1 to 25 of 340 Incident Response Jobs in the UK excluding London

Incident Response Analyst

Hiring Organisation
Morson Edge
Location
Glasgow, Lanarkshire, Scotland, United Kingdom
Employment Type
Contract, Work From Home
Incident Response Analyst Scottish Power HQ, Glasgow Flexible & Hybrid working pattern Negotiable rate, Inside IR35, PAYE and UMB options available Help us create a better future, quicker SP Energy Networks (SPEN) has kicked off an ambitious security transformation programme to transparently reduce risk, achieve compliance with NIS regulations … deliver a cyber resilient business and the Incident Response Analyst is essential in achieving our goals. This role will be integrated into an active and ambitious global cyber security function, contributing to SPEN's cyber security purpose of delivering cyber resilient OT and IT, to enable a safe ...

Senior Incident Response Specialist - Manchester

Hiring Organisation
Circle Recruitment
Location
Manchester, Lancashire, England, United Kingdom
Employment Type
Full-Time
Salary
£50,000 - £85,000 per annum
Senior Incident Response Specialist - Manchester £50-85k DOE Hybrid Manchester (1 day/week with flexibility) Must either hold SC Clearance or be eligible for SC Clearance We are seeking an experienced Incident Response Specialist to deliver high-quality cyber incident response and forensic investigation services across our client's customer and internal environments. In this role, you will lead cyber incident investigations, conduct forensic analysis across endpoint, network, and cloud environments, and work closely with security operations teams to identify, contain, and remediate threats. You will also ...

DFIR Managing Consultant

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Role Purpose: To manage and service NCC Group clients within the Incident Response space. The Managing Consultant plays a critical role within the DFIR team of experienced consultants, delivering high‐quality incident response and proactive services to clients. The role involves leading and contributing to detailed technical analysis, managing incident response activities, and ensuring effective communication and coordination throughout an engagement. With a strong focus on technically supporting clients during live incidents, the Managing Consultant is also expected to contribute ...

Senior Security Consultant - Digital Forensics & Incident Response

Hiring Organisation
Jobleads-UK
Location
Manchester, England, United Kingdom
UBDS group is seeking a highly skilled Senior Digital Forensics and Incident Response (DFIR) Consultant to lead and support complex cyber incident investigations and response activities. The primary focus of this role is the delivery of DFIR services to external clients, ensuring high-quality, timely … professional incident response and forensic capabilities. In addition, the role will support internal cyber security operations and improvement initiatives as required. This role will work closely with Security Operations Centre (SOC) and Infrastructure Operations Centre (IOC) engineers to identify, contain, and remediate cyber threats, while enhancing both client ...

Information Security Incident Manager

Hiring Organisation
Jobleads-UK
Location
Leeds, England, United Kingdom
Information Security Incident Manager Location: Leeds (Hybrid – 2 days per week on site). Contract: Permanent, Full Time. Salary: £70,000 - £80,000 (DOE). Job Overview The Information Security Incident Manager will lead the organisation’s response to cyber security incidents, strengthening overall resilience. The role … commands major cyber incidents, coordinating technical and business teams, ensuring effective governance, preparedness, and regulatory compliance. Responsibilities Lead the organisation’s cyber incident response, coordinating technical, operational, and business activities from containment to recovery. Act as Cyber Incident Commander for major incidents, setting priorities, directing response ...

Senior Cloud Security Engineer

Hiring Organisation
Jobleads-UK
Location
Metropolitan Borough of Solihull, England, United Kingdom
play a critical role in strengthening and maturing Reapit’s cloud security posture. Your work will span hands on security engineering, deep incident response, proactive threat detection, and collaboration with global teams. Design, implement, and enhance secure Cloud infrastructure, services, and applications in collaboration with DevOps teams. Conduct … detail and high quality documentation. Work in a self managing, proactive manner — anticipating security needs, identifying gaps, and driving improvements without close supervision. Incident Response & Threat Detection Respond to SOC alerts. Working with our outsourced SOC, Lead and participate in global incident response activities, including investigation ...

Senior Cyber Security Analyst

Hiring Organisation
Hays
Location
Bolton, Greater Manchester, North West, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£55,000
Senior Cyber Security Analyst to help strengthen its security posture and safeguard critical systems. This is an excellent opportunity for someone passionate about incident response and proactive threat management within a dynamic, fast-paced environment. The ideal candidate will have a positive go-getter attitude, and will have … experience of incident response, using MS security tools and ideally an understanding of Tanium. Key Responsibilities Working with the Head of Information Security to mature the incident response capability Using your understanding of the contemporary threat environment to assist with your vulnerability investigations and response ...

Cyber Security Specialist

Hiring Organisation
LHH
Location
Wokingham, England, United Kingdom
energy operations within a Critical National Infrastructure (CNI) environment. This role is responsible for real-time security monitoring, alert triage, investigation, and early-stage incident response. You will work with industry-standard security monitoring and incident/event management platforms to identify suspicious activity, validate alerts, and escalate … helping tune detections, and strengthening operational procedures and documentation. Key Responsibilities Monitoring and Triage Monitor security events and alerts using industry-standard SIEM and incident/event management platforms (e.g., Elastic, Microsoft Sentinel, Splunk). Perform rapid triage to determine alert validity, severity, scope, and potential business or operational ...

Lead SOC Analyst (L3)

Hiring Organisation
GCS
Location
Manchester Area, United Kingdom
cyber security challenges, and wants to make a real impact within a large-scale enterprise environment. Key Responsibilities Lead and coordinate cyber operations and incident response activities across the organisation. Support the enhancement of cyber containment and response capabilities. Manage and respond to complex cyber security incidents … governance, and security control initiatives. Skills & Experience Required To be successful in this role, you should have: Strong hands-on experience in Cyber Security Incident Response or Cyber Operations. Deep technical expertise in one or more incident response related domains, including: SOC Operations Malware Analysis Endpoint ...

Cyber Security Engineer

Hiring Organisation
Eligo Recruitment
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£75,000 - £90,000 per annum
solving complex security challenges across modern cloud and enterprise environments.You’ll play a key role in strengthening detection capabilities, improving visibility across systems, enhancing incident response processes, and driving automation initiatives within a mature but evolving cyber function.The role offers broad exposure across security engineering, detection engineering, cloud … security, incident response, vulnerability management, and security architecture.Key Responsibilities Design, implement, and improve security controls across cloud and enterprise infrastructure Enhance SIEM, SOAR, and EDR/XDR capabilities including alerting, tuning, and integrations Build intelligent detection and response workflows Develop automation solutions using scripting and AI-assisted ...

AI-Augmented Cyber Security Engineer

Hiring Organisation
Eligo Recruitment
Location
London, South East, England, United Kingdom
Employment Type
Full-Time
Salary
£75,000 - £90,000 per annum
solving complex security challenges across modern cloud and enterprise environments.You’ll play a key role in strengthening detection capabilities, improving visibility across systems, enhancing incident response processes, and driving automation initiatives within a mature but evolving cyber function.The role offers broad exposure across security engineering, detection engineering, cloud … security, incident response, vulnerability management, and security architecture.Key Responsibilities Design, implement, and improve security controls across cloud and enterprise infrastructure Enhance SIEM, SOAR, and EDR/XDR capabilities including alerting, tuning, and integrations Build intelligent detection and response workflows Develop automation solutions using scripting and AI-assisted ...

Cyber Defence Analyst L2

Hiring Organisation
Airbus Protect Limited
Location
Newport, UK
Employment Type
Full-time
using the SOC toolset and following the heuristic guidance steps described in the associated playbooks. * Provide support and offer expertise across stages of the Incident Response lifecycle such as preparation, detection and analysis, containment, post-incident activity. * Ingest and interpret multiple sources of data from research, reports … incidents and turn them into actionable use cases across various technologies. * On request assist with the initial triage, scoping and containment efforts during incident response engagements and compromise assessments. * Mentor junior analysts. * Lead and direct efficient intelligence driven threat hunts. * Act as a solid technical point of contact ...

Cyber Security Engineer

Hiring Organisation
Required IT
Location
Bromley, Kent, England, United Kingdom
Employment Type
Full-Time
Salary
£55,000 - £60,000 per annum
supportive and collaborative environment with ongoing opportunities to develop your technical expertise and progress your career within cyber security. Key Responsibilities Security Monitoring & Incident Response Monitor alerts and telemetry across endpoints, identities, email, and cloud services using Rapid7 SIEM, Microsoft Defender, and Sophos Antivirus. Investigate cyber security incidents … including malware infections, phishing attacks, identity compromise, and unauthorised access attempts. Conduct incident triage, root cause analysis, containment, remediation, and recovery activities. Lead or support incident response activities in line with internal procedures and security standards. Escalate major incidents appropriately and provide timely updates to stakeholders. Threat ...

Cyber Security Operations Specialist

Hiring Organisation
Anson Mccade
Location
Glasgow, Lanarkshire, Scotland, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Edinburgh, Midlothian, Scotland, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Leeds, West Yorkshire, Yorkshire, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Anson Mccade
Location
Bristol, Avon, South West, United Kingdom
Employment Type
Permanent
Salary
£75,000
operations. This is a technical role suited to an experienced analyst with strong engineering instincts, hands-on coding capabilities, and a deep understanding of incident response, detection engineering, and adversary tradecraft. This position includes approximately one week per month of on-call availability for high-priority incident … ideal for someone who has likely grown from an engineering background and can write scripts (Python, Bash) to automate, enhance, and refine detection and response workflows. Experience with Splunk, SIEM operations, cloud endpoints, networks, and detection engineering will be highly advantageous. NOTE: Candidates for this role must be eligible ...

Cyber Security Engineer

Hiring Organisation
Foresters Financial
Location
Kent, South East, United Kingdom
Employment Type
Permanent, Work From Home
Salary
£60,000
environment and you will have on-going opportunities to develop your technical skills and grow within cyber security What you will do: Security Monitoring & Incident Response Actively monitor alerts and telemetry across endpoints, identities, email, and cloud services using Rapid7 SIEM, Microsoft Defender, and Sophos AV. Investigate suspected … malware infections, phishing campaigns, identity compromise, and unauthorised access attempts. Perform triage, root cause analysis, containment, and remediation of security incidents. Lead or support incident response activities in line with internal policies and procedures. Escalate significant incidents appropriately and provide clear, timely updates to stakeholders. Threat Detection & Prevention ...

Senior Cyber Incident Responder

Hiring Organisation
Reed
Location
Sheffield, South Yorkshire, England, United Kingdom
Employment Type
Contractor
Contract Rate
Salary negotiable
Senior Cyber Incident Responder Daily Rate: Inside IR35 Location: Sheffield Job Type: Hybrid (2-3 days on-site) Join our Cyber Defence Centre (CDC) as a Senior Cyber Incident Responder. This senior, business-facing role within Security Operations & Engineering focuses on end-to-end cyber incident management … coordination, and stakeholder engagement across complex environments. You will lead the response to high-severity cyber incidents, ensuring effective command, communication, and decision-making throughout the incident lifecycle. Day-to-day of the role: Incident Leadership & Management: Lead the coordination of high-severity cyber incidents from initiation ...

Senior Security Platform Engineer

Hiring Organisation
NTT Global Data Centers EMEA UK ltd
Location
Hemel Hempstead, Hertfordshire, South East, United Kingdom
Employment Type
Permanent
tasks specialized at threat hunting, SIEM/SOAR, Network Security and other operational security tasks such as performance and availability monitoring, log monitoring, security incident detection and response, security event reporting, and content maintenance (tuning). What we are looking for Key Responsibilities: Serves as a senior member … optimization of enterprise security platforms, overseeing lifecycle management including break-fix, patching, version upgrades, and integration with broader security ecosystems. Directs complex security incident response efforts across multiple vectorsendpoint protection, EDR, malware analysis, network and computer forensicsensuring rapid containment and root cause analysis. Designs and executes advanced vulnerability ...

Cyber Security Manager

Hiring Organisation
Hays
Location
Birmingham, West Midlands, United Kingdom
Employment Type
Permanent
Salary
£650.0 - £750.0 per day + £650 to £750 p/d Inside IR35
capability across a modern hybrid estate.This is a hands-on leadership role where you'll combine technical depth with stakeholder engagement, driving security operations, incident response, and continuous improvement across infrastructure, cloud, and workplace environments. The Role You'll take ownership of cybersecurity operations, leading a small engineering … team and working closely with an outsourced SOC/MSSP to ensure robust monitoring, response, and continuous improvement. Responsibilities Leading technical incident response (containment, eradication, recovery) and post-incident analysis Owning and improving security controls across endpoints, identity, networks, and cloud platforms Driving vulnerability management, patching ...

Cyber Security Manager

Hiring Organisation
Hays Technology
Location
Birmingham, West Midlands, West Midlands (County), United Kingdom
Employment Type
Contract
Contract Rate
£650 - £750/day £650 to £750 p/d Inside IR35
capability across a modern hybrid estate.This is a hands-on leadership role where you'll combine technical depth with stakeholder engagement, driving security operations, incident response, and continuous improvement across infrastructure, cloud, and workplace environments. The Role You'll take ownership of cybersecurity operations, leading a small engineering … team and working closely with an outsourced SOC/MSSP to ensure robust monitoring, response, and continuous improvement. Responsibilities Leading technical incident response (containment, eradication, recovery) and post-incident analysis Owning and improving security controls across endpoints, identity, networks, and cloud platforms Driving vulnerability management, patching ...

Security Lead

Hiring Organisation
Method-Resourcing
Location
Maidenhead, Berkshire, South East, United Kingdom
Employment Type
Contract, Work From Home
Contract Rate
Up to £500 per day
improvement Lead security engagement within client Design Authority and Enterprise Architecture forums Manage integration with the client SOC, including security reporting, SIEM alignment, and incident response coordination Oversee security incident management in line with the client Cyber Security Incident Response Plan Own joiner/mover … Strong understanding of NCSC HMG IAS5, Cyber Assessment Framework (CAF), ISO 27001, and GDPR Hands-on experience integrating with a UK Government SOC, including incident response and security reporting Strong working knowledge of Oracle Cloud security (OCI IAM, Vault, network security, audit, PAM) Experience securing Oracle SaaS applications ...