1 to 25 of 2,082 Incident Response Jobs in the UK

Senior / Lead Incident Response Engineer

Location
Greater London, England, United Kingdom
Title: Senior/Lead Incident Response Engineer Type: Permanent Location: London – Hybrid The Opportunity We are working with a leading, technology-driven financial services organisation to appoint two Senior/Lead Incident Response Engineers on a permanent basis. These are senior-level positions within a highly … sophisticated cybersecurity environment, suited to candidates who have built their careers in cybersecurity engineering and have subsequently developed deep expertise in incident response and major incident management. The organisation is looking for individuals who have already operated through large-scale, high-impact and business-critical cyber incidents ...

Incident Response Consultant (UK)

Location
United Kingdom
Difenda. This was closely followed in December 2024 by the acquisition of US-based, Kivu Consulting, a global cyber security firm with world-leading incident response capabilities. Role Purpose: Incident Response is a core and strategic component of Quorum Cyber’s business. It is central … managed security services and MDR customers, providing specialist expertise when incidents require investigation, containment, remediation, and recovery beyond routine monitoring and response. The Incident Response Consultant supports investigations into cyber security incidents and, with appropriate guidance, takes ownership of defined investigative workstreams. The role provides sound technical analysis ...

Cyber Response & Recovery Manager (Reactive DFIR) - German Speaking

Hiring Organisation
KPMG UK
Location
City of London, Greater London, UK
Cyber Response & Recovery Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice. Your specific … focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands-on incident response role and an opportunity to join a high performing team that works with a wide ...

Associate Manager - Cyber Security Incident Response

Hiring Organisation
Willis Towers Watson
Location
London, UK
Employment Type
Full-time
Associate Manager - Cyber Security Incident Response will play a pivotal role within WTW's Global Information and Cyber Security Defence (ICSD) function, leading the response to complex security incidents and driving initiatives to enhance WTW's Cyber incident management capabilities. This mid senior-level role requires … highly experienced professional with strong expertise in incident response and cybersecurity. The individual will work as part of a global, multi-disciplined security community with strong support across the business, contributing to fostering a security-aware culture while ensuring WTW remains a great place to work. With ...

Cyber Defense Incident Responder - Associate Director

Location
Greater London, England, United Kingdom
responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Senior Manager, Cybersecurity Incident Response

Hiring Organisation
ARM
Location
Cambridge, Cambridgeshire, UK
Employment Type
Full-time
Overview: Interested in defending a global tech company from the latest cyber threats? Arm is seeking a passionate, experienced Senior Manager of Cybersecurity Incident Response to join our growing Cyber Defence Operations (CDO) team, protecting Arm against current and future cyber-attacks! Situated within Arm's Enterprise Security … function, this role will lead Arm's global incident response team across the US, UK and India, including acting as a senior technical and operational leader for major cyber incidents. CDO enables Arm to be successful, delivering scalable and defendable security services that not only provide ...

Senior Incident Response Consultant 2

Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

Incident Response Lead

Hiring Organisation
Morson Edge
Location
Glasgow, Lanarkshire, Scotland, United Kingdom
Employment Type
Contract, Work From Home
Incident Response Lead Scottish Power HQ, Glasgow Flexible & Hybrid working pattern Negotiable rate, Inside IR35, PAYE and UMB options available Help us create a better future, quicker SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations … deliver a cyber resilient business and the Incident Response Lead is essential in achieving our goals. This role will be integrated into an active and ambitious global cyber security function, contributing to SPEN's cyber security purpose of delivering cyber resilient OT and IT, to enable a safe ...

Senior Manager, Global Cyber Security Incident Response (Global CSIRT)

Location
Greater London, England, United Kingdom
trusted security services that support KPMG’s digital transformation and help protect the network and its clients from cyber threats. The Global Cyber Security Incident Response Team forms part of Information Security Services and works alongside the Global Security Operations Centre to detect, investigate and support the remediation … potential threats. In this senior operational role, you will support the strategic direction, effectiveness and continued maturity of the global incident response capability. You will provide calm, credible leadership during major incidents, strengthen collaboration across member firms and deliver improvements that enhance cyber resilience and operational excellence. ...

Cyber Defense Incident Responder

Location
Greater London, England, United Kingdom
responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunity The Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Head of Cyber Defence & Incident Response London - United Kingdom - Full Time

Location
Greater London, England, United Kingdom
Head of Cyber Defence & Incident Response At Quadient, we support businesses of all sizes in their digital transformation and growth journey, unlocking operational efficiency with reliable, secure, and sustainable automation processes. Our success in delivering innovation and business growth is inspired by the connections our diverse teams create … business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection ...

Senior Incident Response Consultant, Rapid Response

Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

Cyber Defense Incident Responder - Assistant Director

Hiring Organisation
EY (Ernst & Young)
Location
London, UK
Employment Type
Full-time
detects, responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunityThe Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

SOC and Incident Response Lead

Location
City Of London, England, United Kingdom
need any adjustments throughout the process in whatever way works best for you. Job Description The Role As an experienced SOC and Incident Response Lead at ASOS, you will provide hands-on technical leadership across security monitoring, detection, engineering, incident response, and threat-led investigations. … will lead the SOC and Incident Response team, ensure security incidents are investigated and resolved effectively, and maintain a strong operating relationship with our external MSSP. The ideal candidate will combine deep technical expertise with proven experience leading analysts, improving operational capability, managing stakeholders, and making sound decisions ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection … response and recovery. Reports directly to the CISO and leads cyber defence operations (including the MSSP) and cybersecurity incident response across the organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology. A key focus is optimising security tooling (e.g., SIEM ...

Associate/Senior Associate - Data & Cyber

Location
West of England, England, United Kingdom
Data & Cyber team advises a wide range of clients across a variety of industry sectors on cyber incidents, regulatory response, technology and data-related claims, and cyber/technology insurance coverage. We are recognised for combining deep cyber incident response capability with a strong understanding … insurance market, enabling us to support clients across the lifecycle of a cyber event and its downstream exposures: from immediate breach response and crisis management, through policy notification and coverage strategy, to regulatory engagement and dispute resolution. The role Based in Bristol, the Associate (1-4 years ...

Regional CERT Manager

Location
Kingston, England, United Kingdom
planet. That’s why our purpose is ‘to make sustainable living commonplace’ Role Overview The Regional CERT Manager is responsible for leading cyber incident response operations across the region, ensuring effective detection, containment, investigation, remediation, and recovery from security incidents. This role combines strategic leadership with hands … technical expertise to drive operational excellence, strengthen security capabilities, and enhance organisational cyber resilience. Key Responsibilities Lead regional Cyber Emergency Response Team (CERT) operations, providing both strategic direction and technical guidance for complex cyber security incidents. Own and continuously improve the end‐to‐end Incident Management lifecycle, ensuring ...

Incident Response Consultant - Weekend Shift (Remote, GBR)

Hiring Organisation
CrowdStrike
Location
United Kingdom
Employment Type
Permanent
Salary
GBP Annual
opportunity to rapidly accelerate your skills? Do you crave new and innovative work that actually matters to your customer? Do you have an Incident Response or Information Security background that you're not fully utilizing? Are you capable of leading teams and interacting with customers? Do you love … working around like-minded, smart people who you can learn from and mentor on a daily basis? What You ll Do: Lead incident response engagements. Develop and use new methods to hunt for bad actors across large sets of data. Work under the direction of outside counsel ...

Incident Response Consultant - Weekend Shift (Remote, GBR)

Location
London, United Kingdom
opportunity to rapidly accelerate your skills? Do you crave new and innovative work that actually matters to your customer? Do you have an Incident Response or Information Security background that you’re not fully utilizing? Are you capable of leading teams and interacting with customers? Do you love … working around like-minded, smart people who you can learn from and mentor on a daily basis? What You''ll Do: Lead incident response engagements. Develop and use new methods to hunt for bad actors across large sets of data. Work under the direction of outside counsel ...

SOC Analyst - SC Cleared

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£545 - £590 per day + Inside IR35
environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams. You will … cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions. Key Responsibilities Security Monitoring & Incident Response Monitor and triage security alerts generated through SIEM and security tooling. Investigate and respond ...

Senior Professional Services Consultant

Location
City Of London, England, United Kingdom
will play a key role in helping organisations strengthen their cyber resilience through the delivery of Solis Security's professional services. Working across Cyber Incident Exercising (CIE), Managed Detection and Response (MDR) and Incident Response (IR), you will partner with clients, delivery teams and commercial stakeholders … offers the opportunity to work on a diverse range of engagements, supporting clients across multiple sectors and geographies. You'll lead and facilitate cyber incident exercises, support client onboarding and service adoption, contribute to incident triage activities and collaborate closely with our Security Operations and Incident Response ...

Senior Security Engineer, Security Incident Response Team (SIRT) - EMEA

Hiring Organisation
GitLab
Location
United Kingdom, UK
Employment Type
Full-time
affiliated with, and do not endorse products or services of GitLab. An overview of this roleAs a Senior Security Engineer on GitLab's Security Incident Response Team (SIRT), you will play a critical role in defending GitLab.com and the broader GitLab environment against evolving security threats. This role … provide 24/7/365 security coverage. You will lead high-impact incidents and investigations, drive continuous improvements in defense, detection and response capabilities, and help scale security operations through automation and intelligent workflows. Operating within a 24/7 global environment (follow the sun model), you will ...

Security Incident Response Manager

Location
Greater London, England, United Kingdom
securely. KPMG is evolving Security Operations across the UK and Switzerland to create a more integrated, intelligence-led approach to cyber resilience. As Security Incident Response Manager, you will lead the Tier 2 Incident Response function and be accountable for managing cyber security incidents escalated … business hours. You must be eligible for Security Check clearance or able to obtain it. Roles and responsibilities Lead, coach and develop Tier 2 Incident Response Analysts, setting clear standards and providing technical guidance. Direct complex investigations across endpoint, identity, email, cloud and network environments, coordinating activity from ...

Cyber Incident Manager (CIM) - Welwyn Garden City, United Kingdom of Great Britain and Northern Ireland

Hiring Organisation
Tesco
Location
Welwyn Garden City, Hertfordshire, UK
Employment Type
Full-time
About the role: As a Cyber Incident Manager at Tesco, you will lead the coordinated response to cyber incidents, protecting the integrity of the retail ecosystem that serves millions of customers every day. Acting as a central orchestrator, you will ensure swift, structured, and effective incident resolution … minimising operational disruption and customer impact. This role is critical to maintaining trust in Tesco's digital platforms by driving proactive, intelligence-led response and embedding continuous improvement across the cyber defence lifecycle. You will operate at the intersection of technology, business impact, and customer outcomes, championing innovation ...

Security analyst - Sector security

Location
Manchester, England, United Kingdom
users across universities, colleges and research organisations. Combining cutting-edge security technologies, threat intelligence and specialist expertise, we provide 24/7 protection, rapid incident response and advanced threat detection to help our members stay secure and resilient. Security Centre brings together Cyber Security Incident Response (CSIRT), Digital Forensics and Incident Response (DFIR), SIEM Analysts and Network Defensive Services specialists. Working at the forefront of cyber defence, we identify and respond to threats, support organisations through cyber incidents, conduct threat hunting activities and continuously evolve our capabilities to stay ahead of emerging risks. ...