1 to 25 of 1,005 Incident Response Jobs in the UK

Cyber Response & Recovery Manager - German Speaker

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Cyber Response & Recovery Manager - German Speaker Cyber Response & Recovery Manager (Reactive DFIR) About the role This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team … within our Cyber Advisory practice. Your specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands‐on incident response role and an opportunity to join a high ...

Senior Incident Response Consultant, Rapid Response

Hiring Organisation
Jobleads-UK
Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

Director, Digital Forensics & Incident Response (Global)

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group’s global Digital Forensics … Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. ...

Associate/Senior Associate - Data & Cyber

Hiring Organisation
RPC
Location
Greater London, United Kingdom
Employment Type
Full Time
ROLE OVERVIEW The team The Data & Cyber team advises a wide range of clients across a variety of industry sectors on cyber incidents, regulatory response, technology and data-related claims, and cyber/technology insurance coverage. We are recognised for combining deep cyber incident response capability with … understanding of the insurance market, enabling us to support clients across the lifecycle of a cyber event and its downstream exposures: from immediate breach response and crisis management, through policy notification and coverage strategy, to regulatory engagement and dispute resolution. The role Based in London, the Associate ...

Incident Response Lead

Hiring Organisation
McGregor Boyall
Location
London, South East, England, United Kingdom
Employment Type
Contractor
Contract Rate
£750 - £850 per day
Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid You will lead and line-manage the London-based cyber security team, delivering cyber operations services, assure the local delivery of globally-prioritised work, and act as Incident Commander and first point of escalation for cyber security in London. … role additionally leads to the Endpoint, Platform and Incident Response capability, owning the global prioritisation of that backlog against enterprise cyber risk. Experience required: A strong, hands-on technical background in operational cyber security spanning endpoint & EDR, identity & Active Directory, Microsoft 365 & Azure, network/ZTNA, and SIEM ...

Cyber Digital Forensics & Incident Response Manager

Hiring Organisation
Capgemini
Location
Cheshire West and Chester, United Kingdom
Employment Type
Full Time
Onsite 2-3 Days Per Week Work Location either Manchester or inverness An excellent opportunity has arisen within our Team for a Digital Forensics & Incident Response (DFIR) Manager. DFIR (Digital Forensics and Incident Response) is a specialist cyber security capability which is responsible for delivering rapid … high‐impact incident response and investigation during significant cyber events, such as Malware or Ransomware attacks or Cyber security breaches. The Digital Forensics and Incident Response Manager is a leadership position within Capgemini’s Cyber Defence Centre’s (CDC’s) team, this role will oversee ...

Incident Response Specialist

Hiring Organisation
Pontoon
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Contract
Contract Rate
£700/day
take your cyber security expertise to the next level? Our client, a leader in the energy sector, is on the lookout for an Incident Response Specialist to join their dynamic cyber security team. Role: Incident Response Specialist Duration: 6 Months (ext. options) Location: Warwick (Hybrid … mindset, promoting shared responsibility among Security Operations teams. Your contributions will be vital in defending against an ever-evolving threat landscape. Key Responsibilities Include: Incident Response: Triage and manage high-priority incidents while ensuring appropriate responses are executed. Produce clear incident summaries quickly and adapt your communication ...

Cyber Incident Response Manager

Hiring Organisation
Hays
Location
Liverpool, Merseyside, North West, United Kingdom
Employment Type
Contract
Contract Rate
£750.0 - £800 per day
IR35 Status: Outside IR35 Contract Length: 6 months initially Location: Hybrid - Liverpool Overview I'm supporting an organisation seeking an experienced Incident Response Manager to lead and mature its Incident Response capability across a complex enterprise environment. Responsibilities Own and manage cyber incidents from detection through … resolution. Review, enhance, and develop Incident Response frameworks, runbooks, and playbooks. Ensure alerts from SIEM, EDR, CTI, and SOC services are effectively integrated into Incident Response processes. Lead tabletop exercises and testing activities. Work closely with SOC, Threat Intelligence, Technology, and Business teams. Drive continual improvement ...

Embedded Cyber Detection and Response Deputy Team Lead

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Cyber Detection and Response Deputy Team Lead serves as the operational second-in-command of the Cyber Detection and Response Team (DART), bridging the gap between hands-on cyber operations and team leadership. The role supports the Team Lead in the ongoing development, maturation, and delivery … client's detection and response capabilities, while providing technical leadership and operational oversight across day-to-day security operations. This position remains actively involved in threat detection, incident response, threat hunting, and detection engineering activities while also assuming supervisory and coordination responsibilities. The Deputy Team Lead acts ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
United Kingdom
Security Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents as Incident Commander, and lead digital forensic investigations in support of Employee Relations, Legal, Compliance, or Information Security cases. Although you will be focused on security incident response, you will also have the opportunity to create and maintain runbooks, automated workflows, and assist in process refinement and implementation. You will collaborate with a diverse team of engineers and key stakeholders on security initiatives across the company. Above all, your focus is bringing Security expertise ...

Cyber Incident Response

Hiring Organisation
LT Harper Recruitment Group
Location
England, United Kingdom
Cyber Response/Incident Response, 3 x roles (DFIR, Recovery and Remediation, Security Operations Consulting) Salary: £55 - £85k base – Excellent benefits Location: London or Manchester Working pattern: hybrid, around 60% of the week with clients or in the office, 40% elsewhere, including from home + on call … eligibility and willingness to obtain it. I’m supporting a growing global consultancy that is looking to hire three people into its cyber response practice, one of a small number of UK Tier 1 incident response providers. The roles DFIR. You will deliver digital forensics and incident ...

Senior Cyber Incident Manager (SCIM)

Hiring Organisation
Jobleads-UK
Location
Welwyn Garden City, England, United Kingdom
Senior Cyber Incident Manager at Tesco, you will command the response to high‐severity cyber incidents, safeguarding a complex retail ecosystem that serves millions of customers globally. Operating at the forefront of cyber defence, you will lead crisis response efforts, ensuring decisive action, minimal disruption, and protection … customer trust. This role is pivotal in shaping Tesco's incident management maturity, driving strategic readiness and resilience across the organisation. You will combine operational excellence with forward‐looking innovation to ensure Tesco remains a leader in cyber incident response. Responsibilities Command Major Incident Response: Lead ...

Head of Cyber Defence

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
leader responsible for developing and executing enterprise-wide cyber defence strategies to protect critical business systems, data, and infrastructure. Leads security operations, threat detection, incident response, and cyber resilience initiatives while ensuring alignment with organisational risk management objectives. Key Responsibilities Lead and manage the Cyber Defence function, overseeing … security operations, threat intelligence, vulnerability management, and incident response capabilities. Develop and implement cyber defence strategies, policies, and procedures to protect against evolving cyber threats. Direct Security Operations Centre (SOC) activities, ensuring effective monitoring, detection, investigation, and response to security incidents. Oversee threat intelligence programmes, identifying emerging ...

Senior IT Security Analyst

Hiring Organisation
Prime Personnel
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£75,000 - £90,000 per annum
practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions … cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365/Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve ...

Senior IT Security Analyst / Engineer

Hiring Organisation
Prime Personnel UK
Location
SW1E, Victoria, Greater London, United Kingdom
Employment Type
Permanent
Salary
£75000 - £90000/annum c£85,000
practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions … cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365/Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve ...

Incident Response Engineer Information security London

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
getting started. The role This role exists to ensure security incidents are rare, contained, and unsurprising. You will own the technical direction of security incident response and response readiness across the company. When a serious incident occurs, you lead from the front — investigating, containing, and driving … Security Operations, IT, and Engineering to reduce real risk, not theoretical risk. What you’ll be responsible for Leading the end-to-end technical response to high-severity security incidents Owning investigation, containment, eradication, and recovery activities Acting as the senior technical authority during live incidents Providing clear, decisive ...

Senior Consultant | Cybersecurity - Incident Response

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Senior Consultant | Cybersecurity - Incident ResponseSkip to main contentWe use cookies to provide website functionality, to analyze our traffic, to personalize content and to enable social media functionality. For further information, please see our Cookie Policy. To enhance your experience, we use an AI assistant, Olivia, to help you explore … roles and learn more about FTI Consulting. For access to Olivia, please accept or decline.#Senior Consultant | Cybersecurity - Incident Response page is loaded## Senior Consultant | Cybersecurity - Incident ResponseApplyremote type: Hybridlocations: London, United Kingdomtime type: Full timeposted on: Posted Todayjob requisition id: JR2520U-TEE**Who We Are**FTI Consulting ...

Cyber Incident Response Team Lead (CSIRT)

Hiring Organisation
Robert Walters
Location
Merseyside, England, United Kingdom
Employment Type
Contractor
Contract Rate
£500 - £600 per day
Blends hands-on incident command and digital forensics with programmatic capability building. Establishes the CSIRT operating model, creates scenario playbooks (ransomware, exfiltration) from scratch, and leads technical containment/recovery during active security events. About the Role My client is a well established business, looking for a hands … CSIRT Lead to establish and run the cyber incident response capability across a complex, multi-site industrial and corporate estate. The role blends hands-on incident command and digital forensics coordination with the programmatic build-out of incident playbooks and operational runbooks from scratch. Key Responsibilities ...

Head of Information Security

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
growth and innovation. You'll define and lead our security strategy, establish governance and compliance frameworks, strengthen cloud and third-party security, and drive incident response and resilience planning across the organisation. Responsibilities As our security leader, you will bring a hands-on, builder mindset to establish … DPAs, transfer mechanisms, and data classification standards across the business. Audit Readiness: Keep the organization continuously prepared for external compliance audits and regulatory assessments. Incident Response & Business Resilience Incident Command: Own the incident response plan, acting as incident commander during crises and managing executive ...

Senior Incident Response Lead — Rapid Response (Ransomware)

Hiring Organisation
Jobleads-UK
Location
Oxford, England, United Kingdom
Sophos is seeking an experienced Senior Incident Response Consultant to join our Incident Response (IR) team. You will lead incident response engagements for customers worldwide, guiding a team of consultants, conducting rapid responses, and delivering executive updates. You will have 5+ years ...

Head of Security Operations

Hiring Organisation
Jobleads-UK
Location
Wolverhampton, England, United Kingdom
will be accountable for the effective operation, continuous improvement and resilience of the Bank's security operations capability, covering Security Operations Centre monitoring and response, Identity and Access Management services, security analysis, operational security controls and supplier-delivered security services. The Head of Security Operations is a senior leadership … India offices, supported where appropriate by third-party managed security service providers. The team provides 24x7 or extended-hours security monitoring and response, identity and access management operations, vulnerability and threat analysis, security tooling administration, control assurance support, reporting, and operational support. Your responsibilities will include... Security Operations Leadership ...

IT Security & Compliance Lead

Hiring Organisation
Jobleads-UK
Location
City of Edinburgh, Scotland, United Kingdom
company grows. You'll build our IT security function from the ground up — covering device management, identity and access, infrastructure controls, and incident response — while also owning the compliance and AI governance work that keeps enterprise customers confident in how we operate. It's a hands‐on, build … tools like Okta. Own infrastructure and cloud security controls across our environment (e.g. AWS), working closely with Engineering to keep systems hardened. Security Operations & Incident Response Lead security incident response — full lifecycle investigations, coordinating with internal teams and external partners (e.g. SOCaaS providers), and running post ...

SPLUNK SOAR Engineer - FTC 12m £110k UK REMOTE

Hiring Organisation
Circle Group
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Temporary
optimising security automation across a large-scale enterprise environment. This is a hands-on engineering position focused on delivering scalable Security Orchestration, Automation and Response (SOAR) capabilities using the Splunk Security platform . Working alongside Incident Response and Threat Management teams, you will develop advanced automation, improve … detection and response processes, and build new use cases that strengthen cyber resilience. This is a 12-month fixed term contract with a strong likelihood of renewal , offering a salary of up to £110,000 , an excellent benefits package and fully expensed travel and accommodation for occasional business travel ...

Product Engineers -Cloud (Multiple Levels) Hybrid TLNT1 NI

Hiring Organisation
Allstate Northern Ireland
Location
Belfast, UK
implementation through deployment and production support and are accountable for the reliability, adoption, and effectiveness of cloud security controls, including their role in incident detection, response, and recovery. Key Responsibilities Design, build, and operate cloud-native security controls as software products across cloud infrastructure, data platforms, and application … implementation through deployment and production support and are accountable for the reliability, adoption, and effectiveness of cloud security controls, including their role in incident detection, response, and recovery. Key Responsibilities Design, build, and operate cloud-native security controls as software products across cloud infrastructure, data platforms, and application ...

Principal Security Engineer

Hiring Organisation
Jobleads-UK
Location
St Albans, England, United Kingdom
Operate as a strategic partner to the IT Ops Specialist. Jointly shape how security and IT operations integrate shared tooling decisions, aligned processes, unified incident response, single view of risk. Stakeholder Influence: Present security posture, risk appetite and investment cases to senior leadership. Translate technical risk into business … MITRE ATT&CK. Continuously reduce false positives and expand coverage. Automation: Engineer automation for security operations at scale — scripting (Python, Bash, PowerShell) for response orchestration, access reviews, compliance checks, vulnerability reporting, threat intel enrichment. Integration & Evaluation: Ensure all security tooling integrates with existing infrastructure and identity platforms. Lead POCs ...