1 to 25 of 353 Incident Response Jobs in the UK

Cyber Response & Recovery Manager (Reactive DFIR) - German Speaking

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice. Your specific … focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands-on incident response role and an opportunity to join a high performing team that works with a wide ...

Cyber Response & Recovery Assistant Manager (Reactive DFIR)

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Assistant Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Assistant Manager role will be working in the Cyber Response Services (CRS) Team within our Advisory practice. Your … specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a junior case manager on smaller cases, or part of a team (reporting to a case manager or senior case manager) on larger cases. This is a hands-on role ...

Cyber Response & Recovery Manager (Remediation)

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Manager (Remediation) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG’s Cyber Advisory practice. Your specific focus will … compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience. This ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
Incident Response Consultant - Mid to Principal - UK Wide UK Remote | Up to £95,000 + benefits | SC Eligible Pref A specialist opportunity for experienced Incident Response professionals looking to work across a varied mix of proactive and reactive Digital Forensics & Incident Response (DFIR) engagements. … This is a hands-on consulting role where you will support organisations through cyber incidents while also helping them improve their readiness, resilience and response capability before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
Incident Response Consultant - Mid to Principal - UK Wide UK Remote | Up to £95,000 + benefits | SC Eligible Pref A specialist opportunity for experienced Incident Response professionals looking to work across a varied mix of proactive and reactive Digital Forensics & Incident Response (DFIR) engagements. … This is a hands-on consulting role where you will support organisations through cyber incidents while also helping them improve their readiness, resilience and response capability before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment ...

Head of Cyber Defence & Incident Response

Hiring Organisation
Quadient
Location
Greater London, United Kingdom
Employment Type
Full Time
business lead the way in powering secure and sustainable business connections through digital and physical channels. Job Description The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‐prem and cloud platforms), ensuring effective monitoring, detection … response and recovery. Reports directly to the CISO and leads cyber defence operations (including the MSSP) and cybersecurity incident response across the organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology. A key focus is optimising security tooling (e.g., SIEM ...

Associate/Senior Associate - Data & Cyber

Hiring Organisation
RPC
Location
Greater London, United Kingdom
Employment Type
Full Time
ROLE OVERVIEW The team The Data & Cyber team advises a wide range of clients across a variety of industry sectors on cyber incidents, regulatory response, technology and data-related claims, and cyber/technology insurance coverage. We are recognised for combining deep cyber incident response capability with … understanding of the insurance market, enabling us to support clients across the lifecycle of a cyber event and its downstream exposures: from immediate breach response and crisis management, through policy notification and coverage strategy, to regulatory engagement and dispute resolution. The role Based in London, the Associate ...

SOC Analyst - SC Cleared

Hiring Organisation
Sanderson Government and Defence
Location
London, United Kingdom
Employment Type
Contract
Contract Rate
£545 - £590 per day + Inside IR35
environments, helping clients protect critical services, systems, and data against evolving cyber threats. The successful candidates will play a key role in security monitoring, incident response, detection engineering, and threat analysis, working alongside Security Operations, Threat Intelligence, and Incident Response teams. You will … cyber security subject matter expert, helping to strengthen defensive capabilities while contributing to the continuous improvement of security operations, threat detection, and incident response functions. Key Responsibilities Security Monitoring & Incident Response Monitor and triage security alerts generated through SIEM and security tooling. Investigate and respond ...

Incident Response Specialist

Hiring Organisation
Pontoon
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Contract
Contract Rate
£700/day
take your cyber security expertise to the next level? Our client, a leader in the energy sector, is on the lookout for an Incident Response Specialist to join their dynamic cyber security team. Role: Incident Response Specialist Duration: 6 Months (ext. options) Location: Warwick (Hybrid … mindset, promoting shared responsibility among Security Operations teams. Your contributions will be vital in defending against an ever-evolving threat landscape. Key Responsibilities Include: Incident Response: Triage and manage high-priority incidents while ensuring appropriate responses are executed. Produce clear incident summaries quickly and adapt your communication ...

Senior Cyber Security Engineer

Hiring Organisation
Comtecs
Location
City of London, London, United Kingdom
Employment Type
Permanent
Cyber Security Specialist/Cyber Security Engineer - CISSP, CEH, CCNA Security, Incident Response, Threat Monitoring, Vulnerability Management, Security Architecture, Azure, Windows Server Infrastructure. Permanent. London Hybrid. c.£90k - £100k + Bons +Benefits Global Law Firm seeks an experienced IT Cyber Security Specialist to join its Infrastructure Engineering team … identify vulnerabilities, respond to incidents and strengthen the firm's overall security posture. This is a hands-on technical role covering Cyber Security Engineering, Incident Response, Threat Monitoring, Vulnerability Management and Security Architecture (Infrastructure focussed) using tools such as MS Defender and MS Sentinel. You'll work across ...

Senior Cyber Security Analyst

Hiring Organisation
Anson Mccade
Location
Central London, London, United Kingdom
Employment Type
Permanent
Blue Team within a dynamic Cyber Practice. This senior role offers the chance to work on high-profile client engagements, delivering threat detection, monitoring, incident response, and security operations expertise. The role is ideal for a self-motivated professional with strong technical skills, inquisitive thinking, and a passion … protecting enterprise systems from evolving cyber threats. The Role The Cyber Security Operations Specialist will use advanced tools and threat intelligence to ensure effective incident detection and response across client environments. Working closely with security analysts and wider teams, the role combines detection engineering, monitoring, incident response ...

Senior Security and Cyber Operations Manager

Hiring Organisation
McCabe & Barton
Location
City of London, London, United Kingdom
Employment Type
Permanent
Financial Services organisation is looking for a Senior Security and Cyber Operations Manager to take ownership of its security operations, cyber defence, monitoring and incident response capabilities. This is a senior, hands-on role within the CISO function, responsible for strengthening the organisations cyber defence capability and ensuring … very flexible working. You will work closely with Technology, Cloud, Data, Architecture, Risk and external security partners, with responsibility for security tooling, detection coverage, incident response, operational cyber risk and service performance. Key Responsibilities Own and continually improve the organisations security operations and cyber defence capability Lead security ...

Cyber Incident Response

Hiring Organisation
LT Harper Recruitment Group
Location
England, United Kingdom
Cyber Response/Incident Response, 3 x roles (DFIR, Recovery and Remediation, Security Operations Consulting) Salary: £65 - £85k base – Excellent benefits Location: London or Manchester Working pattern: hybrid, around 60% of the week with clients or in the office, 40% elsewhere, including from home + on call … eligibility and willingness to obtain it. I’m supporting a growing global consultancy that is looking to hire three people into its cyber response practice, one of a small number of UK Tier 1 incident response providers. The roles DFIR. You will deliver digital forensics and incident ...

SOC Shift Lead

Hiring Organisation
Anson McCade
Location
City of London, London, United Kingdom
security operation in Central London. This is not a traditional SOC Analyst position. You’ll be the senior technical escalation point on shift , leading incident response activity, supporting analysts and taking ownership of complex and high-severity security incidents. What you’ll be doing Lead the response … sources Perform root cause analysis and coordinate containment, eradication and recovery Correlate events across SIEM, EDR and other security tooling to build a clear incident narrative Identify detection gaps and support improvements to rules, thresholds and playbooks Mentor and provide technical guidance to L1 SOC Analysts Produce detailed investigation ...

Cyber Security Consultant

Hiring Organisation
Radius Consultancy
Location
London, United Kingdom
Employment Type
Permanent
Salary
£80000 - £90000/annum
SIEM, NDR, applications, security architecture, IAM, PAM encryption technologies, network security, Zero Trust, secure interconnection patterns and cyber security principles. Experience within Security Operations, Incident Response, Security Assurance, or GRC functions. Experience managing or overseeing MSSP, SOC activities, third party management. Strong understanding of: ISO 27001, SOC2, NIST … Cyber Security Framework, Incident Response methodologies, Cyber Security Governance, GDPR and regulatory compliance Certifications (one or more) CISSP CISM CRISC The Cyber Security Assurance & Incident Response Lead is responsible for strengthening and maintaining Telehouse's cyber security posture through effective security assurance, incident response ...

Graduate SOC Analyst

Hiring Organisation
CyPro
Location
City of London, London, United Kingdom
pigeonholed into one narrow specialism. At CyPro, you’ll have the opportunity to get involved in a wide range of areas including monitoring, incident response, threat intelligence, detection engineering, automation and internal security operations. You’ll play a key role in our Security Operations Centre, delivering … monitoring, detection and response to our growing customer base. You’ll contribute to building out our capabilities, improving tooling and processes, and shaping how we operate as the function matures. As the team grows further, you’ll have the flexibility to focus more deeply on the areas that interest ...

Senior IT Security Analyst / Engineer

Hiring Organisation
Prime Personnel UK
Location
SW1E, Victoria, Greater London, United Kingdom
Employment Type
Permanent
Salary
£75000 - £90000/annum c£85,000
practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions … cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365/Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve ...

Cyber Incident Response Specialist

Hiring Organisation
Adecco
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Contract
Cyber Incident Response Specialist 6-Month Contract - Inside IR35 - Hybrid (Warwick 1 day per week) Our client, a leading energy company is looking for an experienced Cyber Incident Response Specialist to take ownership of cyber security incidents from escalation through to resolution. Working within a dedicated … Incident Response team, you will coordinate containment, remediation and recovery activities, lead incident calls, engage key stakeholders, and ensure incidents are managed effectively through to closure. Key Requirements Experience managing cyber/security incidents end-to-end Strong understanding of cyber threats including phishing, malware and insider ...

SOC Shift Lead

Hiring Organisation
Anson Mccade
Location
City of London, London, United Kingdom
Employment Type
Permanent
join a high-performing cyber security operations team supporting critical, secure infrastructure in a 24/7 environment. This is an opportunity to lead incident response activities, mentor analysts, and play a key role in protecting complex enterprise environments from evolving cyber threats. What You'll Be Doing … Lead the investigation and response to medium and high-severity security incidents. Act as the escalation point for complex cyber security events and threat activity. Conduct root cause analysis and produce detailed incident reports. Coordinate containment, eradication and recovery activities with technical teams. Correlate data across SIEM ...

Legal Counsel

Hiring Organisation
CyberClan
Location
United Kingdom
carefully selected team of experts are capable of solving complex cyber security challenges – keeping data secure and businesses running as usual. CyberClan’s Global Incident Response Teams are available 24/7/365 to leap into action, responding to all cyber-attacks with proven defensive methodology … business operations. Role Overview: This role supports the CERT/Sales team with reviewing insurance policies, assisting with claims assessments, and contributing to breach response efforts. Ideal for someone with early in house or private practice experience who’s ready to grow into a broader commercial legal role. This ...

SOC Manager

Hiring Organisation
NRGTech Talent Solutions Ltd
Location
Nationwide, United Kingdom
Employment Type
Contract
Contract Rate
£750 - £850/day Prestige opportunity
Define and lead the delivery of the Cyber Security Operations Centre (CSOC) to detect real-time cyber security incidents/data breaches and manage response and remediation activities, including the management of senior stakeholders and external agencies. Ensure adequate controls, practices and capabilities are in place to identify vulnerabilities … define the process for remediation or mitigation to ensure cyber readiness and resilience against attack. Providing strategic level advice to senior management regarding incident response, monitoring, logging and analysis of all relevant systems and processes. Leading the development, communication and continuous improvement of the cyber incident response ...

Cyber Security Engineer

Hiring Organisation
Foresters Financial
Location
Bromley, London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
environment and you will have on-going opportunities to develop your technical skills and grow within cyber security What you will do: Security Monitoring & Incident Response Actively monitor alerts and telemetry across endpoints, identities, email, and cloud services using Rapid7 SIEM, Microsoft Defender, and Sophos AV. Investigate suspected … malware infections, phishing campaigns, identity compromise, and unauthorised access attempts. Perform triage, root cause analysis, containment, and remediation of security incidents. Lead or support incident response activities in line with internal policies and procedures. Escalate significant incidents appropriately and provide clear, timely updates to stakeholders. Threat Detection & Prevention ...

Cyber Security Analyst

Hiring Organisation
Holt Executive
Location
London, United Kingdom
Employment Type
Permanent
team. This is an excellent opportunity to join a fast-paced cybersecurity environment, helping to protect critical infrastructure and enterprise systems through proactive monitoring, incident response, and threat analysis. Working as part of a 24/7 operational security function, you will play a key role in identifying … monitoring tools, network infrastructure, and endpoint technologies. Investigate and triage security alerts to identify malicious activity and determine attack methods and techniques. Follow established incident response and escalation procedures to contain and mitigate security risks. Ensure all incidents are accurately documented, including indicators of compromise, evidence, and investigation ...

Security Consultant

Hiring Organisation
Hackajob Ltd
Location
South West London, London, United Kingdom
Employment Type
Permanent, Work From Home
define pragmatic remediation roadmaps aligned to business priorities. Lead and support security architecture reviews across cloud, applications, infrastructure, IAM, data protection and detection/response domains. Provide expert consulting to customers on security strategy, risk reduction, control design, and security operating model improvements. Challenge weak security assumptions with confidence … guardrails. Partner with engineering, platform, DevOps and operations teams to embed security into delivery pipelines and infrastructure as code practices. Support threat detection, incident response readiness, use-case tuning, and post-incident improvement activities. Contribute to security standards, policies, patterns, reusable accelerators, and client-facing deliverables including ...

SOC Shift Lead

Hiring Organisation
Anson Mccade
Location
South West London, London, United Kingdom
Employment Type
Permanent
Salary
£85,000
incidents while leading, mentoring and developing SOC Analysts on shift. Youll act as a key escalation point for complex and high-severity incidents, supporting incident containment, remediation and recovery while providing leadership across the SOC. What youll be doing Leading the SOC team during your assigned shift and handling … escalations Investigating and responding to medium and high-severity security incidents Supporting incident containment, remediation and recovery Mentoring, teaching and upskilling junior SOC Analysts Supporting threat hunting, detection improvement and incident response activities What were looking for 6+ years experience across SOC, Incident Response ...