1 to 25 of 99 Permanent Incident Response Jobs in the North West

Cyber Response and Recovery - Assistant Manager (Reactive)

Hiring Organisation
KPMG
Location
Manchester, Greater Manchester, United Kingdom
Salary
£ 70 K
Cyber Response & Recovery Assistant Manager (Reactive DFIR)This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance.About the role The Cyber Response & Recovery Assistant Manager role will be working in the Cyber Response Services (CRS) Team within our Advisory practice.Your specific focus … will be in the domain of reactive digital forensics and incident response (DFIR) acting as a junior case manager on smaller cases, or part of a team (reporting to a case manager or senior case manager) on larger cases.This is a hands-on role, and an opportunity ...

Cyber Response & Recovery - Manager (Remediation focus)

Hiring Organisation
KPMG
Location
Manchester, Greater Manchester, United Kingdom
Salary
£ 70 K
Cyber Response & Recovery Manager (Remediation)This role requires current SC or DV clearance, or eligibility and willingness to obtain clearance.About the roleThe Cyber Response & Recovery Manager role will sit within the Cyber Response Services team in KPMG’s Cyber Advisory practice.Your specific focus will … compromise, Active Directory compromise, cloud compromise and advanced network intrusions. In these situations, clients look to KPMG not only to investigate and contain the incident, but also to help them recover securely, rebuild critical services, reduce the risk of reinfection and improve their long-term resilience.This is a hands ...

Senior Manager-Associate Director, Cyber Incident Response Advisory and Incident Management, Recovery and Resilience

Hiring Organisation
Deloitte
Location
Manchester, Greater Manchester, United Kingdom
Salary
£ 100 K
operations has become a board level issue. You will provide our clients with a full spectrum of services, covering proactive and reactive Cyber Incident Response (CIR) Services. The proactive arm of our business covers a breadth of propositions, including playbook development, wargaming, readiness assessments, post-breach assessments, managed … threat hunting as well as implementing response automation technologies. Our specialists work with clients to uplift their maturity and fundamentally enhance their preparedness to respond, via targeted capability uplift, C-Suite awareness campaigns and training.Our technical response team support our clients in live incident responses by working ...

Director, Digital Forensics & Incident Response (Global)

Location
Manchester, England, United Kingdom
Director, Digital Forensics & Incident Response (Global) Department: Cyber Services and Capabilities Employment Type: Full Time Location: GBR Manchester Hardman Boulevard Reporting To: Matt Hull (Open to Associate Director with progression path to Director) Description The purpose of this role is to lead NCC Group’s global Digital Forensics … Incident Response (DFIR) capability, ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The global DFIR team will consist of regionally distributed colleagues, delivering a consistent, scalable, and market-leading service that protects client assets, reputation, and business operations. ...

Security Engineer I, AWS Security Incident Response

Hiring Organisation
Amazon
Location
Manchester, Greater Manchester, United Kingdom
Salary
£ 70 K
Security Incident Response is looking for technical Security Engineers that are passionate about learning new concepts and work well within a team environment to keep customers secure. We value engineers that can work through ambiguity to identify suspicious activity, lead security response, and can explain technical security … detective controls such as Amazon GuardDuty and partner products such as CrowdStrike Falcon or Wiz Defend- Develop processes and policies to increase security response effectiveness.- On-call support: This role requires periodic on-call responsibilities including weekends.- Hold or be able to obtain and maintain a UK Government Security ...

Information Security Engineer

Hiring Organisation
Freshfields Bruckhaus Deringer
Location
Manchester, Greater Manchester, United Kingdom
Salary
£ 70 K
Aside from infrastructure, the candidate should have experience and working knowledge of SIEM and vulnerability management platforms. The role will cover elements of cyber incident response, so a background in supporting a wider incident response function is a necessity.Key ResponsibilitiesCloud Security Assessment & Advisory:Assess the security … configurations of Azure IaaS and Google Cloud environments, including infrastructure.Provide recommendations based on industry best practices and emerging security threats.The ability to provide Cyber Incident Responders subject matter expertise in Cloud security when required.Defender & Security Monitoring Advisory:Evaluate and optimise the use of Azure Defender and other security monitoring ...

Information Security Engineer

Hiring Organisation
Freshfields Bruckhaus Deringer
Location
Manchester, UK
Employment Type
Full-time
Aside from infrastructure, the candidate should have experience and working knowledge of SIEM and vulnerability management platforms. The role will cover elements of cyber incident response, so a background in supporting a wider incident response function is a necessity. Key ResponsibilitiesCloud Security Assessment & Advisory: Assess … Azure IaaS and Google Cloud environments, including infrastructure. Provide recommendations based on industry best practices and emerging security threats. The ability to provide Cyber Incident Responders subject matter expertise in Cloud security when required. Defender & Security Monitoring Advisory: Evaluate and optimise the use of Azure Defender and other security ...

Senior Security Specialist

Hiring Organisation
Reonomy
Location
Manchester, Greater Manchester, United Kingdom
Salary
£ 70 K
security operations, expanding our offensive security capabilities, and improving how we detect and respond to emerging threats. Working across security engineering, threat intelligence, incident response, and cloud security, you will identify opportunities to improve detection, automate processes, mature security technologies, and strengthen our overall security posture.This … across Security Operations and technology teams to drive continuous improvement.Work across the full spectrum of modern cybersecurity. From security engineering and cloud security to incident response, threat intelligence, automation, and offensive security, this role offers technical breadth. You will solve complex security challenges, improve detection and response ...

Security Consultant

Hiring Organisation
Version 1
Location
Manchester, Greater Manchester, United Kingdom
Salary
£ 60 K
define pragmatic remediation roadmaps aligned to business priorities. Lead and support security architecture reviews across cloud, applications, infrastructure, IAM, data protection and detection/response domains. Provide expert consulting to customers on security strategy, risk reduction, control design, and security operating model improvements. Challenge weak security assumptions with confidence … guardrails. Partner with engineering, platform, DevOps and operations teams to embed security into delivery pipelines and infrastructure as code practices. Support threat detection, incident response readiness, use-case tuning, and post-incident improvement activities. Contribute to security standards, policies, patterns, reusable accelerators, and client-facing deliverables including ...

Senior Digital Forensics and Incident Response Analyst

Hiring Organisation
Barclays
Location
Knutsford, Cheshire, United Kingdom
Salary
£ 70 K
AccountabilitiesManagement of security monitoring systems, including intrusive prevention and detection systems, to alert, detect and block potential cyber security incidents, and provide a prompt response to restore normal operations with minimised system damage.Identification of emerging cyber security threats, attack techniques and technologies to detect/prevent incidents, and collaborate … Barclays Mindset – to Empower, Challenge and Drive – the operating manual for how we behave. Join us as a Senior DFIR (Digital Forensics and Incident Response) Analyst at Barclays, where you will play a critical role within the Security Operations Centre, protecting the organisation from cyber threats and security ...

Business Incident Manager

Hiring Organisation
Atos
Location
Preston, Lancashire, United Kingdom
Salary
£ 60 K
backed schemes including Tax-Free Childcare, Help to Save, Court Funds Office and Help to Buy. Be at the centre of decision-making – Lead incident response activities, work directly with senior stakeholders and clients, and drive service recovery during high-profile operational events. Grow your career – Develop expertise … incident management, stakeholder engagement, service improvement and data analytics, with opportunities to influence strategic decisions and progress into senior service management and leadership roles.Role PurposeThe Business Incident Manager is responsible for the end-to-end management of business incidents impacting the NS&I B2B account, supporting key services ...

Database Platform Manager

Location
Manchester, England, United Kingdom
fleet reliability and SLOs. This role is weighted toward hands-on technical depth. You should be as credible in a design review or an incident bridge as you are in a planning session with senior stakeholders. Key Responsibilities Technical direction The technical roadmap for the estate. We want someone … performance, high availability and disaster recovery, patching, and backup and recovery Senior escalationpointfor complex L3 work: performance and query tuning, replication and failover, major incident response and post-incident review Automation, infrastructure as code and database CI/CD, with everything in GitHub under proper change management ...

Cyber Security Analyst

Hiring Organisation
The Portfolio Group
Location
Manchester, United Kingdom
Employment Type
Permanent
Salary
£50000 - £55000/annum
infrastructure and established a modern, cloud-first security stack, it is an exciting time to join the business as we mature our detection, response, and automation capabilities across a global estate. You will work collaboratively with the business and the wider IT team - Infrastructure, Network, Development, DevOps, and Service … with Palo Alto Cortex XSIAM and XSOAR, Cortex XDR, Microsoft Purview, Mimecast, Abnormal, Nessus, and Microsoft 365. You will participate in security investigations and incident response, responding to events involving malware, data loss, phishing, or network intrusion, and supporting our data protection and vulnerability management activity. You will ...

Global DFIR Director: Lead Cyber Incident Excellence

Location
Manchester, England, United Kingdom
Group plc seeks a Director, Digital Forensics & Incident Response (Global) to lead the global DFIR capability, setting strategic direction and ensuring effective preparedness, response, recovery, and continuous improvement across cyber incident management and forensic investigations. The role requires driving operational excellence, collaborating with NCC Group leaders … expanding security services through incident response opportunities. #J-18808-Ljbffr ...

Cloud Security Engineer - Manchester - National Security West

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£95,000
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Cloud Security Engineer - London - National Security West

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent, Part Time, Work From Home
Salary
£95,000
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Cloud Security Engineer – Manchester – National Security West

Hiring Organisation
BAE Systems
Location
Manchester, United Kingdom
Employment Type
Full Time
security services and implementing cloud security best practices, including identity, monitoring, threat detection and data protection. Understanding of Security Operations, including monitoring, alerting, incident response, threat detection, and SIEM platforms such as Microsoft Sentinel or Splunk. Strong understanding of Identity and Access Management (IAM), least-privilege access principles … . Designing and implementing secure AWS architectures that align with security and compliance requirements. Building and maintaining security monitoring, alerting and automated response capabilities across cloud environments. Integrating cloud platforms with security tooling, including SIEM solutions such as Microsoft Sentinel and Splunk. Leveraging AWS security services and promoting security ...

Head of Cyber Defence Centre

Hiring Organisation
Lloyds Banking Group
Location
Manchester, Greater Manchester, United Kingdom
Salary
£ 80 K
large-scale security capabilities that protect the UK’s largest digital bank.You’ll provide strategic direction for cyber defence, detection engineering, threat hunting and incident response, while driving continuous improvement across security operations platforms, tooling and processes. Leading a high-performing team, you’ll strengthen operational resilience, coordinate … effective response to cyber threats and incidents, champion a threat-led approach to defence, and help shape a world-class security operation that enables the Group to go faster, safely.Why Join us If you think all banks are the same, you’re wrong. We’re a pioneering, fast-changing ...

Product Security Engineer

Location
Manchester, England, United Kingdom
real control rather than a manifest scan, build-pipeline isolation, third-party risk as runtime telemetry. When the next big supply-chain incident lands, we should know within hours whether it touches us. Detect, respond, contain Runtime detection that catches what actually happens, not what a vendor template guesses … might. Incident response codified as automation: containment, rotation, isolation, evidence capture. Forensics tooling that works on our stack. Adversary emulation against our real attack surface. The metric is mean-time-tocontain, not control coverage. Secure the agentic development surface Our engineers ship with AI agents in the loop ...

Senior DFIR / Incident Response / Digital Forensics

Location
Knutsford, England, United Kingdom
DFIR Lead Cyber Operations Analyst , a VP-level role at the centre of the bank’s cyber defence, delivering advanced digital forensics and incident response. You will analyse malware, malicious samples and network activity to support complex investigations, working closely with internal teams, external partners and law enforcement. This … support may be required, including extended hours and weekend work. To be successful in this role, you will need the following: Digital forensics and incident response expertise, including host, network, cloud and live forensic analysis, supported by rigorous documentation practices. Excellent written and verbal communication skills, with ...

Platform Engineer, Azure Infrastructure

Location
Manchester, England, United Kingdom
compliance Collaborate with developers to improve CI/CD pipelines, deployment strategies, and overall developer experience Enhance observability and reliability, refining alerting, monitoring, and incident response Collaborate on cloud optimization projects, improving performance, cost efficiency, and security posture Mentor and guide team members, fostering a culture of technical … compliance Collaborate with developers to improve CI/CD pipelines, deployment strategies, and overall developer experience Enhance observability and reliability, refining alerting, monitoring, and incident response Collaborate on cloud optimization projects, improving performance, cost efficiency, and security posture Mentor and guide team members, fostering a culture of technical ...

On-Call DFIR Lead - Cyber Operations & Incident Response

Location
Knutsford, England, United Kingdom
seeking a DFIR Lead Cyber Operations Analyst at VP level in Knutsford. In this key role, you will deliver advanced digital forensics and incident response while leading complex investigations. You will collaborate with internal teams and law enforcement, and produce clear reports under pressure. Ideal candidates will have ...

Senior SOC Analyst - Manchester

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
Salary
£95,000
/7 operation with four shift teams working in a standard rotation. They are responsible for utilising the SOC's Security Incident and Event Management (SIEM) toolsets to detect and investigate potential Security and Service Incidents occurring within the monitored networks. These roles require a minimum of SC clearance … using the Protective Monitoring platform and Internet resources to identify cyber-attacks/security incidents. Categorise all suspected incidents in line with the Security Incident policy Recognise potential, successful and unsuccessful intrusion attempts and compromises through reviews and further analysis of relevant event detail and incident summary information. ...

SRE Managing Consultant - Cloud Operating Model

Location
Manchester, England, United Kingdom
Model & Ways of Working**: Define and implement SRE ways of working and engagement patterns, aligning reliability practices with existing ITSM/ITIL processes (e.g., incident, problem, release and change) and modern engineering delivery.* **Reliability Measures (SLIs/SLOs) & Error Budgets**: Establish service measures and targets (SLIs/SLOs … Insight:** Shape observability approaches (metrics/logs/traces) and operational monitoring models that make reliability risks visible and actionable, improving operational decision-making.* **Incident Excellence & Continuous Learning:** Design incident analysis and improvement loops, including practical approaches that strengthen incident response and drive learning through post ...

Vice President, Production Services Application Support

Hiring Organisation
Hackajob Ltd
Location
Manchester, North West, United Kingdom
Employment Type
Permanent
coverage across on-site and offshore support hours. Use SQL scripting, automation, monitoring, and observability tools to improve operational resilience, service health, reliability, and incident response. To be successful in this role, we're seeking the following: Excellent SQL scripting skills. Strong scripting and automation skills using languages such … Proven skills and track record in AI automation, including the use of intelligent automation capabilities to reduce manual effort, improve operational efficiency, and enhance incident response workflows. Experience applying AI and automation solutions for alert correlation, anomaly detection, predictive monitoring, and service optimisation. Strong understanding of Site Reliability ...