1 to 25 of 1,061 Incident Response Jobs in the UK

Cyber Response & Recovery Manager - German Speaker

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Cyber Response & Recovery Manager - German Speaker Cyber Response & Recovery Manager (Reactive DFIR) About the role This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team … within our Cyber Advisory practice. Your specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands‐on incident response role and an opportunity to join a high ...

Cyber Response & Recovery Manager (Reactive DFIR) - German Speaking

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will be working in the Cyber Response Services (CRS) Team within our Cyber Advisory practice. Your specific … focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a case manager on medium to large cases. This is a hands-on incident response role and an opportunity to join a high performing team that works with a wide ...

Cybersecurity Incident Response Lead

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Overview Executive level position reporting to the Director of Cyber Threat Management & Incident Response, this is a hands‐on senior security position working within the Information Security group and with the internal IT department. This position’s core focus is to ensure consistent, measurable end‐to‐end triage … successful candidate will work to assess, develop, and deploy detection capabilities and processes ensuring enterprise systems and data are protected, serving as the Incident Response Lead for European and Pacific regions of the organisation. We are looking for candidates who have a passion for cyber security, threat detection ...

Cyber Response & Recovery Assistant Manager (Reactive DFIR)

Hiring Organisation
KPMG UK
Location
London Area, United Kingdom
Cyber Response & Recovery Assistant Manager (Reactive DFIR) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Assistant Manager role will be working in the Cyber Response Services (CRS) Team within our Advisory practice. Your … specific focus will be in the domain of reactive digital forensics and incident response (DFIR) acting as a junior case manager on smaller cases, or part of a team (reporting to a case manager or senior case manager) on larger cases. This is a hands-on role ...

Senior Incident Response Consultant, Rapid Response

Hiring Organisation
Jobleads-UK
Location
Oxford, England, United Kingdom
human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response. Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection … response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats. Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security ...

Cyber Defense Incident Responder

Hiring Organisation
EY (Ernst & Young)
Location
London, United Kingdom
Salary
£ 70 K
detects, responds, and mitigates cybersecurity risk, protecting EY and client data, and our information management systems. The opportunityThe Cyber & Investigative Services (CIS) Senior Cyber Incident Response Coordinator will exercise exemplary incident management techniques to coordinate incident response to cybersecurity events or incidents stemming from suspected … threats on a global scale. Candidates for the role must have an exceptional comprehension of cybersecurity incident response plans and coordination of activities, establish and foster relationships on a global scale, and have superb verbal and written communication skills. Additionally, candidates must have a sense of diplomacy, ability ...

Cyber Response & Recovery Manager (Remediation)

Hiring Organisation
KPMG UK
Location
City of London, London, United Kingdom
Cyber Response & Recovery Manager (Remediation) This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance. About the role The Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG’s Cyber Advisory practice. Your specific focus will … compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience. This ...

Director, Digital Forensics & Incident Response (Global)

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group’s global Digital Forensics … Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
London, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
Incident Response Consultant - Mid to Principal - UK Wide UK Remote | Up to £95,000 + benefits | SC Eligible Pref A specialist opportunity for experienced Incident Response professionals looking to work across a varied mix of proactive and reactive Digital Forensics & Incident Response (DFIR) engagements. … This is a hands-on consulting role where you will support organisations through cyber incidents while also helping them improve their readiness, resilience and response capability before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment ...

Incident Response Consultant - Mid to Principal - UK Wide

Hiring Organisation
Circle Group
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£95,000
Incident Response Consultant - Mid to Principal - UK Wide UK Remote | Up to £95,000 + benefits | SC Eligible Pref A specialist opportunity for experienced Incident Response professionals looking to work across a varied mix of proactive and reactive Digital Forensics & Incident Response (DFIR) engagements. … This is a hands-on consulting role where you will support organisations through cyber incidents while also helping them improve their readiness, resilience and response capability before incidents occur. Working remotely across the UK, you will join a team delivering high-quality DFIR services including incident investigation, containment ...

Incident Response Lead

Hiring Organisation
McGregor Boyall
Location
London, South East, England, United Kingdom
Employment Type
Contractor
Contract Rate
£750 - £850 per day
Cyber Operations & Incident Response Lead, Cloud, Security, Hybrid You will lead and line-manage the London-based cyber security team, delivering cyber operations services, assure the local delivery of globally-prioritised work, and act as Incident Commander and first point of escalation for cyber security in London. … role additionally leads to the Endpoint, Platform and Incident Response capability, owning the global prioritisation of that backlog against enterprise cyber risk. Experience required: A strong, hands-on technical background in operational cyber security spanning endpoint & EDR, identity & Active Directory, Microsoft 365 & Azure, network/ZTNA, and SIEM ...

Incident Response Specialist

Hiring Organisation
Pontoon
Location
Warwick, Warwickshire, United Kingdom
Employment Type
Contract
Contract Rate
£700/day
take your cyber security expertise to the next level? Our client, a leader in the energy sector, is on the lookout for an Incident Response Specialist to join their dynamic cyber security team. Role: Incident Response Specialist Duration: 6 Months (ext. options) Location: Warwick (Hybrid … mindset, promoting shared responsibility among Security Operations teams. Your contributions will be vital in defending against an ever-evolving threat landscape. Key Responsibilities Include: Incident Response: Triage and manage high-priority incidents while ensuring appropriate responses are executed. Produce clear incident summaries quickly and adapt your communication ...

Cyber Incident Response Manager

Hiring Organisation
Hays
Location
Liverpool, Merseyside, North West, United Kingdom
Employment Type
Contract
Contract Rate
£750.0 - £800 per day
IR35 Status: Outside IR35 Contract Length: 6 months initially Location: Hybrid - Liverpool Overview I'm supporting an organisation seeking an experienced Incident Response Manager to lead and mature its Incident Response capability across a complex enterprise environment. Responsibilities Own and manage cyber incidents from detection through … resolution. Review, enhance, and develop Incident Response frameworks, runbooks, and playbooks. Ensure alerts from SIEM, EDR, CTI, and SOC services are effectively integrated into Incident Response processes. Lead tabletop exercises and testing activities. Work closely with SOC, Threat Intelligence, Technology, and Business teams. Drive continual improvement ...

Security Incident Management Analyst - Active SC or SC Eligible

Hiring Organisation
eTeam Workforce Limited
Location
Preston, Lancashire, United Kingdom
Employment Type
Contract
Contract Rate
GBP 483 Daily
specialist that provides support to the clients across EMEA, APAC, US and Canada. We have an excellent job opportunity for you. Role Title: Security Incident Management Analyst- Active SC or SC Eligible Location: Inverness or Preston | 5 days onsite Duration: 31/03/2027 Pay Rate … inc. (PAYE through Umbrella) Role Description: About the role you're considering The Security Incident Management Analyst operates within the Operational Integrator (OI) function in a multi-supplier (SIAM) environment, supporting the governance and coordination of security incident management activities across suppliers. The role assists in ensuring security ...

SC Cleared Security Incident Management Analyst (x3 seats)

Hiring Organisation
fortice
Location
Preston, Lancashire, United Kingdom
Employment Type
Contract
Contract Rate
GBP 485 Daily
Role Title: Security Incident Management Analyst (x3 seats) Location: Inverness or Preston | 5 days onsite Duration: 31/03/2027 MUST BE PAYE THROUGH UMBRELLA Role Description: About the role you're considering The Security Incident Management Analyst operates within the Operational Integrator (OI) function … multi-supplier (SIAM) environment, supporting the governance and coordination of security incident management activities across suppliers. The role assists in ensuring security incidents are identified, tracked, escalated, and reported in accordance with client policies and agreed service levels. Working closely with suppliers, service management teams, and security stakeholders ...

Embedded Cyber Detection and Response Deputy Team Lead

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Cyber Detection and Response Deputy Team Lead serves as the operational second-in-command of the Cyber Detection and Response Team (DART), bridging the gap between hands-on cyber operations and team leadership. The role supports the Team Lead in the ongoing development, maturation, and delivery … client's detection and response capabilities, while providing technical leadership and operational oversight across day-to-day security operations. This position remains actively involved in threat detection, incident response, threat hunting, and detection engineering activities while also assuming supervisory and coordination responsibilities. The Deputy Team Lead acts ...

Senior Security Engineer

Hiring Organisation
Jobleads-UK
Location
United Kingdom
Security Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents as Incident Commander, and lead digital forensic investigations in support of Employee Relations, Legal, Compliance, or Information Security cases. Although you will be focused on security incident response, you will also have the opportunity to create and maintain runbooks, automated workflows, and assist in process refinement and implementation. You will collaborate with a diverse team of engineers and key stakeholders on security initiatives across the company. Above all, your focus is bringing Security expertise ...

Cyber Incident Response

Hiring Organisation
LT Harper Recruitment Group
Location
England, United Kingdom
Cyber Response/Incident Response, 3 x roles (DFIR, Recovery and Remediation, Security Operations Consulting) Salary: £55 - £85k base – Excellent benefits Location: London or Manchester Working pattern: hybrid, around 60% of the week with clients or in the office, 40% elsewhere, including from home + on call … eligibility and willingness to obtain it. I’m supporting a growing global consultancy that is looking to hire three people into its cyber response practice, one of a small number of UK Tier 1 incident response providers. The roles DFIR. You will deliver digital forensics and incident ...

Data and Cyber Associate/Senior Associate

Hiring Organisation
Auston Legal Limited
Location
City of London, London, United Kingdom
regarding cyber incidents, regulatory responses, technology and data-related claims, and cyber/technology insurance coverage. They are known for their expertise in cyber incident response and their comprehensive understanding of the insurance market, which allows them to assist clients throughout the entire process of a cyber event … associated risks, including immediate breach response and crisis management, policy notification and coverage strategy, as well as regulatory engagement and dispute resolution. The Role: The London team is seeking to recruit an Associate (1-4PQE) and Senior Associate (4-8PQE) who will support Partners in delivering cyber ...

Senior Cyber Security Analyst

Hiring Organisation
Tria Recruitment
Location
London, United Kingdom
Salary
£ 80 K
individual capable of leading cyber incidents operationally, technically and commercially from end-to-end.You will act as a senior technical subject matter expert across incident response, detection engineering, cloud security and vulnerability management, while also providing calm, structured leadership during high-pressure situations.The environment is heavily Microsoft-focused … secure-by-design principlesDetection engineering and automationThreat and vulnerability managementYou will work closely with global technology and cyber teams to continuously improve monitoring, detection, response and remediation capabilities across hybrid cloud and on-premise environments.Key ResponsibilitiesIncident Response & Major Incident ManagementLead the end-to-end management of cyber ...

Senior Cyber Incident Manager (SCIM)

Hiring Organisation
Jobleads-UK
Location
Welwyn Garden City, England, United Kingdom
Senior Cyber Incident Manager at Tesco, you will command the response to high‐severity cyber incidents, safeguarding a complex retail ecosystem that serves millions of customers globally. Operating at the forefront of cyber defence, you will lead crisis response efforts, ensuring decisive action, minimal disruption, and protection … customer trust. This role is pivotal in shaping Tesco's incident management maturity, driving strategic readiness and resilience across the organisation. You will combine operational excellence with forward‐looking innovation to ensure Tesco remains a leader in cyber incident response. Responsibilities Command Major Incident Response: Lead ...

Information Security Incident Response Analyst

Hiring Organisation
NTT
Location
London, United Kingdom
Salary
£ 80 K
clients and society. Our workplace embraces diversity and inclusion – it’s a place where you can grow, belong and thrive.Job Description SummaryThe Information Security Incident Response Analyst supports clients during security incidents by performing technical investigations, analyzing digital forensic evidence, and assisting with containment and remediation activities. This … indicators of compromise, reconstructing attacker activity, and communicating clear, actionable findings.The analyst works as part of a global DFIR team, handling a variety of incident types across diverse environments. They contribute to process improvements, maintain strong client communication, and continue building advanced DFIR skills through hands‐on investigations ...

Senior IT Security Analyst

Hiring Organisation
Prime Personnel
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£75,000 - £90,000 per annum
practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions … cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365/Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve ...

Senior IT Security Analyst / Engineer

Hiring Organisation
Prime Personnel UK
Location
SW1E, Victoria, Greater London, United Kingdom
Employment Type
Permanent
Salary
£75000 - £90000/annum c£85,000
practical improvements to reduce cyber risk. The role combines analyst and engineering responsibilities across security tools, vulnerability and exposure management, web and email security, incident response, and threat-informed remediation. The role works closely with infrastructure, cloud, application, identity and business teams to identify security issues, prioritise actions … cyber defence posture. Owned or materially contributed to one or more cyber security domains, such as endpoint security, vulnerability management, identity security, network security, incident response or Microsoft 365/Azure security. Used CrowdStrike or equivalent EDR tooling to investigate detections, support incident response and improve ...

Incident Response Engineer Information security London

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
getting started. The role This role exists to ensure security incidents are rare, contained, and unsurprising. You will own the technical direction of security incident response and response readiness across the company. When a serious incident occurs, you lead from the front — investigating, containing, and driving … Security Operations, IT, and Engineering to reduce real risk, not theoretical risk. What you’ll be responsible for Leading the end-to-end technical response to high-severity security incidents Owning investigation, containment, eradication, and recovery activities Acting as the senior technical authority during live incidents Providing clear, decisive ...