Incident & Response - Consulting

Hiring Organisation
Oliver James
Location
London, South East England, United Kingdom
Employment Type
Full-Time
Salary
£100,000 - £110,000 per annum
Senior Manager/Associate Director - Cyber Incident Response Advisory & Incident Management This is a senior opportunity within a leading Cyber Risk & Security practice, working with major organisations to strengthen their ability to prepare for, manage and recover from complex cyber incidents. The role sits across both proactive … cyber incident response advisory and live incident management, helping clients improve resilience while supporting them through high-impact security events. You will work closely with senior stakeholders and C-suite leaders, advising on cyber incident preparedness, crisis and incident management, response strategies and organisational ...

Cyber Response & Recovery Manager (Reactive DFIR) - German Speaking

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice. Your specific … focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands-on incident response role and an opportunity to join a high performing team that works with a wide ...

Cyber Defense Incident Responder - Associate Director

Location
Greater London, England, United Kingdom
responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Senior Manager, Cybersecurity Incident Response

Hiring Organisation
ARM
Location
Cambridge, Cambridgeshire, UK
Employment Type
Full-time
Overview: Interested in defending a global tech company from the latest cyber threats? Arm is seeking a passionate, experienced Senior Manager of Cybersecurity Incident Response to join our growing Cyber Defence Operations (CDO) team, protecting Arm against current and future cyber-attacks! Situated within Arm's Enterprise Security … function, this role will lead Arm's global incident response team across the US, UK and India, including acting as a senior technical and operational leader for major cyber incidents. CDO enables Arm to be successful, delivering scalable and defendable security services that not only provide ...

Cyber Defense Incident Responder

Location
Greater London, England, United Kingdom
responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Cyber Response & Recovery Assistant Manager (Reactive DFIR)

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Assistant Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Assistant Manager role will be working in the Cyber Response Services (CRS) Team within our Advisory practice. Your … specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a junior case manager on smaller cases, or part of a team (reporting to a case manager or senior case manager) on larger cases. This is a hands-on role ...

Head of Cyber Defence & Incident Response London - United Kingdom - Full Time

Location
Greater London, England, United Kingdom
Head of Cyber Defence & Incident Response At Quadient, we support businesses of all sizes in their digital transformation and growth journey, unlocking operational efficiency with reliable, secure, and sustainable automation processes. Our success in delivering innovation and business growth is inspired by the connections our diverse teams create … business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection ...

Senior Incident Response Consultant, Rapid Response

Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

Cyber Defense Incident Responder - Assistant Director

Hiring Organisation
EY (Ernst & Young)
Location
London, UK
Employment Type
Full-time
detects, responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunityThe Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Cyber Response & Recovery Manager (Remediation)

Hiring Organisation
KPMG UK
Location
City of London, London, United Kingdom
Cyber Response & Recovery Manager (Remediation) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG’s Cyber Advisory practice. Your specific focus will … compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience. This ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection … response and recovery. Reports directly to the CISO and leads cyber defence operations (including the MSSP) and cybersecurity incident response across the organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology. A key focus is optimising security tooling (e.g., SIEM ...

SOC Analyst - SC Cleared

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£545 - £590 per day + Inside IR35
environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams. You will … cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions. Key Responsibilities Security Monitoring & Incident Response Monitor and triage security alerts generated through SIEM and security tooling. Investigate and respond ...

Cyber Incident Manager (CIM) - Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland

Hiring Organisation
Tesco
Location
Welwyn Garden City, Hertfordshire, UK
Employment Type
Full-time
About the role: As a Cyber Incident Manager at Tesco, you will lead the coordinated response to cyber incidents, protecting the integrity of the retail ecosystem that serves millions of customers every day. Acting as a central orchestrator, you will ensure swift, structured, and effective incident resolution … minimising operational disruption and customer impact. This role is critical to maintaining trust in Tesco's digital platforms by driving proactive, intelligence-led response and embedding continuous improvement across the cyber defence lifecycle. You will operate at the intersection of technology, business impact, and customer outcomes, championing innovation ...

Senior Security & Cyber Operations Manager (Financial Services)

Hiring Organisation
Consol Partners
Location
London, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
Manager Location: Corporate Offices/Hybrid (UK) Industry: Financial Services/Insurance (Regulated Environment) Type: Full-Time, Permanent Senior Security & Cyber Operations Manager | Operations, Incident Response & AI Innovation End-to-end operational ownership of enterprise security operations (SOC), incident response, threat detection, and cyber defence capabilities. … Drive detection engineering, SOAR automation, and AI integration across cloud, hybrid infrastructure, endpoints, and third-party services. Key focus: Incident leadership, MSSP/vendor management, response playbooks, metrics (MTTD/MTTR), and executive risk governance. About the Opportunity A leading UK financial services organisation is seeking a high ...

Threat Response Technology and Capabilities Product Owner

Hiring Organisation
MasterCard
Location
Ringwood, Hampshire, UK
Employment Type
Full-time
networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and SummaryThreat Response Technology and Capabilities Product OwnerOverviewThe Corporate Security Threat and Response Management product ownership team is looking for a Lead Security Engineer to help … ideal candidate is passionate about the modern security tools, capabilities, and strategies. As a Product Owner, you will be defining, owning, and driving the incident response technology and capability strategy across global Security Operations. This role sets the vision for response tooling, automation, AI augmentation, and digital ...

Cyber Operations & 3rd Party Security Manager

Location
Greater London, England, United Kingdom
powered by modern technology. Job Purpose The Cyber Operations & 3rd-Party Security Manager is responsible for the Bank's cyber security operations, threat detection, incident response, vulnerability management and 3rd-party cyber risk management capabilities. The role ensures that cyber threats, vulnerabilities, supplier risks and security events … confidentiality, integrity and availability of the Bank's information assets and services. The role leads the operational execution of the Bank's Cyber Incident Response Plan (CIRP), manages relationships with security service providers, and provides oversight of cyber risks arising from suppliers, outsourced services and 3rd parties. ...

Cyber Incident Response Lead

Location
Greater London, England, United Kingdom
EC2R 7BP Manchester, GB, M1 4HN Bristol, GB, BS32 4TP Leiston, GB, IP16 4EW Felixstowe, GB, IP10 0DD Career Area: Data, Tech & IT Cyber Incident Response Lead Sizewell C’s business is to design, finance, construct, commission, operate, maintain, and eventually decommission the nuclear power plant and related … independent organisation and continue building one of the UK’s largest and most important energy projects. We are now recruiting the below position. Cyber Incident Response Lead Location: Based in London on a hybrid basis with travel to Suffolk as required. Contract : Permanent, full-time. Benefits include: Bonus ...

Cyber Defence Analyst

Location
United Kingdom
playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. … Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand ...

Cyber Defence Analyst

Location
Holywood, Kirkcudbrightshire, United Kingdom
playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. … Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand ...

Cyber Defence Analyst

Hiring Organisation
A&O Shearman
Location
City, Belfast, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. … Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand ...

Cyber Defence Analyst

Hiring Organisation
A&O Shearman
Location
Neston, Cheshire, United Kingdom
Employment Type
Permanent
Salary
GBP Annual
playbooks for the Cyber Defence team. Respond to inbound queries to the information security mailbox, consulting with more senior colleagues for advice where required. Incident Response: Participate in incident response activities, including CSIRT activities, for confirmed incidents in local time-zone: Conduct initial triage and investigation. … Assist with containment, mitigation, and remediation efforts, ensuring any forensic evidence is gathered and documented appropriately. Participate in security incident response exercises and contribute to post-exercise reviews. Be part of the Cyber Defence on-call rota, which may require out-of-hours work. Pick-up and hand ...

Operational Security Manager

Location
Farnborough, England, United Kingdom
will join a growing team of security professionals to protect and maintain the effectiveness of managed service capabilities. The Operational Security Manager supports cybersecurity incident response, investigation, escalation, and regulatory reporting, with a focus on the EU Cyber Resilience Act. Working across Cybersecurity, Product Security, Legal, Compliance, Privacy … Security Manager also provides technical leadership and continuously improves security processes, controls, and supporting technologies. What You'll Be Doing : Support the full cybersecurity incident response lifecycle, including triage, investigation, containment, escalation, remediation, recovery, and post-incident review across enterprise and product environments. Coordinate incident response ...

Lead Security Operations Engineer

Location
Greater London, England, United Kingdom
Define and deliver Pleo's SecOps roadmap for detection, response, and investigation capabilities Build a structured roadmap based on MITRE ATT&CK, NIST, and CIS benchmarks Lead security investigations and digital forensics through incident response Design, tune, and scale SIEM and standardized logging pipelines Strengthen perimeter … configuration, authorization tuning, and suspicious-traffic monitoring Implement DLP controls aligned with sensitive-data locations Improve the on-call rotation, alerting, escalation paths, and response SLAs Automate detection and response workflows using code and AI Reduce SecOps-attributed compliance risk and collect supporting evidence Build dashboards and reporting ...

Incident Response Specialist

Hiring Organisation
Marcus Donald People Ltd
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
GBP 500 - 600 Daily
Incident Response Specialist Working Hours : Wednesday to Saturday, 08:00 to 17:45 (UK Time) Rate: £500 - £600 per day inside IR35 - 12 month contract Remote with two days per month required in the London City office About the Role We are seeking an experienced Incident Response … opportunity to work in the Banking sector. This is an excellent opportunity for a cyber security professional looking to further develop their expertise in incident response, digital forensics, threat containment, and enterprise-scale cyber operations . You will work alongside experienced professionals across Threat Intelligence, Detection Engineering, Security ...