1 to 25 of 470 Incident Response Jobs in the UK

Senior Security Engineer - Detection & Response - EU/UK

Hiring Organisation
Jobleads-UK
Location
United Kingdom
Senior Security Engineer – Detection & Response – EU/UK Remote, UK We are seeking a UK-based Senior Security Engineer to join our Security Operations and Response Team as a senior individual contributor. In this role, you will investigate and respond to security incidents across Marqeta’s environment, proactively … monitor for cyber threats, and serve as incident commander during security events of varying severity. You will contribute to the development and improvement of response methodologies aligned with the NIST Incident Response Lifecycle and help maintain cybersecurity incident response documentation. This position requires strong ...

Incident Response Analyst

Hiring Organisation
Morson Edge
Location
Glasgow, Lanarkshire, Scotland, United Kingdom
Employment Type
Contract, Work From Home
Incident Response Analyst Scottish Power HQ, Glasgow Flexible & Hybrid working pattern Negotiable rate, Inside IR35, PAYE and UMB options available Help us create a better future, quicker SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations … deliver a cyber resilient business and the Incident Response Analyst is essential in achieving our goals. This role will be integrated into an active and ambitious global cyber security function, contributing to SPEN's cyber security purpose of delivering cyber resilient OT and IT, to enable a safe ...

DFIR Managing Consultant

Hiring Organisation
Jobleads-UK
Location
United Kingdom
Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Role Purpose: To manage and service NCC Group clients within the Incident Response space. The Managing Consultant plays a critical role within the DFIR team of experienced consultants, delivering high‐quality incident response and proactive services to clients. The role involves leading and contributing to detailed technical analysis, managing incident response activities, and ensuring effective communication and coordination throughout an engagement. With a strong focus on technically supporting clients during live incidents, the Managing Consultant is also expected to contribute ...

DFIR Managing Consultant

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Role Purpose: To manage and service NCC Group clients within the Incident Response space. The Managing Consultant plays a critical role within the DFIR team of experienced consultants, delivering high‐quality incident response and proactive services to clients. The role involves leading and contributing to detailed technical analysis, managing incident response activities, and ensuring effective communication and coordination throughout an engagement. With a strong focus on technically supporting clients during live incidents, the Managing Consultant is also expected to contribute ...

Cyber Security Consultant (Cyber Incident Response)

Hiring Organisation
Morson Edge
Location
City of London, Clerkenwell, Greater London, United Kingdom
Employment Type
Contract
Cyber Security Consultant (Cyber Incident Response Manager) - Inside IR35 - Remote with occasional travel to London or Gloucester - 3 Months initial contract with potential to extend. We're supporting a major, ZERO CARBON energy organisation at the forefront of building a secure and resilient energy future in the appointment … Cyber Incident Response Manager. This is a high-impact role focused on evolving and optimising an already established cyber incident management capability. You'll take ownership of the strategy, maturity, and continuous improvement of the organisation's incident response and crisis management function-ensuring ...

Cyber Incident Response Manager

Hiring Organisation
Ashdown Group
Location
City of London, London, United Kingdom
Employment Type
Permanent, Work From Home
Incident Response Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £110,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an Incident Response Manager within its cyber threat … point once a month for weekends) - Deliver on information security projects - Ensuring services provided meet the business requirements To be considered suitable for this Incident Response Manager role you will need the following skills and experience: - Experience in a technical cyber/incident response role - Previous ...

Cyber Incident Response Manager

Hiring Organisation
TRIA
Location
Sheffield, England, United Kingdom
Cyber Incident Response Analyst – Contract Location: Sheffield (2 days onsite) Rate: £550 p/d Duration: 6 Months - July 2026 – January 2027 A large enterprise organisation is looking for a Cyber Incident Response Analyst to support their Cyber Defence team on a contract basis. This … coordination-focused incident response role, managing cyber incidents through the response lifecycle rather than deep technical remediation. Experience Required Previous experience within Incident Response/Security Operations Strong understanding of the NIST incident response lifecycle Familiarity with MITRE ATT&CK and cyber kill ...

Cyber Security Incident Manager

Hiring Organisation
Ashdown Group
Location
East London, London, United Kingdom
Employment Type
Permanent, Work From Home
Security Incident Response Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £110,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an Incident Response Manager within its cyber … point once a month for weekends) - Deliver on information security projects - Ensuring services provided meet the business requirements To be considered suitable for this Incident Response Manager role you will need the following skills and experience: - Experience in a technical cyber/incident response role - Previous ...

Cyber Security Incident Manager

Hiring Organisation
Ashdown Group
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£100,000 - £120,000 per annum
Security Incident Response Manager (Cyber Threat) - Global financial services company - Full time permanent role - Salary up to £110,000 plus bonus. Hybrid working (twice a week in the London office) A large global financial services firm is looking for an Incident Response Manager within its cyber … point once a month for weekends) - Deliver on information security projects - Ensuring services provided meet the business requirements To be considered suitable for this Incident Response Manager role you will need the following skills and experience: - Experience in a technical cyber/incident response role - Previous ...

Senior Cyber Security Lead

Hiring Organisation
TRIA
Location
London Area, United Kingdom
capable of leading cyber incidents operationally, technically and commercially from end-to-end. You will act as a senior technical subject matter expert across incident response, detection engineering, cloud security and vulnerability management, while also providing calm, structured leadership during high-pressure situations. The environment is heavily Microsoft … principles Detection engineering and automation Threat and vulnerability management You will work closely with global technology and cyber teams to continuously improve monitoring, detection, response and remediation capabilities across hybrid cloud and on-premise environments. Key Responsibilities Incident Response & Major Incident Management Lead ...

Senior CIRT / Threat Intel Analyst

Hiring Organisation
S&P Global
Location
Greater London, United Kingdom
Employment Type
Full Time
global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. About the Role: Grade Level (for internal use): 11 Cyber Incident Response Analyst The Role As a Cyber Incident Response Analyst, you will be part of the Cyber Defence team that develops … decisively respond to security incidents, enrich investigations with timely intelligence, and help drive proactive defences. While based in the UK, you will support response and intelligence needs globally. Candidates should have a genuine interest in cyber security and a strong grasp of attacker tactics, techniques, and procedures (TTPs). ...

Senior Cloud Security Engineer

Hiring Organisation
Jobleads-UK
Location
Metropolitan Borough of Solihull, England, United Kingdom
play a critical role in strengthening and maturing Reapit’s cloud security posture. Your work will span hands on security engineering, deep incident response, proactive threat detection, and collaboration with global teams. Design, implement, and enhance secure Cloud infrastructure, services, and applications in collaboration with DevOps teams. Conduct … detail and high quality documentation. Work in a self managing, proactive manner — anticipating security needs, identifying gaps, and driving improvements without close supervision. Incident Response & Threat Detection Respond to SOC alerts. Working with our outsourced SOC, Lead and participate in global incident response activities, including investigation ...

IT Security Analyst – Incident Response & Vulnerability Management

Hiring Organisation
Operations Resources
Location
Cardiff, South Glamorgan, Wales, United Kingdom
Employment Type
Full-Time
Salary
Salary negotiable
Title Level 3 Security Analyst – Incident Response & Vulnerability Management Department Service Delivery/Security Reporting To Security Lead/Service Delivery Manager Operates under the direction of the Incident Manager during security incidents Location UK (Hybrid) Office in Cardiff 1-2 days per week, regular client site … travel. Working Pattern Monday to Friday with participation in the on-call Security and Major Incident rota as required Role Purpose The Level 3 Security Analyst is responsible for the technical investigation, containment, remediation, and resolution of IT security incidents and vulnerabilities across a complex, multi-site customer estate ...

Senior Consultant | Cybersecurity - Incident Response | Forensic & Litigation Consulting

Hiring Organisation
Jobleads-UK
Location
Greater London, England, United Kingdom
Senior Consultant | Cybersecurity - Incident Response | Forensic & Litigation Consulting FTI Consulting is the leading global expert firm for organizations facing crisis and transformation. We work with many of the world’s top multinational corporations, law firms, banks and private equity firms on their most important issues to deliver impact … order to assimilate client needs and design appropriate technical solutions. Lead assessment of current threat identification techniques and development of new methodologies and frameworks. Incident analysis, combining sound analytical skills with advanced knowledge of cybersecurity, digital forensics and incident response. Assess client cybersecurity postures against industry‐standard best ...

Lead Incident Response Consultant, CNI

Hiring Organisation
Intaso
Location
United Kingdom
Lead Incident Response Consultant – CNI & Industrial Cyber (Remote) In an era where cyber threats have moved from data theft to physical disruption, the stakes for Operational Technology (OT) have never been higher. We are partnering with a well-regarded UK Cyber Security consultancy evolving their OT incident response practice. This is a rare opportunity to own and develop a specialist OT Incident Response service line, bringing to market a proprietary vision of best practice that protects the utilities, transport, and energy systems the country relies on. The Role You will ...

Cyber Security Specialist

Hiring Organisation
LHH
Location
Wokingham, England, United Kingdom
energy operations within a Critical National Infrastructure (CNI) environment. This role is responsible for real-time security monitoring, alert triage, investigation, and early-stage incident response. You will work with industry-standard security monitoring and incident/event management platforms to identify suspicious activity, validate alerts, and escalate … helping tune detections, and strengthening operational procedures and documentation. Key Responsibilities Monitoring and Triage Monitor security events and alerts using industry-standard SIEM and incident/event management platforms (e.g., Elastic, Microsoft Sentinel, Splunk). Perform rapid triage to determine alert validity, severity, scope, and potential business or operational ...

Network Lead

Hiring Organisation
Hays Specialist Recruitment Limited
Location
West Drayton, Middlesex, England, United Kingdom
Employment Type
Contractor
Contract Rate
Salary negotiable
Facilitate both inbound and outbound connectivity while managing risk and maintaining service integrity. Performance Management:Define and monitor service levels (availability, latency, packet loss, incident response and resolution times). Proactively address issues impacting service quality. Security & Compliance:Oversee next generation firewall deployments, SSE/cloud security services … enforce policy-based access controls. Ensure compliance with all regulatory and business requirements. Incident & Problem Management:Lead the network incident response, prioritization, and escalation processes. Work closely with engineering and service desk teams on rapid restoration and continuous improvement. Vendor & Stakeholder Management:Manage relationships with third-party ...

Lead Network Engineer

Hiring Organisation
Hays
Location
Waterside, Lancashire, UK
Facilitate both inbound and outbound connectivity while managing risk and maintaining service integrity. Performance Management: Define and monitor service levels (availability, latency, packet loss, incident response and resolution times). Proactively address issues impacting service quality. Security & Compliance: Oversee next generation firewall deployments, SSE/cloud security services … enforce policy-based access controls. Ensure compliance with all regulatory and business requirements . Incident & Problem Management: Lead the network incident response, prioritization, and escalation processes. Work closely with engineering and service desk teams on rapid restoration and continuous improvement. Vendor & Stakeholder Management: Manage relationships with third ...

Lead Network Engineer

Hiring Organisation
Hays
Location
Waterside, England, United Kingdom
Facilitate both inbound and outbound connectivity while managing risk and maintaining service integrity. Performance Management: Define and monitor service levels (availability, latency, packet loss, incident response and resolution times). Proactively address issues impacting service quality. Security & Compliance: Oversee next generation firewall deployments, SSE/cloud security services … enforce policy-based access controls. Ensure compliance with all regulatory and business requirements . Incident & Problem Management: Lead the network incident response, prioritization, and escalation processes. Work closely with engineering and service desk teams on rapid restoration and continuous improvement. Vendor & Stakeholder Management: Manage relationships with third ...

Cyber Security Engineer

Hiring Organisation
Required IT
Location
Bromley, Kent, England, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
supportive and collaborative environment with ongoing opportunities to develop your technical expertise and progress your career within cyber security. Key Responsibilities Security Monitoring & Incident Response Monitor alerts and telemetry across endpoints, identities, email, and cloud services using Rapid7 SIEM, Microsoft Defender, and Sophos Antivirus. Investigate cyber security incidents … including malware infections, phishing attacks, identity compromise, and unauthorised access attempts. Conduct incident triage, root cause analysis, containment, remediation, and recovery activities. Lead or support incident response activities in line with internal procedures and security standards. Escalate major incidents appropriately and provide timely updates to stakeholders. Threat ...

Executive Principal Consultant

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
Department: Cyber Services and Capabilities Employment Type: Full Time Location: NLD Rijswijk To manage and service NCC Group clients within the Digital Forensics and Incident Response space. The Principal DFIR Consultant plays a pivotal role within the team of seasoned analysts, actively participating in the analysis and response … collaboration, clear communication, and efficient workflow throughout technical engagements. Responding to emergency incidents, including mitigation and remediation activities. Maintaining composure and effectiveness in client incident‐management scenarios. Providing clients with high‐quality technical investigations. Collaborating in the identification, resolution, and documentation of security incidents. Conducting intelligence‐driven investigative analysis. ...

Solicitor

Hiring Organisation
CyberClan
Location
United Kingdom
carefully selected team of experts are capable of solving complex cyber security challenges – keeping data secure and businesses running as usual. CyberClan’s Global Incident Response Teams are available 24/7/365 to leap into action, responding to all cyber-attacks with proven defensive methodology … business operations. Role Overview: This role supports the CERT/Sales team with reviewing insurance policies, assisting with claims assessments, and contributing to breach response efforts. Ideal for someone with early in house or private practice experience who’s ready to grow into a broader commercial legal role. This ...

Senior Cyber Security Analyst

Hiring Organisation
Anson McCade
Location
London Area, United Kingdom
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

SOC Technical Lead

Hiring Organisation
Experis
Location
Nationwide, United Kingdom
Employment Type
Permanent
Salary
£60000 - £70000/annum
Services (MSSP) function, reporting directly to the Head of SOC Operations. You will act as the senior technical authority, driving excellence in threat detection, incident response, and security operations across a diverse, multi-client portfolio. While you will lead and mentor a team, this is not a purely … schedules, handovers, and on-call rotations Act as the primary escalation point for security incidents and analyst queries Ensure high-quality triage, investigation, and response aligned to SOC processes Drive team development through training, coaching, and technical mentoring Ensure accurate and timely case management (HALO) and delivery against SLAs ...

Cyber Security Engineer

Hiring Organisation
Foresters Financial
Location
Kent, England, United Kingdom
Employment Type
Full-Time
Salary
£60,000 per annum
environment and you will have on-going opportunities to develop your technical skills and grow within cyber security What you will do: Security Monitoring & Incident Response Actively monitor alerts and telemetry across endpoints, identities, email, and cloud services using Rapid7 SIEM, Microsoft Defender, and Sophos AV. Investigate suspected … malware infections, phishing campaigns, identity compromise, and unauthorised access attempts. Perform triage, root cause analysis, containment, and remediation of security incidents. Lead or support incident response activities in line with internal policies and procedures. Escalate significant incidents appropriately and provide clear, timely updates to stakeholders. Threat Detection & Prevention ...