Lead Cyber Incident Responder

Role: Lead Cyber Incident Responder 18-Month FTC

Location: Fully Remote – UK

Salary: Up to £100,000

We're partnering with one of the UK's leading green energy technology companies as they continue to strengthen their Cyber Defence capability.

We're looking for a Lead Cyber Incident Responder to join a small, highly technical team where you'll have genuine ownership and influence. This isn't an Incident Manager position where you coordinate other people doing the investigation; you'll be the person getting hands-on when an incident occurs.

At Lead level, you'll be trusted to operate independently and take technical ownership of incidents ranging from day-to-day security events through to complex, high-severity incidents.

What you'll be doing

  • Lead security incidents end-to-end, from initial investigation and scoping through containment, eradication, recovery and lessons learned.
  • Remain genuinely hands-on with SIEM, EDR, endpoint telemetry, process activity, logs, network evidence and other investigation data.
  • Act as the technical escalation point when incidents become complex or business-critical.
  • Investigate threats across endpoint, cloud, identity, email and network environments.
  • Improve detections, investigation workflows, playbooks and response processes based on lessons learned.
  • Use scripting and automation to make Incident Response faster and more effective.
  • Support and mentor other responders while remaining a senior individual contributor.
  • Work closely with internal security teams and an MSSP during live incidents.

You'll already be operating as a Lead, Principal or highly experienced Senior Incident Responder / CSIRT / DFIR professional.

You'll need significant hands-on experience investigating and responding to security incidents, with the ability to operate independently as the lead technical responder when required.

Experience across enterprise SIEM and EDR/XDR tooling is essential. The environment includes technologies such as Google SecOps/Chronicle and CrowdStrike, alongside cloud environments including GCP/AWS.

We're particularly interested in people with strong experience across DFIR, threat hunting, detection engineering, networking fundamentals, incident automation and major incident response.

Most importantly, you'll be someone who remains calm and methodical when things go wrong, can make evidence-led technical decisions and is comfortable taking ownership when the answer isn't immediately obvious.

📍 Fully Remote – UK

💰 Salary up to £100,000

📄 18-month Fixed-Term Contract

Job Details

Company
Pulse Group
Location
United Kingdom
Hybrid / Remote Options
Posted